Coldcard entropy flaw leaves 87.3% of stolen Bitcoin unmoved

Galaxy Research attributed 1,789.28 Bitcoin stolen from 8,865 addresses to the Coldcard hardware-wallet exploit, worth $114.7 million when taken and about $138.8 million at more recent prices. Approximately 1,561 Bitcoin, or 87.3%, remains unmoved in attacker-controlled collection and holding addresses, including all funds from the first three identified attack waves. Later-wave funds have moved through CoinJoin transactions, peel chains and other obfuscation methods. Galaxy recorded median address-level losses of 0.00152 Bitcoin and mean losses of 0.20184 Bitcoin, while 221 victim reports covered 790.72 Bitcoin, or 44.2% of attributed losses. The incident was linked to a March 2021 firmware configuration error that weakened seed randomness and remained undetected for years, contributing to reported losses of more than $100 million, mostly from single-seed wallets. Casa CEO Nick Neuman claimed that 233,000 bitcoins moved to safety in response. The episode has prompted a reassessment of single-signature self-custody and growing recommendations for multi-vendor multisig, which requires multiple key pairs from different providers but adds operational complexity.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.