Coldcard Hacker Gets Brazen Bitcoin Laundering Offer Onchain

2 hours ago

The Coldcard information incidental entered different section aft a nationalist bitcoin transaction offered laundering services to the thief down 1 of the largest self-custody bitcoin thefts ever recorded, portion users besides reported exigency firmware updates leaving immoderate hardware wallets unusable.

Key Takeaways

  • Coinkite thefts reached 1,359.8820 BTC aft caller onslaught waves done Aug. 2.
  • OP_RETURN carried a 10% laundering connection to the Coldcard hacker connected Aug. 1.
  • Coldcard users await Coinkite guidance arsenic firmware bricking reports continue.

The caller developments travel conscionable days aft Coinkite disclosed that a long-dormant firmware flaw had allowed attackers to retrieve weakly generated wallet seeds and systematically drain susceptible single-signature wallets. The estimated full has present climbed to astir 1,359.8820 BTC, according to stats collected by the Coldcard Sweep Watch dashboard, with astir of the identified coins remaining successful a fistful of addresses nether the attacker’s control.

OP_RETURN Turns the Bitcoin Blockchain Into a Public Bulletin Board

On Aug. 1, 1 of the attacker’s holding addresses received an unusual transaction containing an OP_RETURN message. OP_RETURN is simply a peculiar Bitcoin transaction output that stores imperishable substance connected the blockchain alternatively than transferring spendable funds.

mempool.space screenshot. Onchain connection sent to the hacker’s wallets. Speculators wonderment if it is simply a superior connection oregon a honeypot. Image source: mempool.space.

The connection openly advertised services to “clean” bitcoin, supply know-your-customer (KYC) assistance, and currency retired the stolen coins successful speech for a 10% fee, on with a Telegram contact. It was not a method connection oregon a unfortunate appeal. Instead, it appeared to beryllium a nonstop solicitation aimed astatine whoever controls the stolen bitcoin. Some suggest it could beryllium instrumentality enforcement oregon idiosyncratic mounting a trap.

Attack Leaves Most Stolen Bitcoin Sitting successful Plain Sight

Although the theft progressive much than 1,300 BTC, blockchain researchers person observed that overmuch of the bitcoin remains mostly untouched. The attacker consolidated funds into a comparatively tiny fig of addresses aft sweeping susceptible wallets during respective coordinated waves opening connected July 30.

That visibility has go 1 of the much antithetic aspects of the case. Bitcoin’s transparent ledger allows anyone to show high-value addresses, meaning victims, investigators, researchers, and adjacent opportunists tin each ticker the aforesaid transactions unfold successful existent time. OP_RETURN messages show that the blockchain tin besides relation arsenic a imperishable nationalist messaging strategy during large incidents.

Several projects that person been hacked successful the past usage OP_RETURN messages to sermon bounties and demands with hackers.

Emergency Firmware Fix Creates New Headaches

As users rushed to unafraid their remaining funds, different occupation emerged.

Coinkite released exigency firmware updates designed to destruct the anemic random fig procreation that caused the archetypal vulnerability. The institution made wide that the caller firmware lone protects wallets created successful the aboriginal and does not repair seeds already generated connected susceptible versions.

X screenshot. Image source: X

Soon aft the release, users began reporting that immoderate devices became stuck connected mistake screens, failed to footwear oregon appeared wholly bricked aft installing the update. Reports person chiefly progressive Mk4 and Q devices, though immoderate Mk3 users person besides described akin problems. As of Aug. 2, Coinkite had not publically confirmed a wide firmware defect, but respective idiosyncratic reports person fueled increasing interest passim the Bitcoin community.

Security Experts Push Users to Move Funds First

One of the strongest messages circulating among experienced bitcoin information advocates is that owners of perchance susceptible wallets should migrate funds earlier updating firmware whenever possible.

That proposal reflects an important regulation of the exigency patch. Updating bundle cannot fortify a anemic effect that was already created years ago. If the archetypal wallet was generated with insufficient randomness, the lone lasting solution is to determination funds into an wholly caller wallet created with beardown entropy.

For galore users, verified effect backups person go the quality betwixt a hardware nonaccomplishment and imperishable loss, since a damaged instrumentality tin often beryllium replaced portion the betterment operation restores entree to the funds.

Confidence Faces Its Biggest Test Yet

The ongoing Coldcard incident has evolved beyond a azygous firmware flaw into a broader trial of assurance successful hardware wallet security. The operation of a historical entropy bug, a nationalist laundering solicitation embedded straight connected Bitcoin’s blockchain and reports that exigency updates whitethorn ceramic immoderate devices has intensified statement implicit wallet design, effect generation, and semipermanent self-custody practices.

While monitoring of the known attacker addresses continues, users are present watching 2 developments conscionable arsenic closely: whether the stolen bitcoin yet moves and whether Coinkite issues further guidance for customers experiencing firmware failures.

View source