New Research Details How Coldcard Attackers Prioritized Rich Wallets

New Research Details How Coldcard Attackers Prioritized Rich Wallets

N
News Editor
2026-08-13 21:39:51
According to Bitcoin News, new research by @PraveenPerera details how Coldcard attackers operated: they first identified vulnerable addresses, then sorted them by bitcoin holdings and began transferring funds from the highest-balance addresses. The tool used was rough — in one address with 225 spendable UTXOs, it pulled exactly the 200 newest records, matching a blockchain API's default 200-record limit and suggesting the attacker may not have loaded the next page. The software also spent a 294-satoshi UTXO, increasing transaction fees by around 2,040 satoshis. The researchers conclude the builder understood balance systems better than Bitcoin's UTXO model. Despite the attacker seemingly obtaining full seeds, at least 75 BTC remain in other addresses derived from those seeds; 132.95 BTC still sit in 153 stolen addresses, and the seeds cannot be reproduced, leaving open the possibility of undisclosed private device data.
New research by @PraveenPerera, as reported by Bitcoin News, offers a closer look at how attackers moved money out of Coldcard wallets. The study suggests the attackers first singled out vulnerable addresses, then sorted them by bitcoin holdings and began transferring funds from the addresses with the largest balances. The tool actually used for the transfers was fairly rudimentary. One example stands out. An address held 225 spendable UTXOs. The attacker withdrew exactly the newest 200, leaving the earliest 25 — including a UTXO worth 0.16 BTC — untouched. That pattern matches the default 200-record return limit of a blockchain API the researchers looked into. It appears the attacker may never have loaded the next page of data. The software also spent a 294-satoshi UTXO, reportedly inflating transaction fees by about 2,040 satoshis, a cost far greater than the UTXO's own value. The authors see this as evidence that the tool's builder may have a stronger grasp of account balance systems than of Bitcoin's UTXO model. Even though the attacker seems to have obtained the victim's full seed phrase, at least 75 BTC remain in other addresses derived from that same seed. The biggest puzzle: 132.95 BTC still sit in 153 stolen addresses. Researchers have been unable to reproduce the seeds behind those addresses, so they have not ruled out the possibility that the attacker gained access to undisclosed private device data or candidate data.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
360

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.