BTC $76,931.08 -0.41%
ETH $2,490.36 -1.31%
BNB $718.53 -1.08%
XRP $1.34 -1.43%
SOL $100.15 -1.40%
TRX $0.3406 +0.21%
DOGE $0.0830 -1.99%
ADA $0.2049 -0.91%
BCH $221.69 -1.69%
LINK $11.26 -2.15%
HYPE $77.78 -2.28%
AAVE $124.63 -0.71%
SUI $0.7075 -2.03%
XLM $0.1779 -1.18%
ZEC $1,073.52 -4.43%
AAPL $330.40 -0.85%
AMZN $254.10 -1.06%
GOOGL $336.97 -1.32%
MSFT $491.04 -0.91%
META $644.40 -0.64%
NVDA $214.82 -1.64%
TSLA $361.96 -1.47%
SNDK $1,566.79 -3.58%
INTC $98.62 -3.29%
SPCX $149.01 -0.71%
MU $935.57 -3.23%
AMD $500.04 -3.13%
BTC $76,931.08 -0.41%
ETH $2,490.36 -1.31%
BNB $718.53 -1.08%
XRP $1.34 -1.43%
SOL $100.15 -1.40%
TRX $0.3406 +0.21%
DOGE $0.0830 -1.99%
ADA $0.2049 -0.91%
BCH $221.69 -1.69%
LINK $11.26 -2.15%
HYPE $77.78 -2.28%
AAVE $124.63 -0.71%
SUI $0.7075 -2.03%
XLM $0.1779 -1.18%
ZEC $1,073.52 -4.43%
AAPL $330.40 -0.85%
AMZN $254.10 -1.06%
GOOGL $336.97 -1.32%
MSFT $491.04 -0.91%
META $644.40 -0.64%
NVDA $214.82 -1.64%
TSLA $361.96 -1.47%
SNDK $1,566.79 -3.58%
INTC $98.62 -3.29%
SPCX $149.01 -0.71%
MU $935.57 -3.23%
AMD $500.04 -3.13%

coldcard

All
Article
Flash

Galaxy Research: Coldcard attackers continue to transfer funds, approximately 45% of the stolen assets have entered mixing or cross-chain pathways

Galaxy Research published that the attackers in the Coldcard "Wave 3" attack are still continuously transferring the stolen funds. During this phase, the attackers created 293 2-of-2 multi-signature wallets for each victim's assets. The first batch of funds was transferred across chains to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attackers are processing the largest amounts of stolen funds in order of the stolen amount, having sequentially transferred the funds from wallets ranked 1 to 11. The next 10 wallets that have not yet been transferred hold a total of 30.81 BTC, while wallets ranked 61 to 293 hold a total of 33.77 BTC. So far, the attackers have transferred about 45% of the stolen assets from this exploit, with funds flowing to Ethereum (via THORChain) or entering CoinJoin mixing transactions. Additionally, this fund transfer has revealed a previously unknown wallet: 58 addresses jointly spent in a 2-of-2 multi-signature format identical to that of Wave 3, and these were further transferred by the Wave 3 attackers to a jump address that funds CoinJoin.The on-chain analysis team currently marks this wallet as "cause = open," but believes it likely also belongs to Coldcard victims, which means the number of wallets involved in Wave 3 may increase to 294, raising the previously reported total amount stolen from the Coldcard vulnerability to approximately 1806 BTC. Currently, about 82% of the stolen BTC remains in addresses initially controlled by the attackers, while about 18% has been transferred, with the flow of funds indicating that it may be undergoing laundering processes.

Coldcard releases new firmware to enhance security; affected users need to regenerate their mnemonic phrases and migrate their assets

Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following an emergency fix, focusing on addressing the security risks posed by previous mnemonic phrase generation attacks. Each newly generated mnemonic phrase must include at least one user entropy source, such as irregular key presses at least 65 times, physical dice rolls 50 times, or physical coin tosses 128 times, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2.The new firmware also adds pre-signing phased PSBT verification, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard states that this update aims to further reduce the risk of the device being attacked.The official reminder is that updating the firmware cannot fix existing mnemonic phrases generated by previously affected firmware. If a user's mnemonic phrase falls within the scope of this security announcement, they should first update the device, then generate and verify a brand new mnemonic phrase, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signatures of the downloaded firmware.
app_icon
ChainCatcher Building the Web3 world with innovations.