According to Galaxy Research, over 87 per cent of the bitcoin stolen in connection with the Coldcard attack is still in the wallet address controlled by the attackers. This means that most of the funds have not yet entered a more complex transfer phase, and there are still clearer observation windows for chain tracking.

Confirmed loss close to 1,800 bitcoins

Alex Thorn, head of Galaxy Research, disclosed on platform X that researchers had attributed 1,789.28 bitcoin out of 8,865 addresses to the attack. The value at the time of theft was approximately $114.7 million; at current prices, it was approximately $138.8 million.

Of these, approximately 1,561 bitcoins have not yet been transferred, accounting for 87.3 per cent of the losses attributed to them. According to the researchers, all bitcoin involved in the first three identified attacks is currently static, which provides a clearer chain record for follow-up monitoring.

Follow-up funds began to use confusion techniques

Galaxy also found that part of the funds in subsequent attacks had begun to move. According to the researchers, the attackers used CoinJoin, Peel Chain and others to try to make the flow of funds more difficult.

Of these, CoinJoin consolidates multiple participants ' transactions and weakens the correlation between input and output; Peel chain divides larger balances and transfers them to a new address, stretching the trade path.

Galaxy indicated that these transfers had been followed up on an ongoing basis and that the addresses of the identified attackers had been shared with the encryption exchange, compliance companies and law enforcement agencies. The Platform may have the opportunity to identify and freeze some of its assets if the funds eventually flow to centralized services.

The victim's report shows a large loss.

To date, Galaxy has received 221 victim reports, involving a total of 790.72 bitcoin, or 44.2 per cent of the total loss attributable to it.

  • 1.04272 BTC
  • The average loss reported for the sample was 3.57792 BTC
  • Median held before the stolen bitcoin was about 3.25 years

Thorn explained that the median number was more than 1 bitcoin, meaning that at least half of the victims had been reported to have lost 1 bitcoin or more. At the same time, the stolen assets remained in place long before the theft, indicating that the affected users included long-term currency holders.

He also indicated that, if addresses that had not yet been fully recognized but with medium confidence were included, the scale of the loss could have risen to approximately 1,824 bitcoin, estimated at approximately US$ 140 million at the time of each theft.

Hole points to the problem of random number of solid pieces

TRM Labs previously indicated on 5 August that the incident included multiple attacks that began on 30 July and pointed to the random number in the Coldcard solid. According to the Agency, the problem arose from a construction configuration error introduced in March 2021, which resulted in some equipment not relying fully on hardware entropy sources when generating wallet seeds, but reverting to a weaker, random software generation method.

According to TRM Labs, this reduces the strength of the key so that the assailant may recover the private key by violent calculation without having to contact the wallet hardware. It also noted that the replacement of the solids alone would not repair old seeds that had been generated with a weak random number, and that affected users needed to regenerate new seeds on secure hardware and transfer bitcoin to a new address.

Hardware wallets are safe and secure.

The incident once again pushed the security of the hardware wallet to the stage. The report mentions that Coinkite just released Coldcard MK5 in May this year, continuing the dual security component design, offline trading processes and product routes that support only bitcoin.

At the same time, there have been a number of recent discussions and disclosures related to the security of wallets within the industry, including the randomity of software wallet assistive words, as well as physical attacks by researchers on other hardware wallets. The key point of this event, however, was that the seed generation chain itself was defective, rather than that the traditional equipment was broken directly and remotely.

For the investigators, 1,561 bitcoins still outstanding are the most important source of evidence in the chain. As long as these funds remain at identified addresses, there remains an opportunity for exchanges, compliance agencies and law enforcement agencies to monitor their follow-up.