New details are emerging about how the attacker behind the Coldcard hardware wallet exploit identified and drained vulnerable addresses. Clay Garrett, an engineer at payments company Block, says the thief used a paid account at a well-known blockchain-services provider to query source addresses and coordinate sweep transactions, rather than relying on a purpose-built tracking system.
The theft has grown considerably since it first came to light: an initial drain of roughly $35 million on Thursday was followed by additional sweeps that pushed the total above $70 million.

How the attacker found the money
Garrett described the investigative process that led to the finding: "The pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider." The provider's identity has not been publicly disclosed, at its own request, though Garrett said the relevant authorities have been notified.
The underlying vulnerability affects Coldcard Mk3 devices running firmware versions 4.0.1 and later, dating back to March 2021. Rather than using the device's dedicated hardware random number generator, affected units fell back to weaker software-based randomness during seed generation. That weakness made private keys predictable enough to reconstruct through brute-force methods, particularly for single-signature wallets that lacked dice-roll entropy or a strong BIP-39 passphrase.
Galaxy Digital confirms a single operator
Galaxy Digital's research team, which has been tracking the theft's on-chain footprint, described the pattern of transactions as "unusual" and confirmed the sweeps were "all the same attacker." The firm is recommending that Bitcoin holders move funds out of single-signature Coldcard addresses generated on vulnerable firmware and into new, securely generated wallets.
Scope has widened beyond initial reports
What began as reports focused on the Mk3 line has since expanded: subsequent thefts revealed that all Coldcard models were vulnerable to the same underlying flaw, not just the originally implicated hardware. Coinkite, the company behind Coldcard, has released emergency firmware updates and is urging affected users to generate entirely new seeds on patched devices rather than treat the update itself as sufficient protection for keys already exposed.