Podcast

ColdCard Hack: What Alex Thorn Found On-Chain

Galaxy Research's Alex Thorn joins me five days into the ColdCard crisis to walk through the on-chain forensics: three attacker waves, ~1,500 BTC in high-confidence stolen funds, a Wave 1 identity trail, and what every ColdCard user needs to do right now.

13 min read
Alex Thorn and Marty Bent discussing ColdCard hack on-chain forensics on the TFTC podcast
Share

↓ Jump to the video and timestamps

I was at the Galaxy DC event last Thursday when the alarm first went off. I spent most of that night in a corner on my phone instead of at the party, and I've been on trains and in Spaces watching this unfold every day since. It's been a shitty week. The ColdCard RNG vulnerability has now crossed nine figures in confirmed stolen funds, and the picture is still growing.

I got Alex Thorn on as fast as I could because he and the team at Galaxy Research have done the most rigorous on-chain forensic work of anyone in the space right now. Alex runs a proprietary Bitcoin stack with what he calls "clankers" sitting on top of it, tools that let him traverse the entire UTXO history across every state the Bitcoin ledger has ever been in. He's been gathering victim reports, building out the attack topology wave by wave, and providing forensic reports back to victims they can hand to law enforcement. This conversation is the field report from the middle of an active crisis.

My bottom line before you read another word: if you have a ColdCard and you don't have ironclad confidence in your setup, move your funds right now. Not after you finish reading this. Now. The clock has been ticking since Thursday night, and every day that passes means more actors piling in.

Key takeaways

  • Move your ColdCard funds immediately. If your seed was generated on firmware released on or after March 17, 2021, and you didn't use dice rolls, your private keys may be brute-forceable. The alarm is out. More attackers are entering the field. The pace of that clock can only accelerate.
  • Galaxy Research has traced roughly 1,500 BTC in high-confidence stolen funds across three distinct attacker waves, with Waves 1, 2, and 3 coins still sitting inert in holding addresses as of recording. They haven't been laundered yet, which creates a narrow window.
  • The Wave 1 attacker may have made a critical mistake. According to Block/BitKey's published findings, they used a paid account at a blockchain infrastructure provider to query victim addresses before draining them. Authorities have been notified.
  • No multisig wallet has been confirmed breached in any of the high-confidence waves. Collaborative custody across multiple hardware devices remains the most resilient self-custody architecture available.
  • AI is the force multiplier behind this attack, and the guardrails on frontier US AI models are actively hampering defenders, forcing the Bitcoin security community to fall back on open-source Chinese models to do code review. That's insane, and something needs to give.
  • This was not user error and self-custody is not dead. The victims did everything right. A broken RNG implementation in ColdCard firmware failed them. The answer is better auditing and multisig architecture, not abandoning self-custody.

What Galaxy Research Actually Found On-Chain

Alex walked me through a Sankey chart breakdown of the three high-confidence attacker waves, what he calls "promoted" findings, meaning the evidence is strong enough that he's stating these are stolen funds, full stop.

Wave 1 is the one that got identified first, by engineers at Block (the company behind Cash App, BitKey, and Spiral). The pattern they spotted: a fixed 30 sat/vByte fee on every draining transaction, substantially above the median fee at the time. Normal wallets suggest fee rates based on confirmation targets. Normal people don't have mechanical bursts of transactions from previously unknown addresses all at exactly the same fee rate.

Wave 1 hit entirely within a 41-minute window, just after midnight UTC on July 30th. Everything in that wave looks automated, the topology, the fee structure, the mechanics of it.

The Sankey chart for Wave 1 shows many victim addresses funneling into four independent collector addresses, which then moved to three second-hop holding addresses. The coins are still sitting there. They haven't moved.

Wave 2 looks structurally similar to Wave 1, many victims consolidated into a small number of staging addresses, then into second hops where they sit inert. One of the most significant pieces of evidence tying Waves 1 and 2 together: a number of victims who were only partially drained in Wave 1 were later fully drained in Wave 2. That co-spend pattern gives Alex medium-to-high confidence they're the same attacker.

Wave 3 is more sophisticated. No common collector address. Alex's analysis identified 293 independent chains, each group of victim addresses moved into its own staging address, then into its own vault. The topology looks nothing like Waves 1 and 2.

