Hacker Coldcard Receives Brazen Bitcoin Money Laundering Proposal on the Blockchain
Coldcard, a Bitcoin hardware wallet, faced a significant security breach a few days after Coinkite disclosed a long-undetected firmware vulnerability. The flaw allowed attackers to recover weakly generated wallet seeds, systematically draining vulnerable single-signature wallets. According to Coldcard Sweep Watch, total losses have reached approximately 1,359.882 BTC, with most stolen funds still concentrated on addresses controlled by the attacker.
An unusual event occurred on August 1st when a transaction containing an OP_RETURN message was sent to one of the attacker's addresses. This message openly advertised money laundering services, offering help with KYC procedures and cashing out stolen coins for a 10% fee, and included a Telegram contact. This has led to speculation that it could be a serious offer, a trap, or possibly even law enforcement.
Despite the theft of over 1,300 BTC, blockchain researchers note that the majority of the funds remain unmoved on a small number of addresses, making the stolen coins highly visible on Bitcoin's transparent ledger.
In response, Coinkite released emergency firmware updates to fix the weak random number generator responsible for the vulnerability. However, the update only protects newly created wallets and does not fix seeds already generated by vulnerable versions. Furthermore, users began reporting that the update caused some Mk4 and Q devices (and some Mk3) to freeze, display errors, or become completely inoperable. Coinkite has not yet publicly confirmed a widespread firmware defect.
Security experts are strongly advising users of potentially vulnerable wallets to move their funds to a new, securely generated wallet *before* applying any firmware update, as the patch cannot strengthen an already weak seed.
This incident has evolved into a major test of trust in hardware wallet security, highlighting concerns about wallet design, seed generation, and long-term self-custody practices. The community is now closely watching to see if the stolen Bitcoin will be moved and if Coinkite will issue further guidance for affected customers.
cryptonews.ru08/03 09:37