Galaxy research head says Coldcard exploit tracking requires tracing fund inflows

Smaller attackers showed distinct discovery patterns, making victim reports critical and complicating investigation versus typical DeFi or CEX hacks.

Summary

Galaxy's research head said on X that investigators have identified multiple smaller-scale attackers, each with a different discovery pattern, and that these actors would not have been found without reports from victims. The post said the Coldcard vulnerability and its exploitation differ from typical DeFi or CEX (centralized exchange) hacks, where funds can usually be seen leaving a central point and then tracked downstream. In this case, investigators also need to trace the inflow side of funds, a less common requirement in on-chain thefts that the post said helps explain why the vulnerability and exploit are unusually complex and destructive.

Terms & Concepts
  • DeFi: decentralized finance applications
  • CEX: centralized crypto exchange
  • on-chain thefts: thefts traceable on blockchain