New research flagged by Bitcoin News shows the Coldcard attacker identified vulnerable addresses, ranked them by bitcoin holdings, and began moving funds from the largest balances first. The transfer tool used appears crude: from one address with 225 spendable UTXOs, it pulled only the newest 200 and left the oldest 25, including a 0.16 BTC UTXO. That matches the default 200-record limit of a blockchain API the researchers looked at, suggesting the attacker may have failed to load the next page of data. The software even spent a 294-satoshi UTXO, reportedly adding about 2,040 satoshis in fees. While the attacker likely obtained full seeds, at least 75 BTC remain in other addresses derived from the same seeds, and 132.95 BTC still sit across 153 compromised addresses. Researchers cannot reproduce the seeds behind those addresses, and have not ruled out access to unpublished private device data or candidate data.
New research flagged by Bitcoin News shows the Coldcard attacker appears to have identified vulnerable addresses first, then ranked them by bitcoin holdings and started transferring funds from the addresses with the largest balances.
The actual transfer software was fairly crude. One address held 225 spendable UTXOs, and the attacker pulled exactly the newest 200, leaving the oldest 25 behind, including a UTXO worth 0.16 BTC. That matches a 200-record default limit found in a blockchain API the researchers examined, suggesting the attacker may not have loaded the next page of data.
The software even spent a 294-satoshi UTXO, reportedly pushing transaction fees up by around 2,040 satoshis, an amount clearly exceeding the UTXO's own value. The researchers argue the tool's builder may have understood account balance systems better than Bitcoin's UTXO model.
Even though the attacker appears to have obtained the victims' full seeds, at least 75 BTC remain in other addresses derived from the same seeds.
The biggest open question: 132.95 BTC still sit across 153 stolen addresses, and researchers cannot reproduce the seeds behind them. They have not ruled out that the attacker obtained unpublished private device data or candidate data.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.