Skip to main content

Coldcard Hacker Gets Brazen Bitcoin Laundering Offer Onchain

Importance High

The Coldcard security incident escalated this week after a public bitcoin transaction offered laundering services to the thief responsible for one of the largest self-custody bitcoin thefts on record. Meanwhile, users report that emergency firmware updates have left some hardware wallets unusable.

Coinkite, the maker of Coldcard, recently disclosed that a firmware flaw allowed attackers to recover weakly generated wallet seeds and drain vulnerable single-signature wallets. According to the Coldcard Sweep Watch dashboard, the stolen total has risen to approximately 1,359.8820 BTC, with most funds still sitting in a small number of addresses controlled by the attacker.

On Aug. 1, one of the attacker’s addresses received a transaction carrying an OP_RETURN message. OP_RETURN allows permanent text to be stored on the Bitcoin blockchain without transferring spendable funds. The message openly advertised bitcoin “cleaning” services, KYC assistance, and cash-out options for a 10% fee, along with a Telegram contact. It was not a victim appeal but a direct solicitation to whoever controls the stolen coins. Some speculate it might be law enforcement or a trap.

Despite the scale of the theft, blockchain researchers note that much of the bitcoin remains untouched. The attacker consolidated funds into a few addresses after sweeping vulnerable wallets during coordinated waves starting July 30. Bitcoin’s transparent ledger means anyone can monitor these addresses, turning the incident into a public spectacle.

In response to the vulnerability, Coinkite released emergency firmware updates designed to eliminate the weak random number generation that caused the issue. The company stressed that the update only protects wallets created in the future and cannot repair seeds generated on vulnerable versions. Soon after, users began reporting devices stuck on error screens, failing to boot, or appearing bricked, primarily affecting Mk4 and Q models. Coinkite had not yet confirmed a widespread defect as of Aug. 2, but concerns are growing.

Security experts advise users of potentially vulnerable wallets to move funds to a new wallet created with strong entropy before updating firmware. Updating cannot fix a weak seed; only generating a new wallet with sufficient randomness can protect assets. Verified seed backups remain critical, as a damaged device can be replaced while the recovery phrase restores access.

The Coldcard incident has become a broader test of confidence in hardware wallet security, combining a historic entropy bug, a public laundering solicitation on the blockchain, and reports of bricked devices. As monitoring of attacker addresses continues, the community watches whether the stolen bitcoin moves and whether Coinkite issues further guidance for affected customers.

Source: https://news.bitcoin.com/crypto-news/coldcard-hacker-gets-brazen-bitcoin-laundering-offer-onchain/