Back to News
Coldcard Attackers Appear to Target Vulnerable Addresses in BTC Theft Campaign
By Exbasi Intelligence
Sourced from Binance News
New research shared by @PraveenPerera and monitored by Bitcoin News suggests Coldcard attackers first identified vulnerable addresses, then ranked them by the amount of bitcoin held and transferred funds in batches starting with the largest balances. According to ChainCatcher, the transfer software used in the operation appeared crude, and researchers said it may have only partially loaded address data.In one case, an address with 225 spendable UTXOs saw attackers extract the newest 200 and leave the oldest 25, including a UTXO worth 0.16 BTC. The pattern matched a blockchain API limit that returns 200 records by default, leading researchers to suspect the attacker failed to load the next page of results. The software also spent a 294-satoshi UTXO, reportedly increasing the transaction fee by about 2,040 satoshis and making the spent amount far exceed the UTXO’s own value.The study’s author said the tool’s builder may have understood account-based balances better than Bitcoin’s UTXO model. Although the attackers appear to have obtained the victim’s full seed, at least 75 BTC remained in other addresses derived from the same seed. Researchers also said 132.95 BTC remained in 153 stolen addresses, and they could not yet reproduce the seed behind those addresses, leaving open the possibility that the attackers obtained undisclosed private device data or candidate data.