TLDR
- The largest known Coldcard attacker controls 1,159 BTC spread across seven addresses.
- None of that 1,159 BTC has moved into a mixer or a cash-out service.
- A separate attacker sent 64 BTC toward a mixer, with about 10 BTC mixed so far.
- Investigators have flagged roughly 600 addresses tied to the theft and shared them with exchanges and law enforcement.
- Galaxy Research says total losses from the Coldcard flaw stand near 1,596 BTC, with a possible fourth wave pushing that closer to 2,055 BTC.
Blockchain investigators are tracking new activity tied to the Coldcard wallet theft. Most of the stolen Bitcoin has not moved. But one attacker has started sending funds toward a mixing service.
Galaxy Research says the largest known attacker holds 1,159 BTC. That Bitcoin sits across seven separate addresses. None of it has been sent to an exchange, a mixer, or any other service that could help convert it to cash.
The Largest Holder Stays Quiet
The theft tied to these seven addresses happened fast. On-chain monitoring shows the funds were swept up within 41 minutes.
Since then, the addresses have stayed still. Analysts describe the Bitcoin as unmoved rather than frozen. Bitcoin cannot actually be locked at the network level just because an address has been flagged.
Still, moving the funds carries risk for the attacker. Law enforcement agencies, exchanges, and blockchain analytics firms have flagged about 600 addresses connected to the theft.
Any attempt to send that Bitcoin to a regulated exchange could trigger a compliance review. That could lead to questions about where the funds came from.
A Smaller Attacker Starts Mixing
A separate person appears to be trying to hide their stolen Bitcoin. Analysts spotted 64 BTC entering a transaction linked to a mixing service.
About 10 BTC was mixed first. Roughly 54 BTC came back as change. That remaining amount was then split into smaller pieces of about 7 BTC each.
Mixers work by blending transactions together. This makes it harder to trace where the coins started and where they ended up.
Analysts say the even, repeated size of these outputs makes the pattern easier to follow. That gives investigators a trail to keep watching.
This activity appears separate from the seven-address cluster holding 1,159 BTC. Multiple people may have exploited the same wallet flaw, so one attacker’s moves do not explain the whole case.
Galaxy Research previously confirmed that 1,596 BTC was stolen from about 7,300 addresses. The theft happened across three separate attack waves.
The firm also found 14 smaller incidents linked to the same bug. A possible fourth wave could raise the total closer to 2,055 BTC, though Galaxy has not confirmed those extra losses yet.
The problem started with a firmware error in the Coldcard device. It weakened the randomness used to create wallet seed phrases.
That let attackers guess possible seed phrases offline. They could then check those guesses against real addresses on the blockchain, without ever touching the physical device or its PIN.
Coinkite, the company behind Coldcard, has released fixed firmware. But that fix cannot protect a seed phrase that was already created using the flawed version.
Anyone affected needs to generate a brand new seed phrase. They must then move their Bitcoin to fresh addresses tied to that new seed.
Galaxy Research has shared confirmed attacker and victim addresses with US law enforcement and cyber-investigation groups. This growing list may help track stolen funds if attackers try to use regulated platforms.
Recovery is still not guaranteed. Attackers can move funds through multiple wallets, mixers, or platforms outside US jurisdiction before trying to cash out.
For now, the 1,159 BTC held by the largest attacker remains untouched and under watch, while the newer mixing attempt gives investigators a fresh trail to follow.
The post Coldcard Bitcoin Theft Attacker Holds 1,159 BTC as Mixing Begins appeared first on Blockonomi.

11 hours ago
11









English (US) ·