Particle.news
Download on the App Store

Coldcard Attacker Moves Nearly Half of Third‑Wave Haul After Firmware Entropy Flaw

Shifts into THORChain and CoinJoin signal active laundering, requiring victims to create new seeds and migrate funds.

Overview

  • Galaxy Research said Monday that the operator has moved roughly 97.09 BTC, about 45% of the Wave 3 vaults, by swapping through THORChain and sending portions into CoinJoin mixing rounds.
  • Researchers trace total confirmed losses at about 1,789 BTC and report a newly identified 58‑address cluster that could raise the toll to roughly 1,806 BTC across more than 8,600 addresses and about 190 victims.
  • The thefts stem from a March 2021 Coldcard firmware change that routed seed generation to a MicroPython software PRNG, cutting effective entropy to roughly 40–72 bits and making offline brute‑force recovery of single‑signature seeds practical.
  • Coinkite has released emergency firmware patches that stop future vulnerable seed creation but cannot change seeds already made on affected builds, so exposed users must generate fresh seeds or adopt stronger custody setups and then move their coins.
  • On‑chain trackers and firms are following the laundered funds and sharing leads with exchanges and law enforcement, and the case is likely to renew scrutiny of hardware‑wallet audits, vendor governance, and the risks of single‑key self‑custody.