And critically, there are no co-spends between any of the three waves' attacker addresses. These are distinct operations.

One detail that grounds the entire analysis: not a single UTXO in the high-confidence promoted set was created before March 17, 2021, the date the ColdCard firmware bug was introduced. And by Alex's read of the data, the median dormancy of the stolen coins is around 3.8 years.

The vast majority of these addresses had never spent a coin. They were just receiving addresses. People stacking sats into cold storage, doing everything right.

Alex also has what he calls Footprints A through N, lower-confidence pattern matches that, combined, push the unconfirmed picture well above 2,000 BTC. Those are not yet promoted, but he's tracking them. As of the recording, he had direct victim confirmation for roughly 400 BTC of the approximately 1,500 BTC in promoted addresses. The figures are live and growing, this is not a final tally.

For more on how this situation reached nine figures, see our earlier post: The COLDCARD Disaster Has Reached Nine Figures.

The Vulnerability Itself, What Broke and When

The bug is in the random number generator (RNG), specifically, the entropy implementation in ColdCard firmware. The firmware version affected is the one released around March 17, 2021. My read is that version 4.0.0 and beyond are affected, though verify that against Coinkite's official advisory rather than taking my word on the exact version number.

On older ColdCard models: I'm pretty confident they have more entropy than the affected firmware, but still not enough to protect you from a brute-force attack if you're relying on the RNG alone. Again, check the Coinkite advisory for the specifics rather than hanging your security posture on my read.

RNG and entropy bugs in crypto wallet implementations have been found before, without AI. Alex was clear on that. This isn't a problem that required AI to discover.

But AI is almost certainly being used to operationalize the vulnerability at scale, to accelerate the brute-forcing across a huge namespace of addresses and to do it fast. The difference between "someone could theoretically do this" and "someone is actively doing this at machine speed" is largely AI.

This was, as Alex put it, a poorly implemented thing. Random number generators work. They are proven to work. This one wasn't.

The Wave 1 Attacker May Be Identifiable

This is the most law-enforcement-forward detail in the whole conversation, and it came from Block/BitKey's published work on the Wave 1 pattern.

According to Alex, Block's team, he specifically referenced Clay from BitKey, identified that the Wave 1 attacker used a paid account at a blockchain infrastructure provider to query the victim addresses before draining them. These are RPC/API providers that let you pull blockchain data without running your own node. Totally legitimate services used for totally legitimate reasons all the time. But apparently this particular attacker used one, paid for it, and in doing so left an identity trail.

Alex's read on that: "You say run your own node, verify your own transactions in the blockchain. Apparently Wave 1 hacker did not do that." Authorities have been notified, per Alex's account of what Block/BitKey reported. Whether that leads anywhere is still an open question, but it's the clearest potential path to identification we have.

Locate Block/BitKey's published blog post on this finding, Alex references it as published, and it's worth reading directly.

Where the Coins Are and Why They Haven't Moved

Waves 1, 2, and 3 coins are sitting inert. That's the one piece of good news in this mess, they haven't been laundered, which means there's still a window, however narrow.

Alex walked through what money laundering out of Bitcoin actually looks like for anyone who's been closer to the protocol side than the hacking side. Mixers exist. Peel chains exist. Bridges to chains with privacy protocols exist. It is possible to launder Bitcoin. It is hard, and it's watched.

The fact that the Wave 1/2/3 attacker hasn't moved yet could mean a lot of things, operational patience, waiting for heat to die down, not yet having the infrastructure to do it cleanly, but Alex was clear you shouldn't hang your hat on it. Don't assume those coins are permanently frozen because they haven't moved yet.

There was one case that did see movement: a victim (not in Waves 1, 2, or 3) whose 7 to 10 of 17 BTC went through Thorchain, converted to ETH, and landed at an offshore casino called Dual.com. Alex traced it, notified the victim, and they sent a freeze request to Dual.com at around 1 AM on a Sunday. The response: no freeze without a police report.

Alex found that offensive, and so do I. He had a cryptographic forensic report effectively proving the funds came from a stolen address. He wasn't asking them to seize the coins, just don't allow withdrawal while the investigation runs. They declined.

