Bullish
Coldcard Hack Leaves 132.95 BTC Unaccounted For as Attackers Fail to Drain All Funds
05:39
Researchers identify crude attack software limiting UTXO retrieval, leaving 75+ BTC undrained and 132.95 BTC in unlinked stolen addresses.
Woofun AI reports that Coldcard attackers employed a methodical approach, identifying vulnerable addresses and prioritizing transfers based on Bitcoin holdings. Analysis reveals the attack software was rudimentary, failing to retrieve all spendable UTXOs due to API limitations; for instance, one address retained 25 early UTXOs, including one worth 0.16 BTC, while the tool inefficiently spent a 294-satoshi UTXO, incurring fees far exceeding its value. This suggests the tool builder possessed limited understanding of the Bitcoin UTXO model. Although the victim's seed phrase appears compromised, at least 75 BTC remains in other derived addresses. Currently, 132.95 BTC sits in 153 stolen addresses whose seed phrases researchers have not yet reproduced, raising the possibility that attackers accessed additional private devices.
WOOFUN AI
Impact Assessment · Quick Read
The inefficiency of the attack software highlights a gap in the attackers' technical sophistication regarding Bitcoin's UTXO structure, resulting in significant funds remaining undrained. The inability to reproduce the seed phrases for the 132.95 BTC in stolen addresses introduces uncertainty regarding the scope of the breach, potentially indicating broader device compromise beyond a single seed leak. This partial drain may mitigate total loss impact but underscores persistent security risks in hardware wallet ecosystems.
Generated by WOOFUN AI · For reference only, not investment advice
Comments
No comments yet.