Article URL: https://medium.com/mountain-movers/the-coldcard-disaster-gets-worse-the-hack-may-have-reached-88-6-af507b028594 Comments URL: https://news.ycombinator.com/item?id=4914…

Galaxy Research has identified the traces of three distinct waves in the Coldcard firmware vulnerability, in which nearly 1,367.05 BTC has been stolen across 4,585 addresses. That’s a massive increase from earlier estimates of the total losses of around $38 million, and it looks like the figure could be even higher as the attack continues. What’s very telling about this attack is that the person or people responsible seem to be maintaining a level of operational discipline. In all of the known transactions generated by the exploit, the attacker hasn’t spent any of the stolen coins. The coins have been accumulated in 4,585 addresses, which have been left unspent so far despite the high value of the deposits. Galaxy Research’s findings come from reviewing the patterns of transactions generated by the exploit rather than direct evidence that the hacking was done by taking control of the Coldcard hardware. As such, there’s still a chance that the actual total loss caused by this attack could be even higher than the current figure of $88.6 million. On one hand, that doesn’t really matter because the damage has already been done as the exploit has been carried out over the last few weeks, and more than 4,500 addresses have been compromised. It’s a possibility that is worth considering though, as the situation could evolve further before the attack is fully realized. The main takeaway here is that the exploit has raised new questions about the security of hardware wallet custody options, and it’s having an extremely negative impact on the psychological outlook of a large number of Bitcoin holders. The first public indication that something was very wrong came when Jonathan closely examined the internal workings of his old Coldcard and found his 18.25 BTC mysteriously drained. That’s where it all started, but it’s important to step back and consider the broader picture. According to the research carried out by Galaxy Research, the same exploit has been used to empty out 4,585 addresses so far. These are highly impressive figures, and they tell us what the exploit has the capability of becoming. It also needs to be taken into consideration that it’s extremely difficult to categorically prove that the firmware vulnerability was the means by which this exploit took place. We still don’t have any evidence that demonstrates direct control over the Coldcard hardware by the attacker. Instead, the exploits involved are a series of distinct thefts that appear to have been carried out using a specific tool. These facts mean it’s still possible that some of these exploits are not actually linked to the Coldcard firmware hack. There are multiple reasons, both statistical and anecdotal, to believe otherwise, however. While we are still dealing with bits of information rather than definitive proof, it seems clear that whoever is carrying out these exploits is targeting the same attack vector each time. That doesn’t necessarily mean that the firmware was compromised, but statistics point in that direction. While any rumors that we hear should be treated with caution, the sheer scale of the Coldcard thefts points in the general direction of a specific and targeted exploit of a key space. Someone is scanning a specific range of addresses and finding Coldcards hidden in there, and then extracting the coins. According to Galaxy Research’s findings, the exploit appears to have taken place in three waves, which can be broken down like this: Wave 1: July 30, with 1,195 addresses drained for 1,082.65 BTC. The first wave of the exploit targeted a significant number of high-value addresses, which is one reason why this round of the attack stands out as the major theft from the exploit so far.