Approximately $100 million in Bitcoin and Ether was stolen from 7,300 wallets following a Coldcard exploit. The initial drain occurred across three attack waves, with subsequent transfers totalling $4.17 million in Bitcoin and $380,000 in Ether utilising cryptocurrency mixing protocols. Traceability efforts are currently underway, focused on monitoring transactions within attacker-controlled wallets.
Further complicating the situation is the identification of approximately 64 BTC transferred to Wasabi, a crypto mixer, and 200 ETH sent to Tornado Cash, another privacy protocol. The attacks began following a firmware bug discovered in March 2021 that weakened seed randomness on certain Coldcard wallets, reducing the strength of security keys.
Initial analysis by CertiK, a blockchain security platform, assessed the situation, while TRM Labs is conducting on-chain tracing to identify the perpetrators. Haseeb Qureshi, Managing Partner at Dragonfly, has suggested potential preventative measures involving artificial intelligence, estimating that approximately $2 could have been spent on AI hardening to mitigate the vulnerability.
The timeline of the attacks began with a Bitcoin transfer to Wasabi on Tuesday and continued with the 200 Ether transfer to Tornado Cash on Wednesday. A TRM Labs report was published on Thursday following these events. Investigators are examining differences in transaction construction across attack waves, reportedly suggesting multiple attackers.
A suspected fourth wave could potentially increase total losses to around $130 million in Bitcoin. This remains unconfirmed, yet highlights the ongoing risk associated with the exploit. The full extent of the attack and the precise number of individuals involved remain under investigation, adding to the complexity of the situation.
Continued monitoring by TRM Labs is crucial as they attempt to discern the structure behind these attacks. The movement of funds through Wasabi and Tornado Cash provides an avenue for potential recovery efforts. Efforts to pinpoint multiple attackers are ongoing.
Written by Daniel Brooks
Security Desk