This raises a real issue around "hold authority", the idea that a platform receiving credible fraud notice should be able to freeze funds for a short window without civil liability. Alex mentioned the CLARITY Act contains a provision along these lines, giving platforms immunity for a 48-hour freeze window. Whether Dual.com is subject to any of that depends on jurisdiction, and Alex noted he doesn't know where they're registered or whether they are at all.

One more important data point from Alex: as of his last analysis, zero multisig wallets have been identified in any of the high-confidence promoted waves. Not one. That's meaningful.

What You Should Do Right Now

If you have a ColdCard and you haven't moved your funds, do it now. Do it immediately, without waiting for more information.

After you've secured your funds, Alex's guidance:

File a police report with your local authorities. File with the FBI's Internet Crime Complaint Center. If you're in Canada, file with the Canadian Anti-Fraud Centre and the RCMP. These reports matter, not just for any potential recovery, but to establish your victimhood early. If funds are ever recovered and multiple parties are claiming the same keys, having a time-stamped police report on file is critical.

Share your drained addresses and the transaction IDs that drained them with Alex directly at @IntangibleCoins on X. He's providing forensic reports back to victims they can hand to law enforcement and exchanges. The more victim reports he has, the more complete the picture gets, and the better the chance of tracing and potentially freezing funds.

Do not destroy your ColdCard. Even after you've moved your coins, or even if they've already been drained. The physical device may carry forensic evidence that helps establish you as the primary key holder if funds are ever recovered.

The community response has been real. "Wicked" has been running live Spaces helping people migrate coins off their ColdCards one by one. Rob Hamilton and a red team have been doing code review across Bitcoin infrastructure, every wallet codebase, every library they can get their hands on.

Portland HODL and Praveen have been in this too. The immune response has been genuine, and it matters.

For the forward-looking self-custody picture: Alex's view, and I agree with it, is that the future is multisig collaborative custody. Firms like Casa, Unchained, Nunchuck, Liana Wallet, and AnchorWatch offer setups that diversify your exposure across multiple devices and key generation mechanisms. If you're committed to self-custody, and you should be, that's the architecture to be moving toward.

AI, Defense, and Who Has Access to What

This is where the ColdCard story connects to something bigger.

Alex raised the case of an AI agent swarm that breached Hugging Face, an incident we covered here. Hugging Face's response team reportedly couldn't use frontier models to defend themselves because they kept hitting cyber safeguards. They had to fall back on open-source Chinese models, Kimi and GLM, to do the defensive work. Alex's reaction was the same as mine: the idea that American companies have to rely on Chinese AI models to defend themselves is absurd.

Alex himself has been hitting Claude's safeguards while doing Bitcoin UTXO forensics on his own local database of public data. He's running a query on his own machine, asking it to pull transaction information from a victim report, and getting downgraded to a less capable model because the query pattern triggers safety filters. His words: "It's insane. It's just insane."

This maps directly to the argument I've been making about KYC/AML restrictions on Bitcoin for years. You can throw guardrails on defenders all you want. Criminals don't care. They're going to use the tools anyway, that's the definition of being a criminal.

The only thing the guardrails actually accomplish is tilting the field toward the attackers.

The red team working on codebase audits did reportedly get access to OpenAI's Edge Enterprise Frontier model. There's also an open-source LLM security vulnerability project that Alex mentioned is working on this space; Steve Lee is reportedly involved. If those details are accurate they're worth tracking.

On the infrastructure side: I mentioned a report out of Minnesota, I believe a water treatment plant attacked by a virus, as an example of why this isn't a Bitcoin-specific problem. The software running grid and water systems in this country is ancient. Getting frontier model access to the people defending those systems is a national security imperative.

Alex's framing on where we are historically: attackers outpace defenders in every new weapons era until defenders catch up. Mongol horse archers. American guerrilla warfare against British column tactics. We're in that early asymmetric phase right now with AI-enabled cyberattacks.

The defenders will catch up. But right now they don't have access to the tools they need, and people are losing their life savings because of it.

Also see: Boltz suspended Bitcoin swaps as AI attacks outpaced patching and Claude breaching real organizations in a misconfigured security test, both part of the same pattern.

