Saturday, August 1, 2026
Catatonic Times
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
No Result
View All Result
Catatonic Times
No Result
View All Result

Coldcard Attacker Stole $30M in 10 Minutes by Targeting Big Wallets

by Catatonic Times
July 31, 2026
in Bitcoin
Reading Time: 3 mins read
0 0
A A
0
Home Bitcoin
Share on FacebookShare on Twitter


Key Takeaways

The attacker stole roughly $30 million in the course of the first 10 minutes.Investigators recognized 500 sufferer wallets swept inside 25 minutes.Weak seeds require substitute, even after putting in the hotfix.

Attacker Prioritized Coldcard Wallets With the Largest Balances

Blockchain analytics agency Chainalysis revealed on July 31 that the attacker focused high-value Coldcard {hardware} wallets early, quickly growing the whole quantity stolen. The agency discovered that three of the ten largest affected wallets held no less than 10 BTC, price roughly $636,000 in the course of the evaluation.

One sufferer misplaced about $1.8 million, whereas the cumulative worth taken climbed towards $30 million in the course of the operation’s first 10 minutes. The ordering prompt that the attacker had examined the accessible pockets inhabitants earlier than starting the systematic sweep.

Chainalysis reported:

“This sample means that the attacker studied the sufferer pockets inhabitants earlier than continuing.”

Chart: Chainalysis knowledge reveals the attacker swept the highest-value bitcoin first, with transaction values declining quickly over time because the sweep expanded to smaller wallets. Supply: Chainalysis.

Over roughly 25 minutes, the attacker drained 500 distinct wallets, producing a pointy improve in stolen worth earlier than increasing throughout smaller balances. Chainalysis used its Reactor investigation platform to look at the move of funds, sufferer addresses, and focus among the many largest losses.

The sequence signifies a deliberate effort to maximise early proceeds relatively than processing wallets randomly or following their unique era order. Prioritizing bigger balances additionally lowered the danger that warnings, change controls, or defensive transfers would restrict the attacker’s most dear alternatives.

Paid Blockchain Service Account Traced Throughout Sweeps

Block’s investigation into the Coldcard pockets drains started after the corporate’s bitcoin engineering and safety groups acquired reviews that wallets outdoors the corporate’s Bitkey platform had been being drained. Bitkey Engineering Lead Clay Garrett described an uncommon request sample that helped investigators determine a suspected operational workflow.

Investigators decided that the operator had used a paid account at a well known blockchain-services supplier to question supply addresses and conduct associated exercise. The supplier’s inside information reportedly matched the suspected quantity, timing, and sequence of requests with what Garrett characterised as extraordinary specificity.

Garrett said:

“The supplier was supplying its customary companies in response to requests that didn’t reveal their broader goal.”

Block discovered no proof that the unnamed supplier knowingly participated within the suspected theft or deliberately helped the operator carry it out. The corporate contacted the supplier instantly and commenced sharing related info with applicable authorities whereas limiting disclosures that would disrupt the investigation.

Coinkite Advisory Identifies Affected Coldcard Firmware

As investigators traced the stolen funds, Coinkite reiterated which units had been affected by the underlying vulnerability. The corporate’s Coldcard Mk3 safety advisory lined units that generated seeds on firmware variations 4.0.1 by 5.0.3. Early findings indicated that Mk4, Q, and Mk5 fashions had been unaffected, whereas reviews linked roughly 594 BTC, valued at practically $38 million, to about 500 dormant wallets swept inside roughly 25 minutes.

Many affected addresses had remained inactive for years and generally held balances starting from 0.15 BTC to 0.26 BTC. Coinkite beneficial making a substitute seed on an unaffected machine, sending a small take a look at transaction, confirming the receiving handle on the {hardware} display, and retaining the earlier backup till the migration succeeds.

Weak Seeds Stay Uncovered After Firmware Updates

Coldcard homeowners who generated seeds utilizing weak firmware face dangers that putting in the most recent hotfix alone can’t resolve. Chainalysis suggested affected customers to create a wholly new seed on patched {hardware} earlier than transferring their bitcoin from affected wallets.

The agency additionally beneficial utilizing a robust BIP-39 passphrase for extra safety. Chainalysis continues monitoring the exploiter pockets, a consolidation handle, and reviews of doubtless ongoing assaults in opposition to addresses suspected to be derived from weak non-public keys. Block mentioned it’ll launch extra findings as soon as doing so not dangers interfering with the investigation.



Source link

Tags: 30MAttackerBigCOLDCARDMinutesstoleTargetingWallets
Previous Post

New Bitcoin study shows the strongest recurring liquidation warning signs cannot warn of an individual crash

Related Posts

BTC Holdings & Key Risks
Bitcoin

BTC Holdings & Key Risks

July 31, 2026
Base Says Its Distribution Edge Can Outlast Robinhood Chain’s Early Surge
Bitcoin

Base Says Its Distribution Edge Can Outlast Robinhood Chain’s Early Surge

July 31, 2026
Samsung SDS Plans Stablecoin Expansion With Upbit Operator Dunamu
Bitcoin

Samsung SDS Plans Stablecoin Expansion With Upbit Operator Dunamu

July 30, 2026
‘Bitcoin Senator’ Blasts Democrats For Stalling Clarity Act
Bitcoin

‘Bitcoin Senator’ Blasts Democrats For Stalling Clarity Act

July 31, 2026
Bitcoin Treasury Strategy Posts .2 Billion Loss
Bitcoin

Bitcoin Treasury Strategy Posts $8.2 Billion Loss

July 31, 2026
Spanish Bank Banco Santander Reveals .3M Bitcoin Position
Bitcoin

Spanish Bank Banco Santander Reveals $4.3M Bitcoin Position

July 30, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Catatonic Times

Stay ahead in the cryptocurrency world with Catatonic Times. Get real-time updates, expert analyses, and in-depth blockchain news tailored for investors, enthusiasts, and innovators.

Categories

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

Latest Updates

  • Coldcard Attacker Stole $30M in 10 Minutes by Targeting Big Wallets
  • New Bitcoin study shows the strongest recurring liquidation warning signs cannot warn of an individual crash
  • COLDCARD Bug Puts Hundreds of Hardware Wallets at Risk
  • About Us
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.