Coldcard exploit: more than $30 million stolen in first 10 minutes

AI Market Summary
Chainalysis-linked analysis of a Coldcard vulnerability exploit indicates attackers pre-profiled high-value wallets and stole roughly $30M within 10 minutes, later draining about 500 wallets. Use of a paid account at a major blockchain service provider to query victim addresses highlights operational sophistication and potential privacy/metadata leakage risks. The incident can weigh on near-term crypto risk appetite and increase scrutiny of self-custody security practices.
Impact level
● Medium
Affected assets
BTC/USDT-2.97%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ChainCatcher reports that, based on Bitcoin News monitoring, Chainalysis reviewed the Coldcard exploit linked to more than $38 million in losses and found signs of pre-targeting. The attackers moved on the largest-value wallets first, including one holding $1.8 million, suggesting victims had been profiled before transfers began. Roughly $30 million was taken in the first 10 minutes, and about 500 additional wallets were drained over the following 25 minutes. Block's Clay Garrett said investigators also confirmed the attackers used a paid account from a well-known blockchain service provider to look up victim addresses during the operation. The provider's internal logs matched the timing and sequence of the queries, and Block said there is no evidence the company knew of or assisted in the theft. The information has been shared with authorities.