BlockBeats News, August 2nd, Bitcoin hardware wallet Coldcard was attacked, with the stolen funds now totaling 1367.05 BTC, worth approximately $88.6 million, involving 4585 addresses. Galaxy Research Director Alex Thorn stated that the attack is still ongoing, and users who have not yet moved their funds should immediately transfer their assets out of the addresses generated by Coldcard. He also urged affected users to voluntarily provide information to help track the stolen funds and report to law enforcement.
Thorn stated that the previously confirmed three rounds of large-scale attacks have obvious programmatic characteristics, with similar transaction patterns that may have been orchestrated automatically; the related stolen BTC is currently still held in the attacker's addresses and has not been transferred. However, smaller opportunistic attackers have emerged recently, who will move and launder funds within a few hours, with some funds flowing to overseas gambling platforms through cross-chain services like ThorChain.
All Coldcard single-signer addresses generated after the March 2021 firmware upgrade are ultimately vulnerable to theft, and users should complete the migration as soon as possible. The stolen funds were on average dormant for 3.18 years, with a median of 3.55 years, and the victims are mainly long-term holders.
Thorn stated that most of the discovered stolen assets have not yet been moved, and the relevant addresses have been provided to U.S. law enforcement and industry contacts. He believes that this incident is a significant blow to Bitcoin self-custody, and the industry needs to improve security, education, and risk warnings regarding the complexity of self-custody.
