خبری درباره‌ی پیث نتورک (PYTH)

Coldcard Attacker Moves 45% of Wave 3 Bitcoin Through CoinJoin

36Crypto ۸ روز پیش خلاصه‌ی فارسی · ۴۵۱ کلمه
Coldcard Attacker Moves 45% of Wave 3 Bitcoin Through CoinJoin

Summary Coldcard attacker moved 97.09 BTC through CoinJoin, representing 45% of assets stolen during the third identified wave within the campaign. A 2021 firmware flaw weakened wallet seed randomness, allowing attackers to brute-force private phrases and drain single-signature Bitcoin wallets remotely. Galaxy linked 1,806 BTC worth $143.9 million to the exploit, while 82% remains inside original attacker-controlled addresses under blockchain monitoring. The attacker behind the Coldcard hardware wallet exploits has moved 45% of the Bitcoin stolen during the third attack wave. According to Galaxy Research, the Wave 3 operator transferred 97.09 Bitcoin (BTC), worth approximately $7.8 million. The exploiter processed those assets through CoinJoin transactions, making the movement of stolen funds harder to trace. CoinJoin combines several Bitcoin payments within one transaction, reducing the visibility of links between senders and recipients. However, Galaxy’s analysis indicates that the attacker follows a calculated order when selecting compromised wallets. The operator has targeted the affected vaults according to their balances, beginning with wallets holding the largest amounts. Vaults ranked between one and eleven have already recorded movements linked to the laundering operation. Meanwhile, the next ten untouched vaults contain a combined 30.81 BTC, based on Galaxy’s findings. Another group of smaller vaults, ranked between 61 and 293, collectively holds 33.77 BTC. This transfer pattern provides investigators with possible indicators regarding which compromised wallets the attacker could target. Coldcard ‘Wave 3’ exploiter continues to move funds In wave 3, the exploiter created 293 2-of-2 multisig vaults for each victim’s coins. The first movements on 9/2 sent coins over THORChain to Ethereum. Tonight’s movements are going into coinjoins rounds. pic.twitter.com/H7HIpcI7ah — Galaxy Research (@glxyresearch) September 7, 2026 Before using CoinJoin, the exploiter converted stolen Bitcoin (BTC) into Ethereum (ETH) through THORChain on September 2. THORChain allows users to exchange assets across different blockchains without relying on a centralized cryptocurrency exchange. The conversion marked another effort to separate the stolen assets from their original Coldcard addresses. Galaxy reported that 82% of all stolen funds remain inside the attacker’s original wallets. Consequently, only 18% has moved through transactions that appear connected to laundering or asset conversion activities. Also Read: PYTH Price Prediction 2026–2030: Can Pyth Network Reach $0.20 Soon? Coldcard Firmware Bug Weakened Wallet Seed Generation The Coldcard thefts began on July 30 and originated from a firmware flaw that Coinkite shipped in 2021. The vulnerability affected the method that certain Coldcard devices used to generate wallet seeds for their owners. These devices produced seed phrases with insufficient randomness, weakening the security protecting corresponding private keys. Attackers could therefore brute-force vulnerable seed phrases and identify the Bitcoin addresses linked to those phrases. Significantly, the attackers drained single-signature wallets without physically obtaining or interacting with the affected Coldcard devices.

عنوان اصلی (انگلیسی): Coldcard Attacker Moves 45% of Wave 3 Bitcoin Through CoinJoin

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به پیث نتورک

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.