Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
coindesk.com
+ 1 more7 h
The attacker behind the third wave of thefts from Coldcard hardware wallets moved 97.09 $BTC ($7.7 million), roughly 45% of the bitcoin taken, through two separate methods.
Galaxy Research said the attacker routed about 20.5 $BTC from its largest vault through decentralized exchange THORChain on Sept. 2, with the proceeds landing on Ethereum.
It then sent 15.48 $BTC from the second-largest vault into a CoinJoin transaction on Sept. 5, followed by another 61.12 $BTC from 10 vaults the next day.
CoinJoin combines bitcoin transactions from multiple users, making it harder to link specific inputs with their eventual outputs.
Galaxy said the attacker has been working through the 293 vaults in order of size and has now emptied the 11 largest. The next 10 hold 30.81 $BTC, while vaults ranked 61 through 293 contain a combined 33.77 $BTC.
The vaults are not victims’ own wallets. Galaxy said the exploiter created them, one for each victim’s coins, using a two-of-two multisignature setup that requires two keys to move the bitcoin. The previously unidentified vault, funded by 58 addresses, used the same format.
Galaxy said the vault was probably linked to another Coldcard victim, though its origin remains unconfirmed. Including it would raise Wave 3 to 294 vaults and bring the wider exploit to about 1,806 $BTC, worth roughly $143.9 million.
About 82% of the bitcoin taken across all waves remains at its original attacker-controlled addresses, while 18% has moved in transactions that appear designed to obscure the funds’ trail, Galaxy said.
The thefts began July 30 after attackers exploited a firmware flaw that weakened the randomness used by Coldcard devices to generate wallet seeds.
Coinkite has released fixed firmware, but said affected users must create new seeds and move their funds because an update alone cannot repair compromised ones.
Similar news (1)
Source: <a href="https://cryptonews.net/news/security/33407134/” target=”_blank” rel=”nofollow noopener”>cryptonews.net
