Loading IndicatorLoading Indicator

Galaxy Research Says Coldcard Addresses Created Since March 2021 Face Ongoing Risk

Source

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Coldcard
Photo: Coldcard

A Bitcoin theft campaign exploiting a flaw in the random-number generation, or entropy, of the Coldcard hardware wallet is still ongoing.

Alex Thorn, head of research at Galaxy Research, wrote on X on Aug. 1 that an active theft operation is targeting all single-signature Coldcard addresses created after a firmware update in March 2021. Users with funds in those addresses should move them immediately.

The attack initially came in three large, sophisticated waves, Thorn wrote. He said the pattern appears to have been programmatically designed using large language models, or LLMs. Most of the stolen Bitcoin remains frozen in attacker-controlled addresses and has not been moved.

More recently, smaller opportunistic attackers have entered the fray, with repeated attempts to launder funds through THORChain and overseas casinos, he added.

Most of the affected assets belonged to long-term Bitcoin holders. The average dormancy period of the stolen Bitcoin was 3.18 years, indicating the attack mainly hit coins kept in self-custody rather than with crypto exchanges or decentralized finance protocols.

Restrictions tied to U.S.-developed LLMs have forced investigators to rely on open-source Chinese AI models while tracing and protecting stolen funds, Thorn wrote. He said he would raise the related regulatory issues with senior U.S. government and industry officials.

Galaxy Research is collecting victim reports and attacker address data and sharing them with U.S. law enforcement and industry participants as it continues its investigation.

#Crypto Hack
#Hardware Wallet

cow5361@bloomingbit.ioHello, I'm a reporter at bloomingbit

What do you think about this news?








PiCK News






Hashtag News