The attacker behind a major Coldcard wallet drain stole about $30m in the first 10 minutes by targeting the largest balances first, according to blockchain analytics firm Chainalysis.
More than $38m in bitcoin was ultimately taken from about 500 dormant wallets during a sweep that lasted roughly 25 minutes. Chainalysis said the order in which the wallets were drained suggested the operator had assessed the available targets before beginning a systematic attack.
Three of the 10 largest affected wallets contained at least 10 BTC each, worth about $636,000 at the time of the analysis. One victim lost approximately $1.8m, while the total value stolen rose rapidly towards $30m during the opening 10 minutes.
The pattern indicated that the attacker was seeking to maximise early proceeds instead of processing wallets randomly or working through them in the order in which they had originally been created. Taking the largest balances first may also have reduced the chance of warnings, exchange restrictions or defensive transfers preventing access to the most valuable wallets.
Using its Reactor investigation platform, Chainalysis examined the movement of funds, the addresses involved and the concentration of losses among the biggest victims. The firm found that 500 distinct wallets were drained over the course of the operation, with the attack later extending to smaller balances.
Block began investigating after its bitcoin engineering and security teams received reports that wallets outside its Bitkey platform were being emptied. Clay Garrett, Bitkey Engineering Lead, identified an unusual pattern of requests that helped investigators establish a suspected operational process.
The investigation found that the operator had used a paid account with a well-known blockchain-services provider to query source addresses and carry out related activity. The provider’s internal records reportedly matched the suspected number, timing and sequence of requests with what Garrett described as extraordinary specificity.
Block found no evidence that the unnamed provider knowingly took part in the theft or deliberately assisted the operator. The company contacted the provider, shared relevant information with the appropriate authorities and limited the details it made public in order not to compromise the investigation.
As the stolen bitcoin was traced, Coldcard manufacturer Coinkite restated which devices were exposed to the vulnerability. Its Coldcard Mk3 security advisory applies to devices that generated seeds using firmware versions 4.0.1 through 5.0.3.
Initial findings suggested that the Coldcard Mk4, Coldcard Q and Coldcard Mk5 were not affected. Reports connected about 594 BTC, worth almost $38m, to approximately 500 dormant wallets swept in around 25 minutes.
Many of the affected addresses had been inactive for years and held between 0.15 BTC and 0.26 BTC. Coinkite advised users to generate a replacement seed on an unaffected device, make a small test transaction, check the receiving address on the hardware screen and keep the old backup until the migration had been completed successfully.
Installing the latest hotfix alone does not remove the risk for owners who created seeds while using vulnerable firmware. Chainalysis advised those users to generate a completely new seed on patched hardware before moving bitcoin from the affected wallets.
It also recommended using a strong BIP-39 passphrase for additional protection. Chainalysis said it was continuing to monitor the exploiter wallet, a consolidation address and reports of possible continuing attacks against addresses believed to have been derived from vulnerable private keys.
Block said it would publish further findings when doing so no longer risked interfering with the investigation.
