Coldcard Hacker Moves $7.7M Bitcoin, Empties Vaults Systematically

Editorial illustration: Five open steel vaults decrease in size from left to right. Copper-colored coins extend along a tray from the middle vault, while a large metal key lies in the foreground.

In brief

  • Attacker moved 97.09 BTC (~$7.7M), roughly 45% of wave 3 haul, from compromised Coldcard wallets
  • 293 two-of-two multisig vaults created and emptied largest-first, eleven now empty
  • March 2021 firmware bug reduced seed generation entropy from 128 bits to as low as 40 bits
  • Coinkite released patch requiring manual randomness input via key presses or dice rolls

Vault Draining Strategy

The attacker created 293 two-of-two multisig vaults for victims' coins during wave 3. By methodically draining them in order of size, the operator has converted stolen Bitcoin into other assets using mixing techniques. The first exit came on September 2, when around 20.5 BTC from the largest vault went through THORChain and came out as Ethereum. More recent moves show tactical variation—coins spent on Sunday night went into CoinJoin rounds instead, a Bitcoin privacy technique that pools transactions from multiple users.

The deliberate pace and structure suggest the attacker is managing operational risk. Eighty-two percent of stolen coins across all waves remain untouched, indicating the operator may be spacing out exits to avoid detection or market impact.

The Firmware Bug Behind the Theft

The thefts trace to a firmware bug Coinkite introduced in March 2021, which rerouted seed generation from the device's hardware random-number chip to a software stand-in. The bug collapsed key strength from 128 bits of entropy to as low as 40 bits—a catastrophic weakness that made brute-force attacks feasible.

The sweeps began on July 30. Coinkite's response came quickly but couldn't undo the damage. The company released patched firmware requiring owners to supply their own randomness through key presses, dice rolls, or coin flips.

Coinkite's Reckoning

Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31, writing that the company would have to "earn back our users' trust." The statement acknowledged the scale of the breach without minimizing it—a necessary step for a hardware wallet maker whose entire value proposition rests on cryptographic security.

Galaxy Research's published total for the exploit stands at about 1,806 BTC, or $143.9 million, including an unconfirmed fourth wave of 638.5 BTC reported in August. No attacker sweeps had been logged since August 6 until this week's movement, suggesting the operator may have paused to assess risk or plan the next phase.