The amount of bitcoin tied to the Coldcard security incident has risen to about 1,359.882 BTC, according to figures tracked by the Coldcard Sweep Watch dashboard. The data shows that most of the identified funds remain parked in a small number of addresses controlled by the attacker.
On Aug. 1, one of those holding addresses received a transaction carrying an OP_RETURN message. The message openly offered services to "clean" the stolen bitcoin for a 10% fee, assist with KYC, and cash out the proceeds, while also providing a Telegram contact.
Coinkite, the hardware wallet maker behind Coldcard, has released an emergency firmware update to address the weak random number generation issue that caused the vulnerability. The company said the new firmware can protect only wallets created in the future and cannot repair seeds that were already generated on affected versions.
Some users have also reported device problems after installing the update, including units stuck on an error screen, failure to boot, or suspected bricking. Reports have mainly involved Mk4 and Q devices, with some Mk3 users describing similar issues. As of Aug. 2, Coinkite had not publicly confirmed any widespread firmware defect.
In the Coldcard security incident involving hardware wallet maker Coinkite, the amount of stolen bitcoin has climbed to about 1,359.882 BTC.
Figures from the Coldcard Sweep Watch dashboard show that most of the identified bitcoin remains in a small number of addresses controlled by the attacker.
Attacker-linked address received a laundering pitch
On Aug. 1, one address holding the funds received a transaction containing an OP_RETURN message. That message publicly offered to "clean" the bitcoin for a 10% fee, help with KYC, and cash out the stolen proceeds. It also included a Telegram contact.
Emergency firmware update released
Coinkite has issued an emergency firmware update to remove the weak random number generation flaw behind the original vulnerability. The company said the new firmware protects only wallets created going forward and cannot fix seeds that were generated on affected versions.
Users report problems after installing the update
Some users said their devices remained stuck on an error page after the update, would not boot, or appeared to be bricked. The reports mainly involved Mk4 and Q devices, though some Mk3 users described similar problems. As of Aug. 2, Coinkite had not publicly confirmed any large-scale firmware defect.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.