Security Alert: Coldcard Attack Ongoing, Users Should Immediately Migrate Funds from Affected Addresses
August 2nd, Coldcard Hacked, with the stolen funds now totaling 1367.05 BTC, worth approximately $88.6 million, involving 4585 addresses. Galaxy Research Director Alex Thorn stated that the attack is still ongoing, and users who have not yet moved their funds should immediately withdraw their assets from addresses generated by Coldcard. He also urged affected users to voluntarily provide information to help trace the stolen funds and report to law enforcement.
Thorn stated that the previously confirmed three large-scale attacks have obvious programmatic characteristics, with similar transaction patterns that may have been orchestrated through automation; the related stolen BTC is currently still in the attacker's addresses and has not been transferred. However, smaller opportunistic attackers have recently emerged, who will transfer and launder funds within a few hours, with some funds flowing to overseas gambling platforms through cross-chain services like ThorChain.
All Coldcard single-signed addresses generated after the firmware upgrade in March 2021 may eventually be compromised, and users should complete the migration as soon as possible. The stolen funds have been inactive for an average of 3.18 years, with a median of 3.55 years, mainly affecting long-term holders.
Thorn stated that most of the discovered stolen assets have not yet moved, and the related addresses have been provided to U.S. law enforcement and industry contacts. He believes that this incident is a significant blow to Bitcoin self-custody, and the industry needs to improve security, education, and risk warnings about the complexity of self-custody.