Register and share your invite link to earn from video plays and referrals.

Galaxy Research
@glxyresearch
$GLXY | Newsletter | Podcast | Reports Disclaimer:
Joined May 2019
75 Following    23.3K Followers
We have completed a review of every Bitcoin transaction in the past 30 days and have identified NO additional transactions that match this pattern. The analysis below captures the totality of transactions matching this fingerprint. However, the nature of the vulnerability means that future attacks are possible on any Coldcard-generated address and those do not need to match this pattern. (The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins.) Stay vigilant and move coins out of single-signature Coldcard addresses and into secure custody, either at a custodian or exchange you trust or into a multisig self-custody setup.
Show more
We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett 1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks 960,183-960,191. That preceded the hardware-wallet vendor's public advisory by ~30 hours. Signature: every sweep paid an identical hardcoded 30.0 sat/vB — a 30-75x overpay vs the 0.4-1.0 sat/vB median that week — and left no change output. That looks like an automated tool spending keys it already held, not owners moving funds. Victims: 1,183 native segwit (BIP-84), 7 BIP-49, 6 BIP-44 — consistent with multi-path key scanning. Proceeds consolidated within minutes and have NOT moved since: - bc1qq85v2c9...cu9r — 562.02 BTC - bc1qx76cae2...fhe3 — 398.48 BTC - bc1q8jy96fe...tp3q — 89.62 BTC - bc1qnk4zh9q...fecp0 — 32.45 BTC (unmoved)
Show more