One hacker holds 1,159 BTC stolen from a series of Coldcard wallet exploits across seven separate addresses. Based on on-chain monitoring, the tens of millions of dollars in funds have not moved an inch since the theft occurred. This pool of coins stems purely from a lightning attack, where the entire 1,159 BTC asset stash was drained in just 41 minutes. A Galaxy Research report confirmed a broader theft scale: a total of 1,596 BTC vanished from approximately 7,300 user addresses across three consecutive waves of attacks. A fourth wave is predicted to potentially drive total losses to as high as 2,055 BTC.
Not Frozen, Just Held
Law enforcement, crypto exchanges, and analytics firms have flagged about 600 addresses directly linked to this hack. The main hacker’s silence across the seven storage addresses does not mean the funds have been frozen by the network. The Bitcoin protocol is built on permissionless principles and does not have a pause button to reverse transactions. The stolen funds are held purely because the hacker is aware the coins have been blacklisted. Forcing them into licensed exchanges would inevitably trigger seizure. As a precautionary measure, the Galaxy team has submitted the list of perpetrator and victim addresses to U.S. authorities, exchange platforms, and international cyber investigation groups.
Why the Laundering Pattern Actually Helps Trackers
While the main culprit chooses the safe path, another hacker outside the seven-address cluster has begun taking risks by laundering funds through a mixer service. Investigators detected a transfer of 64 BTC into a mixer. Out of that amount, about 10 BTC was mixed and the remaining 54 BTC was returned as change. This change was then split into several wallets in uniform amounts of approximately 7 BTC for further laundering.
This method ultimately backfired on the perpetrator. Sending large, uniform output amounts makes it easier for investigators to trace the flow of coins on the public ledger. The repeated numerical patterns make it stand out amidst the sea of daily Bitcoin transactions, defeating the mixer’s original purpose of concealing the funds’ origin.
Don’t Stop at Device Updates
The root of the entire incident stems from a firmware vulnerability that weakened the randomization of Coldcard’s seed phrases. Device manufacturer Coinkite has indeed released a patching firmware, but the update does not block hacker access to old wallets. As long as users continue to use the old seed phrase generated while the system was vulnerable, the hacker still holds the key. The only safe way forward for wallet owners is to generate a new seed phrase on the updated device and immediately transfer their coins to a new wallet address. Reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.
