Coldcard exploit: how stolen BTC is moving and why a firmware patch cannot repair an old seed

Galaxy Research says the attacker moved 97.09 BTC, about 45% of the third-wave haul, using THORChain and CoinJoin. The reported exploit traces back to a firmware bug that could reduce seed entropy, and a firmware update cannot repair a weak seed that was already generated.

Coldcard exploit: how stolen BTC is moving and why a firmware patch cannot repair an old seed

Galaxy Research says the operator linked to the third wave of Coldcard wallet thefts moved 97.09 BTC, roughly 45% of that wave and about $7.7 million at prices cited in the report. The first large portion moved through THORChain and emerged on Ethereum, while later coins entered CoinJoin rounds that make subsequent tracing more difficult.

Researchers say the attacker created 293 separate 2-of-2 multisig vaults and has been emptying them roughly from largest to smallest. Some value remained as unspent CoinJoin change, so “moved” should not be read as “fully converted or cashed out.” Onchain analysis describes a custody path and does not identify the ultimate beneficial owner by itself.

The source ties the thefts to a firmware bug introduced in 2021. Seed generation could be routed away from the hardware random source to a software fallback, and in the worst case entropy was reportedly reduced enough to make some private keys recoverable offline without physical access to the device.

Coinkite updated firmware and changed the randomness-generation process, but software updates cannot strengthen a weak seed that already exists. Affected wallets need a newly generated seed under the corrected process and a transfer of funds, which is why patching the generator is different from repairing previously created keys.

Trust 62 Importance 52 Noise 8% Related symbol Informational material, not financial advice.