Coldcard Hacker Moves $1.9M In Bitcoin As Wallet Activity Returns

fiverr
fiverr


What to know:

  • Coldcard hacker moves 30.185 Bitcoin worth $1.94M after several weeks of wallet inactivity.
  • Galaxy Research links up to 2,055 BTC worth about $130M to the wider Coldcard breach.
  • Coinkite urges affected users to replace vulnerable seeds as investigators track funds.

A Bitcoin wallet linked to the Coldcard hardware-wallet hack moved 30.185 BTC worth about $1.94 million on Aug. 7. On-chain tracker Lookonchain said the funds were sent to a newly created address after weeks of inactivity.

The transfer represents about 1.5% of the estimated 2,055 BTC tied to the theft. It was the first reported movement from the attacker since the initial breach.

The transaction does not show whether the Bitcoin will be sold or exchanged. The funds could remain at the new address or move again.

bybit

How the Coldcard Flaw Exposed Bitcoin Wallets

This comes after a breach in hardware wallets, which resulted in losses of over $100 million. Galaxy Research revealed three confirmed attacks resulting in the loss of 1,596 BTC from over 7,300 addresses.

Also Read: Optimism Plans 343 Million OP Increase as Buybacks Reach 9 Million

If a fourth attack happens, the total amount would rise to almost 2,055 BTCs, worth approximately $130 million.

Prior to the transfer on August 7th, Galaxy Research noted that almost 90 percent of the stolen Bitcoin had been untouched. The funds stayed in addresses where they received them after being stolen.

Source: X

Since Bitcoin transactions are registered in a public blockchain, it is possible to trace the movement of funds from the known attacker addresses.

On-chain analysts will be monitoring the latest transfer, waiting for additional activities. The second transfer will give information about the handling of stolen funds.

Usually, attackers transfer stolen funds via several wallets to reach exchanges. Nonetheless, the latest transfer cannot guarantee that the attacker will cash out his Bitcoin.

This security breach was caused by the vulnerability in the software of Coldcard hardware wallets designed by Coinkite. According to the firm, it affected the version that came into the market in March 2021.

Coinkite noted that vulnerable software used a deterministic pseudo-random generator in the generation of wallet seeds. It was supposed to use a hardware-based true random number generator.

The security vulnerability posed a great threat for users of the affected wallet, as hackers could rebuild their seed phrases or private keys without physical access.

The seed phrases and private keys grant users the ability to sign transactions. Whoever accesses these details can control the funds on the wallet.

What Happens Next in the Coldcard Bitcoin Hack

Coinkite encouraged users who had created seed keys using vulnerable firmware to transfer their money to safe addresses and create new wallet seeds.

The company issued updates to the firmware to solve the problem. Nevertheless, all existing seeds that were created using vulnerable firmware still have vulnerabilities and need to be changed.

Now focus shifts to the new address that has received 30.185 BTC. Any further transactions will give clues about whether the money is being divided, moved, or transferred to another service.

Galaxy Research stated that it has passed information obtained during the investigation to law enforcement agencies in the United States. This information includes all attacker and victim addresses.

The platform has also passed all this information to cryptocurrency exchanges and cybercrime investigators. The identification of attacker wallets is still necessary in order to monitor the future transactions of Bitcoin.

Also Read: CleanSpark Loss Hits $239 Million as Q3 Revenue Misses Expectations



Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*