Chainalysis: Coldcard exploit attacker hit biggest wallets first; Block says probe mapped sweeper workflow

AI Market Summary
Chainalysis' findings on a $38M+ Coldcard-related wallet sweep highlight targeted profiling and rapid, large-scale theft, reinforcing operational and custody risks in self-custody and wallet infrastructure. Block's investigation indicates the attacker used a paid blockchain services account to query victim addresses, with logs corroborating the workflow but no evidence of provider complicity. Near term, this can weigh on crypto risk appetite and increase scrutiny of wallet tooling and monitoring.
Impact level
● Medium
Affected assets
BTC/USDT-2.97%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Chainalysis said its review of the more than $38 million Coldcard exploit indicates the attacker systematically targeted the largest wallets first, including one containing $1.8 million, pointing to victim profiling before the sweep began. About $30 million was taken in the first 10 minutes, followed by the draining of roughly 500 wallets over the next 25 minutes. Block's Clay Garrett said investigators also determined the attacker used a paid account with a well-known blockchain services provider to query victim addresses during the operation. Block said the provider's internal logs aligned with the timing and order of the requests, and added it found no evidence the firm knowingly aided the theft. Block said it has shared relevant information with authorities.