Bullish

Coldcard Exploit Drains $30M in 10 Minutes, Attacker Targets High-Value Wallets First

2026-08-01 05:05:17

Chainalysis data reveals a Coldcard vulnerability led to $38M+ theft, with $30M stolen in the first 10 minutes as attackers prioritized high-balance wallets using pre-profiled data.

Woofun AI reports that Chainalysis analysis of the Coldcard exploit indicates over $38 million was stolen, with approximately $30 million extracted within the first 10 minutes. The attacker systematically targeted the highest-value wallets first, including one holding $1.8 million, suggesting victims were profiled prior to the asset transfers. Around 500 wallets were drained within 25 minutes. Block's Clay Garrett confirmed investigators found the attacker used a paid account with a major blockchain service provider to query victim addresses during the operation. Internal logs from the provider matched the request timestamps and sequence, though Block stated no evidence suggests the company knowingly assisted in the theft. Relevant information has been shared with authorities.

WOOFUN AI

Impact Assessment · Quick Read

The rapid extraction of $30 million in the initial 10 minutes highlights sophisticated pre-exploit reconnaissance, likely involving off-chain data leakage or API abuse. The use of a legitimate blockchain service provider for address querying raises concerns about potential weaknesses in API rate-limiting or identity verification protocols. While the provider denies complicity, the incident underscores the critical need for enhanced monitoring of high-frequency address lookups linked to known hardware wallet vulnerabilities.
Generated by WOOFUN AI · For reference only, not investment advice

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions