A vulnerability in the Coldcard wallet has most affected Canadian users: 25% of all Canadian losses. Chainalysis explains that Coldcard's disproportionate impact is due to its popularity in the region, aided by influencer-led promotional campaigns.
Chainalysis used blockchain data and available exchange connections to link the Coldcard address database to the most likely regions. Canada is known for early Bitcoin adoption and influencers promoting Bitcoin maximalism, which led to an even wider spread of the wallet with insufficient entropy and vulnerable address generation.
According to data from Chainalysis, the United States and Thailand were also heavily affected by the ongoing attacks .
As Cryptopolitan reported, the Coldcard attack impacted the overall sentiment towards $BTC and the trend of self-custody.
According to other estimates, losses from the Coldcard hack range from $110 to $150 million.
Red Team Initiative Aims to Limit Coldcard and Similar Attacks
The Coldcard attacks initiated one of the largest vulnerability discovery campaigns in the Bitcoin ecosystem.
In the early days after the Coldcard hack, some funds were moved as part of 'white-hat' hacking attempts. The 'Red Team' initiative is expanding this approach, using AI-powered analysis to identify similar vulnerabilities.
The Red Team has spent over $20,000 on tokens and received additional funding to continue its work. The initiative is led by Rob Hamilton, CEO of AnchorWatch. To date, the initiative has scanned 150 code repositories and is attempting to contact all stakeholders
The Red Team has asked OpenAI to launch Cyber Harness — a more thorough vulnerability scanning model for the most critical components of the Bitcoin ecosystem.
Among the additional reports is the use of the free Kimi K3 model to search for vulnerabilities in cryptographic code. The current initiative also identifies new opportunities for AI-powered attacks, where malicious actors discover vulnerabilities first.
The recent attacks occurred just as some of the most widely used AI models lowered their prices, leading to the sharpest weekly drop in a year. Free models have also simplified AI-based attacks.
The Red Team reported discovering approximately one major or critical vulnerability for every hour of its AI-assisted audits. The team is deploying its test environments in crypto libraries, wallets, and infrastructure, having contacted several Bitcoin-related projects in the past 12 hours
Coldcard Attack Could Involve Up to 15 Different Entities
The Coldcard attack involves not just one malicious actor, but many others. After the vulnerability became known, many attackers managed to drain unprotected wallets.
According to Alex Thorn, Head of Corporate Research, the attack was carried out in multiple phases, with the first attack being the largest.
The ongoing attack has stolen over 1,816 $BTC from 5,200 affected addresses. Initially, the stolen funds were believed to be frozen. Unlike other crypto attacks where funds were mixed within hours of the hack, most of the $BTC remains at the recipient addresses.
According to blockchain reports, one wallet, containing about 64 of the stolen $BTC, may have participated in preliminary mixing. The wallet conducted a series of transactions, mixing 10 $BTC and transferring 54 $BTC to a new address.
Currently, most target wallets are flagged by law enforcement, but the mixing of various wallets may render some funds unrecoverable.
All Coldcard owners are strongly advised not only to update the firmware but also to generate a new secure wallet seed phrase and then transfer their funds, setting a higher transaction fee. Some managed to save their funds by paying more and getting their transaction ahead of the attacker's.
end-content




