TLDR
- Galaxy Research investigated a Bitcoin theft tied to a 2021 Coldcard firmware flaw
- 192 victims have confirmed losses of about 714.8 Bitcoin in the public dataset
- Total losses across all linked addresses have climbed past $115 million
- Attackers left different transaction habits, grouped into waves and footprints
- Most of the stolen coins were generated between 2021 and 2022
It has been 18 days since the Coldcard exploit first came to light on July 30. The impact is still being felt by Bitcoin holders.
Galaxy Research spoke with more than 200 victims on August 16 to learn more about the theft. Their goal was to understand how the attackers worked.
The stolen coins were traced back to a single date. That date is March 17, 2021, when the flawed Coldcard firmware was first released.
At that time, Bitcoin had reached a block height of 674,951. This detail matters because it links the exploit directly to a flaw in how wallet seeds were created.
How the Theft Happened
The flaw allowed bad actors to predict or recreate the entropy used to generate a wallet seed. In simple terms, this let them guess or rebuild the private keys tied to affected wallets.
Galaxy’s research shows that most of the theft activity took place between 2021 and 2022. This was the period when the largest number of stolen addresses first appeared.
Galaxy published a public dataset listing 8,680 addresses connected to the theft. These addresses hold roughly 1,778.6 Bitcoin combined.
Only a small share of those addresses have been directly linked to victims who came forward. Even so, the numbers are large.
Out of the public dataset, 192 people have confirmed losses. Their cases involve about 1,790 addresses and 714.8 Bitcoin.
Earlier reporting had placed total losses at more than 1,596 Bitcoin across roughly 7,300 addresses. At the time, that was valued at over $100 million.
Using Bitcoin’s price on August 16, the total value of losses has now passed $115 million.
Tracking the Attackers
Researchers identified several patterns, or fingerprints, in how the stolen funds moved. These patterns include block timing, transaction fees, lock times, and destination addresses.
One group, labeled Wave 1, stole about 1,082.65 Bitcoin from blocks 960,183 through 960,191. This group typically moved one victim’s coins per transaction into four collection addresses.
Other groups worked differently. Wave 3 handled 63 victims, while Wave 2 handled only 19.
A separate pattern called Footprint E grouped as many as 795 victims into a single transaction. The median number of victims per transaction for this group was 118.
The way stolen funds were spread out also varied. Some groups scattered the coins across hundreds of addresses, while others kept the funds concentrated in just a few wallets.
As of August 16, the confirmed losses stand at more than $115 million. Galaxy Research says the investigation into the full scope of the theft is ongoing.
The post Galaxy Research Details Bitcoin Losses From Coldcard Vulnerability appeared first on Blockonomi.
