Researchers suspect that a vulnerability in COLDCARD hardware wallet firmware was exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator.
Digital asset research firm Galaxy Research says it identified an initial wave of transactions that it believes was likely linked to the vulnerability, draining approximately 1,083 BTC, worth $70.2 million, from 1,196 addresses on July 30.
The 41-minute attack occurred approximately 30 hours before Coinkite publicly disclosed the flaw.
Every transaction used an identical hardcoded fee rate of 30 satoshis per virtual byte and left no change output, making Galaxy believe the attackers used an automated tool.
"Signature: every sweep paid an identical hardcoded 30.0 sat/vB — a 30-75x overpay vs the 0.4-1.0 sat/vB median that week — and left no change output, explained Galaxy.
"That looks like an automated tool spending keys it already held, not owners moving funds."
On August 1, Galaxy Research identified a second and third wave, raising the estimated total to 1,367 Bitcoin, worth approximately $88.6 million, stolen from 4,585 addresses. The stolen Bitcoin remained in the attacker-controlled addresses at the time of its report.
Chainalysis found that the attacker prioritized high-value wallets, stealing approximately $30 million during the first ten minutes and taking $1.8 million from one victim.
The company said this suggested the attacker had identified and studied the affected wallets before beginning the thefts.
Transactions for stolen COLDCARD assets over time
... continue reading