Crypto Prices

Investigation uncovers mixing activity as Bitcoin thief retains 1,159 BTC

38 minutes ago
1 min read
1 views

Overview of the COLDCARD Wallet Theft

A recent analysis by Galaxy Research reveals that a significant portion of the Bitcoin stolen due to a vulnerability in the COLDCARD wallet, totaling 1,159.42 BTC (approximately $72.71 million), has not been moved since the heist occurred in just 41 minutes. This theft, originating from 870 compromised addresses, is now spread across seven main addresses linked to the assailant.

Investigation and Laundering Attempts

While the bulk of these funds remains untouched, investigators have observed a new development: a different perpetrator seems to be attempting to launder smaller amounts of the stolen Bitcoin through a mixing service.

The initial wave of thefts, related to the COLDCARD flaw, has resulted in widespread concern as law enforcement, exchanges, and blockchain analysis firms have flagged around 600 addresses tied to the incident, complicating the thief’s chances of cashing in on their illicit gains. Any attempt to transfer these funds to regulated exchanges could invite scrutiny due to the tracking systems in place designed to detect suspicious transactions.

On-Chain Activity and Mixing Techniques

In a separate on-chain activity unrelated to the major 1,159 BTC group, it appears that an attacker has initiated transactions involving 64 BTC sent to a mixer. Out of this, approximately 10 BTC was mixed, with around 54 BTC returned as change, further broken down into smaller outputs of about 7 BTC each for additional mixing. This method of using mixers serves to obfuscate the original source of the cryptocurrency and complicates tracking efforts, although analysts note that the uniform size of outputs allows for relatively straightforward monitoring.

Impact of the Vulnerability

The ongoing investigation does not conflate these two groups of funds, as it has been previously reported that multiple attackers exploited the same wallet vulnerability, indicating that movements from one collection of compromised funds may not apply uniformly across all related thefts. Collectively, about 1,596 BTC have been stolen during several attack waves, and as speculations rise regarding a potential increase in total losses to approximately 2,055 BTC, the ramifications of this vulnerability continue to evolve.

The root of the problem stems from a firmware glitch that compromised the randomness in generating wallet seed phrases, enabling criminals to recreate possible seeds offline without needing direct access to compromised devices. Following the breach, Coinkite has issued updated firmware, but criminals could still exploit existing vulnerabilities until affected users migrate their Bitcoin to newly generated addresses. Notably, Canadian Bitcoin holders are significantly affected, with an estimated 25% of the losses being attributed to users in Canada alone.

Future Outlook

As law enforcement continues to develop its understanding of the web of theft, the outlook for recovering stolen Bitcoin remains uncertain, given that the attackers could redistribute their funds across various decentralized platforms or outside of US jurisdiction before any attempt to convert them occurs.

Popular