Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

Coldcard Wave 3 Attacker Starts Swapping Stolen Bitcoin for ETH Through THORChain

bullish:

0

bearish:

0

Coldcard, Bitcoin, THORChain, Ethereum, Crypto Exploit,

Bitcoin stolen during the third major Coldcard attack wave has begun moving from its original attacker addresses for the first time, with part of the funds converted into Ether through THORChain.

Approximately 4.2 BTC was swapped into about 135 ETH as the attacker tested multiple routes through the cross-chain liquidity protocol. Several attempted swaps were refunded before being retried, while the resulting ETH was traced to a newly created Ethereum address.

Wave 3 Funds Leave Original Addresses

The movement marks the first confirmed outbound activity from the original consolidation addresses associated with Coldcard Waves 1, 2 or 3.

Wave 3 originally drained 207.7294 BTC from vulnerable wallets in early August and used a transaction structure distinct from the first two large attack waves.

Most of that Wave 3 Bitcoin remains unmoved. The latest transactions instead represent an initial attempt to convert part of the stolen BTC into assets that can move across Ethereum and other blockchain infrastructure more easily than native Bitcoin.

The destination Ethereum address and related transaction paths have been shared with exchanges, compliance companies and law-enforcement investigators as efforts continue to identify potential off-ramps.

Coldcard Theft Reached at Least 1,778 BTC

The broader Coldcard compromise resulted from weak seed generation introduced through faulty firmware dating back to March 2021. A random-number-generation failure could leave some wallets with dramatically weaker private-key entropy, allowing attackers with sufficient computing resources to reconstruct affected seeds remotely.

At least 1,778.84 BTC was confirmed stolen from more than 8,600 addresses by mid-August. Additional lower-confidence clusters could push the ultimate total considerably higher.

Movement had already occurred from smaller attacker footprints outside the three primary waves, including funds routed through CoinJoin transactions, peel chains, bridges and centralized services. The new THORChain activity is significant because the original wallets associated with the three largest identified attack waves had remained untouched after receiving stolen BTC.

Firmware Fix Cannot Repair Existing Seeds

Coinkite released updated Coldcard security firmware in August that requires additional user-supplied randomness when generating new wallet seeds.

Updating affected hardware does not make an existing vulnerable seed secure. Bitcoin held under seeds generated on affected firmware must be transferred to a newly generated wallet using patched software and sufficient fresh entropy.

Most Bitcoin associated with the original Wave 3 addresses remained in place after the first THORChain swaps, while investigators continue tracking the newly received ETH and any subsequent transfers from the destination address.

The post Coldcard Wave 3 Attacker Starts Swapping Stolen Bitcoin for ETH Through THORChain appeared first on Crypto Adventure.

bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.