A Coldcard attacker is holding 1,159 BTC, according to Galaxy Research. The funds remain spread across seven addresses associated with the attacker and have not moved since the initial sweep. However, a separate attacker has started routing smaller amounts through a mixer, with 64 BTC entering a transaction flow linked to a mixer.
Mixer Activity
Analysts tracked the mixer activity, which involved combining or restructuring transactions to make it harder to connect the original source of cryptocurrency with its eventual destination. Approximately 10 BTC was initially mixed, while about 54 BTC returned as change.
Coldcard Vulnerability
The Coldcard vulnerability resulted from a firmware error that weakened the randomness used to generate wallet seed phrases. Attackers could reproduce possible seeds offline, derive their Bitcoin addresses, and compare them with addresses visible on the blockchain. Coinkite has released corrected firmware, but an update cannot secure a seed phrase generated using a vulnerable version. Affected users must create an entirely new seed and transfer their Bitcoin to addresses derived from it.



