News linked to both this project and an event.
according to Galaxy's head of research, the COLDCARD Seed Entropy theft incident has resulted in 1,830 BTC being stolen, involving 3 rounds of attacks and more than 30 smaller related indicators. A total of 256 victims have reported their situations to GLXY Research, with a median loss of 1.1 BTC, and efforts to track the attackers are still ongoing.
according to Bitcoin News monitoring, this batch of Bitcoin is worth over $4 million, accounting for approximately 2.8% of the total Bitcoin related to the Coldcard vulnerability. Crypto Recovery Trust will verify the ownership of the funds and attempt to return them; Galaxy Digital research director Alex Thorn stated that another 3.0134 BTC was transferred to this address in the same transaction, but its source has not yet been confirmed.
Odaily News: On September 21, a white hat actor transferred 40.71 BTC linked to the Coldcard vulnerability in a single transaction valued at approximately $3.31 million. The transaction consolidated funds from 11 addresses and included an OP_RETURN message pointing to the Crypto Recovery Trust.Alex Thorn, head of Galaxy Research, disclosed that the broader consolidation involved a total of 52.37 BTC across multiple clusters of attacker addresses, accounting for approximately 2.8% of the funds tied to the vulnerability. A firmware flaw in Coldcard devices dating back to March 2021 resulted in insufficient mnemonic seed randomness, with the total funds involved peaking at approximately $130 million. (Decrypt)
Odaily News: According to monitoring by Galaxy's head of research, Coldcard white hat funds consolidated 52.37 BTC from Wave 2, Footprints AA, AU, and AX into a new address, which inscribed the OP_RETURN message "claim:cryptorecoverytrust dot com" in block 967,948. These white hat funds account for 2.8% of the Coldcard exploit attack funds.
according to Bitcoin News monitoring, the Coldcard thief is prioritizing emptying the largest portion of the third wave of vaults. Galaxy Research stated that these wallets have transferred out 97.09 BTC, worth approximately $7.7 million, accounting for about 45% of the assets in this batch. The attacker created 293 2/2 vaults themselves and previously moved some tokens via THORChain on September 2, followed by multiple rounds of CoinJoin over the weekend. The vulnerability stems from a 2021 firmware flaw that reduced seed entropy to a minimum of 40 bits. Of the tokens stolen in this exploit, approximately 82% remain unmoved.
According to Galaxy Research, in the Coldcard wallet attack incident, the Wave 3 attacker has transferred approximately 45% of the stolen Bitcoin, with the related funds routed to Ethereum via THORChain or entering CoinJoin transactions to increase tracking difficulty. Galaxy stated that the attacker previously created 293 2-of-2 multisig vaults to hold victim funds, draining them from largest to smallest amount, and the funds in the 11 largest vaults have now been fully transferred out.
According to Odaily, monitoring by Galaxy's Head of Research revealed that Liquid's white hat hacker stated they would return most of the 4,000 BTC after the Liquid Network vulnerability is patched. The hacker communicated with Blockstream through OP_RETURN messages and PGP-encrypted text: In block 965,822, a Blockstream address sent 1,000 satoshis with the message "Please contact the security team via the Blockstream website"; in block 965,865, the hacker sent an encrypted message to their own key, accompanied by a detached PGP signature that can be verified using the key published by Blockstream; in block 965,869, the hacker sent 1,000 satoshis to the Liquid federation peg-in wallet via a self-spend transaction with the message "Can we return the majority of the funds to the federation address?"; in block 965,875, the hacker conducted another self-spend transaction, sending 1,000 satoshis to the federation peg-in wallet and leaving an OP_RETURN message: "Please fix the vulnerability first. As of the latest commit, there is risk on-chain. Please ensure every node completes the patch update. Once the fix is confirmed, we will securely transfer the funds back." Relevant technical details were encrypted via PGP messages to the key published by Blockstream, readable only by Blockstream.
