Skip to main content

Coldcard Attacker Stole $30M in 10 Minutes by Targeting Big Wallets

Importance High

Blockchain analytics firm Chainalysis revealed on July 31 that the attacker behind the Coldcard wallet drain prioritized high-value wallets, stealing roughly $30 million within the first 10 minutes. The attack targeted Coldcard hardware wallets, with three of the 10 largest affected wallets holding at least 10 BTC, worth approximately $636,000 during analysis. One victim lost about $1.8 million. The attacker appeared to study the victim wallet population before proceeding, draining 500 distinct wallets over approximately 25 minutes. The sequence suggests a deliberate effort to maximize early proceeds rather than processing wallets randomly or following their original generation order.

Block’s investigation into the Coldcard wallet drains began after its bitcoin engineering and security teams received reports of wallets outside its Bitkey platform being drained. Bitkey Engineering Lead Clay Garrett described an unusual request pattern that helped identify a suspected operational workflow. Investigators determined the operator used a paid account at a well-known blockchain-services provider to query source addresses. The provider’s internal records matched the suspected number, timing, and sequence of requests with extraordinary specificity. Block found no evidence the provider knowingly participated, and contacted the provider while sharing information with authorities.

Coinkite, the company behind Coldcard, reiterated which devices were affected. The advisory covered Mk3 devices with seeds generated on firmware versions 4.0.1 through 5.0.3. Mk4, Q, and Mk5 models were unaffected. Reports linked roughly 594 BTC (valued at nearly $38 million) to about 500 dormant wallets swept within approximately 25 minutes. Many addresses had been inactive for years. Chainalysis advised affected users to create a new seed on patched hardware before transferring bitcoin from affected wallets, as installing the latest hotfix alone cannot resolve the risk. The firm also recommended using a strong BIP-39 passphrase for additional protection and continues monitoring the exploiter wallet.

Source: https://news.bitcoin.com/security/coldcard-attacker-stole-30m-in-10-minutes-by-targeting-big-wallets/