Coldcard exploit was the worst for Canadian holders - AltcoinDaily.co
featured-image

The Coldcard wallet exploit has affected Canadian holders the most, with 25% of the attributed losses tracked down to Canadian users. Chainalysis explains that the disproportionate effect of Coldcard was due to local popularity, boosted by influencer campaigns.

Chainalysis used on-chain data and available connections to exchanges to link the Coldcard address database to the most likely regions. Canada has been known for early Bitcoin adoption and influencers promoting Bitcoin maximalism, resulting in an even wider adoption of the wallet with inadequate entropy and vulnerable address generation. 

The USA and Thailand are also heavily hit by the ongoing exploits, based on Chainalysis data.

As Cryptopolitan reported earlier, the attack against Coldcard has affected general BTC sentiment and the trend of self-custody.

Estimated losses from the Coldcard hack range from over $110M to $150M, according to other estimates. 

Red Team tries to limit Coldcard and other similar attacks

The Coldcard attacks led to one of the biggest drives to discover vulnerabilities in the Bitcoin ecosystem. 

In the early days after the Coldcard exploit, some of the funds were moved in white-hat hacking attempts. The Red Team initiative scales that approach, using AI analysis to find similar vulnerabilities. 

The Red Team has spent over $20,000 on tokens, and has secured further funding to continue its work. Rob Hamilton, CEO of AnchorWatch, is spearheading the initiative. The initiative has scanned 150 code repos to date, and tries to contact all related parties. 

The Red Team has reached out to OpenAI to run Cyber Harness, a more thorough model of scanning for vulnerabilities for the most critical elements of the Bitcoin ecosystem. 

Additional reports include the usage of the free Kimi K3 model to find flaws in crypto codebases. The current initiative also reveals the new opportunities in unleashing AI attacks, where threat actors find the vulnerabilities first.          

The recent attacks happened just as some of the most widely used AI models decreased their pricing, causing the steepest weekly decline for the year. Free models also made AI-assisted attacks easier. 

Red Team has reported discovering roughly one serious or critical vulnerability for each hour of its AI-assisted audits. The team deploys its testing harnesses to crypto libraries, wallets, and infrastructure, contacting several Bitcoin-related projects in the past 12 hours. 

Coldcard attack may be spread to 15 different entities

The Coldcard attack is not limited to one threat actor, but to multiple entities. Once the vulnerability became known, many threat actors succeeded in draining exposed wallets. 

According to Alex Thorn, head of Firmwide Research, the attack came in multiple waves, with the first attack being the biggest. 

The ongoing attack stole over 1,816 BTC from 5,200 affected addresses, according to Onchain Lens. Initially, the stolen funds were considered frozen. Unlike other crypto attacks, where mixing happened within hours of the exploit, most of the BTC sits in destination addresses. 

On-chain reports show one wallet with around 64 stolen BTC may have engaged in early mixing. The wallet performed a series of transactions, where 10 BTC were mixed, and 54 BTC were moved to a new address. 

For now, most of the destination wallets have been tagged by law enforcement, but mixing can make some of the funds unreachable.

All Coldcard owners are urged not just to update the firmware, but to generate a new safe wallet seed, then move funds while assigning a higher transaction fee. Some funds have been salvaged by paying more and front-running the attacker’s transaction.

If you’re reading this, you’re already ahead. Stay there with our newsletter.