Odaily News – According to Bitcoin News monitoring, hackers linked to the third wave of Coldcard wallet thefts have begun moving stolen funds for the first time, converting Bitcoin into ETH via THORChain. Galaxy Research's Alex Thorn stated that approximately 10% of the stolen BTC has been moved, while the remaining 90% remains untouched. The attacker reportedly encountered difficulties during the fund conversion, with multiple THORChain transactions being returned and retried. Researchers have traced the related swap activity to a new Ethereum address, which Alex Thorn noted has been shared with relevant authorities and cryptocurrency companies. Galaxy Research indicated that the broader Coldcard exploit has resulted in losses of at least 1,789 BTC across 8,865 addresses, valued at approximately $115 million based on prices at the time of the theft.
Odaily News: According to monitoring by Galaxy's Head of Research, the COLDCARD Wave 3 attacker has moved stolen funds for the first time, exchanging them for ETH via the THORChain cross-chain DEX. This marks the first on-chain transfer of funds from the original hacker address across Waves 1, 2, or 3.
Odaily News: According to monitoring by Galaxy's Head of Research, the Coldcard hacker remains active, with one hacker stealing a key generated by adding entropy from 5 dice rolls.
Odaily News reported that Galaxy Research tracking found that 6 bitcoin wallets, dormant since 2011, 2012, and 2014, transferred a total of 553.59 BTC between August 16 and 26, valued at $40.15 million at the time of transfer. Two of the wallets carry the "Salomon Client Dusted" tag linked to a New York lawsuit involving Noah Doe.One of the transfers involved 40 BTC from a wallet dormant since May 28, 2012, with the funds moved on August 26 to German crypto custodian bank Boerse Stuttgart Digital. Calculated at a cost of approximately $5, the funds appreciated by roughly 1,535,911%.The remaining transfers included 212 BTC, 150 BTC, and 132.31 BTC, originating from wallets inactive since 2012, 2014, and 2011, respectively. The Noah Doe lawsuit seeks to declare 39,069 dormant bitcoin addresses in New York State as lost property. Additionally, several long-term holding addresses moved funds following the July Coldcard hardware wallet vulnerability incident. (Decrypt)
According to Cointelegraph, the latest statistics from Galaxy Research show that the Coldcard hack involved 8,865 addresses, resulting in the theft of 1,789.28 Bitcoin valued at approximately $114.7 million based on the price at the time of the incident. Of this amount, 1,561 Bitcoin, representing roughly 87.3% of the stolen funds, have not yet been transferred and remain in aggregation or holding addresses controlled by the attackers.
Odaily News According to Galaxy's head of research, the Coldcard vulnerability incident involved 8,865 addresses, resulting in total losses of 1,789.28 BTC, valued at $114.7 million at the time of theft and currently valued at $138.8 million.By address, the median loss per address was 0.00152 BTC, with an average of 0.20184 BTC; the median dormancy period for affected addresses was 3.2 years, with an average of 3.6 years.Among 221 victim reports, the median loss was 1.04272 BTC, with an average of 3.57792 BTC; the median dormancy period was 3.25 years, with an average of 2.99 years. The losses reported by victims amount to 790.72 BTC, accounting for 44.2% of total losses. If medium-confidence losses are included and related losses remain unconfirmed, total losses would reach 1,824 BTC, valued at $140 million based on prices at the time of the incident.
according to Bitcoin News monitoring, analysis by Galaxy Research (@glxyresearch) has identified distinct characteristics among various groups that exploited weakly secured COLDCARD seeds in their attacks. The 10 largest groups alone transferred approximately 1,700 BTC, with the biggest group moving over 1,080 BTC. Researchers differentiated the attackers based on patterns such as fee strategies, transaction timing, fund consolidation methods, and the destinations of the stolen BTC. Several of the largest groups are still suspected to hold nearly all of the stolen BTC. Victims of COLDCARD attacks can contact @intangiblecoins to assist in gathering evidence and reaching out to relevant authorities.
