Alex Thorn, head of research at Galaxy, confirmed the transfers began on September 3, noting that the perpetrator encountered repeated technical hurdles. The protocol frequently refunded the attacker’s swap attempts, forcing them to resubmit transactions. While the exact cause of these failures remains unconfirmed, analysts suspect liquidity constraints or internal protocol safeguards may be responsible. Researchers have successfully traced the funds to a new Ethereum address and shared this destination with law enforcement and various crypto service providers to monitor for further laundering.
Despite the activity, approximately 90% of the funds from the third wave remain stationary at their original addresses. Galaxy Research estimates that a total of 1,789.28 BTC—valued at roughly $114.7 million at the time of the breach—was compromised across 8,865 addresses due to a firmware vulnerability that limited the randomness of seed generation. Coinkite, the manufacturer of Coldcard, has repeatedly warned that firmware updates alone cannot secure compromised wallets. Users are required to generate entirely new seeds and migrate their assets, as the existing private keys remain mathematically discoverable by attackers using automated scanning tools.

Comments (0)
No comments yet. Be the first!