Galaxy Research says the largest attacker tied to the Coldcard wallet flaw still holds 1,159 BTC across seven addresses, untouched since the theft. A separate attacker has begun routing 64 BTC through a mixer, giving investigators a fresh trail, while about 600 flagged addresses now sit with law enforcement and exchanges.
The attacker behind the largest known theft tied to the Coldcard wallet vulnerability has left 1,159 BTC untouched across seven addresses, according to Galaxy Research. Investigators have not detected transfers from that cluster to an exchange, mixer, or other cash-out service since the initial sweep.
Bitcoin's protocol cannot lock an address just because analysts have flagged it, so the coins are unmoved rather than frozen. Converting them still carries risk: law enforcement agencies, exchanges and blockchain analytics firms have reportedly flagged about 600 addresses tied to the broader theft, and any transfer to a compliant exchange could trigger monitoring checks.
Second attacker starts mixing 64 BTC
A separate attacker has begun obscuring stolen funds. Analysts tracked 64 BTC entering a mixer. Roughly 10 BTC was mixed initially, while about 54 BTC returned as change and was later split into outputs of about 7 BTC each.
Analysts noted the outputs are large and consistently sized, which makes the trail easier to follow. The activity appears distinct from the cluster holding the largest stolen sum, since previous reporting found that multiple attackers may have exploited the same flaw.
A firmware flaw, not a network attack
The vulnerability stems from a firmware error that weakened the randomness Coldcard used to generate seed phrases, letting attackers reproduce possible seeds offline, derive the matching addresses, and check them against the blockchain. They needed no physical access to the devices, no PINs, and did not compromise the Bitcoin network itself.
Coinkite has released corrected firmware, but the fix cannot secure a hardware wallet seed generated before the update. Anyone affected must generate an entirely new seed and move their Bitcoin to fresh addresses.
Galaxy Research previously found attackers stole 1,596 BTC from about 7,300 addresses across three attack waves, plus 14 smaller incidents tied to the same flaw. A suspected fourth wave could raise the total to roughly 2,055 BTC, though Galaxy has not confirmed those additional losses.
Recovery remains uncertain
US authorities, exchanges and cyber-investigation groups have received Galaxy's confirmed attacker and victim addresses, and the expanding list could help them catch stolen funds if attackers use regulated services. Still, an attacker may route coins through mixers, decentralized platforms or services outside US jurisdiction before attempting a cash-out.
The new mixing activity hands investigators a fresh transaction trail, while 1,159 BTC held by the largest attacker remains exposed to continuous public monitoring.
Source: crypto.news
Trading involves risk.