Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider: Report
A thief stole over $70 million in Bitcoin from Coldcard devices by exploiting a firmware bug. The thief used a top blockchain services provider to query source addresses and perform other related activity during the sweeps.
Intelligence analysis by Llama

A thief stole over $70 million in Bitcoin from Coldcard devices by exploiting a firmware bug. The thief used a top blockchain services provider to query source addresses and perform other related activity during the sweeps. Experts warn that more Bitcoin addresses could be at risk.
Imagine you have a special kind of safe that keeps your Bitcoin secure. But, what if someone found a way to guess the combination to that safe? That's basically what happened with the Coldcard devices. A thief used a special service to help them guess the combination and steal over $70 million in Bitcoin. Experts are warning people to move their Bitcoin to a safer place to avoid getting hacked.
Analysis
A $60B Vote of Confidence
The recent theft of over $70 million in Bitcoin from Coldcard devices has sent shockwaves through the cryptocurrency community. The thief exploited a firmware bug in the devices' system, which allowed them to brute-force private keys for single-signature wallets. The bug, which affects all Coldcard models, was first introduced in March 2021 with the release of version 4.0.1. This vulnerability has been identified as a major security risk, and experts warn that more Bitcoin addresses could be at risk.
Why Cursor?
Experts have been investigating the theft and have identified an unusual pattern in the sweeps. This pattern led them to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps. The authorities have been notified, and the incident is being treated as a serious security breach.
The Road Ahead
The theft has highlighted the importance of secure custody and the need for users to move funds out of single-signature Coldcard addresses and into secure custody. Coinkite, the company behind the Coldcard devices, has released a fixed firmware update to address the vulnerability. However, experts warn that the incident is a reminder of the importance of security and the need for users to take proactive steps to protect their funds.
Key points
- A thief stole over $70 million in Bitcoin from Coldcard devices by exploiting a firmware bug.
- The thief used a top blockchain services provider to query source addresses and perform other related activity during the sweeps.
- Experts warn that more Bitcoin addresses could be at risk due to the vulnerability.
- Coinkite has released a fixed firmware update to address the vulnerability.
- Experts are warning people to move their Bitcoin to a safer place to avoid getting hacked.
If the incident is handled properly, it could lead to increased security measures and awareness among users, ultimately making the cryptocurrency space a safer place.
The theft could lead to a loss of trust in Coldcard devices and potentially even the entire cryptocurrency market, causing a significant decline in value.