Odaily News, Galaxy Research Head Alex Thorn stated on the X platform that attacks exploiting the Coldcard hardware wallet vulnerability have noticeably declined, but cumulative losses continue to rise as more victims come forward. The impact of this incident on the Bitcoin community is significant, as the victims are primarily long-term BTC holders who adhered to self-custody cold storage principles, rather than those who lost assets due to high-risk trading or DeFi activities.At a scale of $112 million, this incident ranks among the top 20 largest hacks in crypto history and is one of the most severe security breaches in the hardware wallet self-custody sector to date. Bitcoin culture may be entering a new phase—the era of relying solely on ideological advocacy and extreme self-custody promotion is coming to an end. The community needs to place greater emphasis on technical security, lower the barrier to entry for users, and avoid simply shifting the burden of security responsibility onto ordinary users. This crisis may ultimately drive the Bitcoin ecosystem to establish a more mature security framework.Galaxy Research has directly contacted 190 victims and has confirmed with high confidence that the exploit has led to the theft of 1,778.84 BTC (approximately $112.7 million) from over 8,600 addresses. This tally does not yet include certain moderately credible suspicious attack records, such as the unconfirmed "Wave 4." If these potential attack scopes are incorporated, total losses could expand to 2,417.35 BTC (approximately $153 million).Meanwhile, the incident is reshaping market perceptions of self-custody security. Galaxy noted that multisig wallets have emerged as the "winners" of this event, with no stolen transactions traced to multisig wallets so far. Multisig service providers including Casa, Unchained, Nunchuk, and Anchorwatch have all observed a notable increase in user registrations and BTC inflows.
Odaily News: According to monitoring by Galaxy's Head of Research, since July 31, they have communicated with over 190 victims of the Coldcard vulnerability attack, and have asked victims who have not yet been in touch to reach out via direct message so they can provide tracking information and assist in reporting losses to relevant authorities. Since August 6, no new attacks have been confirmed, but this does not mean that new attacks cannot occur, and vigilance should be maintained.
Odaily News: Hardware wallet Coldcard has suffered a hack, with no confirmed total loss amount yet. Blockchain analytics platform CryptoQuant has confirmed losses of 1,432 BTC, while Galaxy Research places a high-confidence minimum estimate at 1,730 BTC. Other analyses suggest the scale of losses could be even higher. Research firm Galaxy Research stated that its earlier estimate of 1,816 BTC represents a potential figure, not a confirmed total. As of Tuesday, the firm's confirmed high-confidence minimum loss stands at 1,730 BTC, with over 450 BTC directly confirmed based on victim reports. Blockchain intelligence firm TRM Labs estimates that the attacker moved approximately 1,816 BTC from more than 5,200 addresses in four phases. CryptoQuant stated that its confirmed figures only include addresses publicly disclosed by victims and verified through on-chain patterns, meaning the tally could rise as more victims come forward with information. (Cointelegraph)
Odaily News – According to monitoring by Galaxy's Head of Research, the median dormancy period for stolen coins is 3.5 years, with 88% of stolen coins being over one year old. By address, the median loss is 0.014 BTC and the average loss is 0.212 BTC; over 250 victim reports have been received. Based on victim reports, the median loss is 1.022 BTC and the average loss is 4.04 BTC, with reported losses ranging from 624 satoshis to 58.97 BTC.
Odaily News: DefiLlama data shows that hackers stole $247 million in crypto assets in July, making it the second-highest month since 2026, trailing only April's $644 million; this figure represents a significant increase from June's $75 million and May's $60 million. Galaxy Digital stated that the Coldcard vulnerability was the largest attack event of the month, confirming three rounds of attacks involving 7,300 wallets, with at least $100 million in Bitcoin stolen; the firm also identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million. DefiLlama's hack tracker estimates losses related to this vulnerability at $115 million. Other attacks in July include a $9 million exploit on decentralized finance protocol Bonzo Lend, a $2.6 million theft from Cardano-based wallet SecondFi, a $24 million theft from Arbitrum-based perpetual trading platform AFX, and a $7.5 million theft from the Verus Ethereum Bridge.
Odaily News: According to Bitcoin News monitoring, Galaxy Research stated that the largest known COLDCARD theft incident involves 1,159 BTC, distributed across seven attacker addresses, which remain untouched to date, with 0 BTC cashed out or transferred through mixers. The relevant BTC was stolen within 41 minutes, but approximately 600 attacker addresses have been flagged by law enforcement agencies, exchanges, and blockchain analysis firms. Meanwhile, a smaller-scale attacker appears to have begun cleaning funds. On-chain analysts have tracked 64 BTC entering mixers, of which only about 10 BTC initially completed mixing, 54 BTC returned as change, and were subsequently split into outputs of approximately 7 BTC each for further mixing. Analysts noted that these unusually large outputs remain easy to trace, making this cleaning attempt relatively transparent.