About Alex Thorn

Alex Thorn is the Head of Firmwide Research at Galaxy Digital, where he leads the Galaxy Research team. He covers Bitcoin, digital assets, macroeconomics, and on-chain forensics. He runs a proprietary Bitcoin forensic stack and has been one of the primary researchers tracing stolen funds in the ColdCard hack since the attack began. He's a longtime Bitcoin holder and ColdCard user himself. You can follow his research at @GalaxyResearch on X and reach him directly at @IntangibleCoins.

Sources mentioned

Watch the conversation

Timestamps

  • 0:07 - Bitcoin as safe haven in a fiat debasement world
  • 1:20 - Intro: Galaxy Research victim outreach and the forensic picture so far
  • 5:59 - Wave 1 pattern: fixed fee rate, automated topology, Block/BitKey discovery
  • 7:55 - Sankey charts and how attacker waves are mapped on-chain
  • 13:24 - Wave 1 in 41 minutes; March 17, 2021 cutoff; median dormancy; footprints A, N
  • 18:46 - Sponsors
  • 24:20 - White hat sweeping dilemma; holding onto your device for forensic evidence
  • 32:53 - Can the stolen Bitcoin be laundered? Mixers, Thorchain, Dual.com casino
  • 37:38 - The community immune response: code audits, Spaces, red team work
  • 41:13 - AI and defending Bitcoin infrastructure; frontier model access problem; Chinese open-source fallback
  • 46:24 - Water treatment plant attacks; national security imperative of frontier model access
  • 52:29 - Outro: how to reach Alex, self-custody is not dead, the case for multisig

Sponsors

Frequently Asked Questions

The firmware bug was introduced with the version released around March 17, 2021. My read is that version 4.0.0 and beyond are affected, but verify that against Coinkite's official security advisory rather than treating my characterization as settled. If your seed was generated on firmware released before that date, or if you used dice rolls to generate your seed, your exposure is different, but if you have any doubt, move your coins.

Check whether your addresses show any unexpected outgoing transactions you didn't initiate. Alex's analysis found that the high-confidence stolen UTXOs were all created on or after March 17, 2021, and most had never spent a coin before they were drained. If you've been a long-term stacker with a ColdCard and funds have disappeared, reach out to Alex at @IntangibleCoins on X with your drained addresses and transaction IDs.

As of Alex's last analysis at the time of recording, zero multisig wallets have been identified in any of the high-confidence promoted waves. That said, if you had a 2-of-3 multisig where two of the three keys were ColdCard MK3s with no passphrase and no dice roll, those keys are theoretically vulnerable even if no one has attacked that specific configuration yet. Alex's position, and mine, is that any key generated on affected firmware should be rotated regardless.

The coins from Waves 1, 2, and 3, roughly 1,500 BTC in high-confidence promoted addresses, are still sitting inert as of recording. They haven't been laundered, which creates a narrow window, but it's not a guarantee.

Exchanges and services can freeze funds if they receive credible forensic reports and police reports. Filing those reports now, and sharing your information with Alex and Galaxy Research, is the best thing a victim can do to improve the odds.

Alex runs a proprietary Bitcoin stack that includes the full UTXO history across every state the Bitcoin ledger has ever been in, by his characterization, around 3.8 billion rows of data. He uses pattern matching on transaction topology, fee rates, co-spend analysis, and victim reports to identify attacker clusters. Wave 1 was pattern-identified first by Block/BitKey engineers; Waves 2 and 3 were built entirely from victim reports that Galaxy Research then expanded by looking for matching topological patterns across all blocks around the reported transactions.

Each wave represents a distinct cluster of attacks with a recognizable on-chain pattern, including similar transaction topology, fee structures, staging address behavior, and co-spends among victim addresses. Wave 1 happened in 41 minutes. Wave 2 shows co-spends with Wave 1 and likely the same attacker. Wave 3 is more sophisticated, with 293 independent chains and no common collector address. Beyond the three promoted waves, Alex has identified Footprints A through N, lower-confidence pattern clusters still being confirmed.

This vulnerability was a broken RNG implementation in ColdCard's firmware, not a failure of the self-custody model itself. As Alex put it: random number generators work, this one wasn't implemented correctly, and that's what failed.

The answer is better code auditing, rotation to firmware you can verify, and multisig architecture that distributes key generation across multiple devices. None of that means you should put your Bitcoin on an exchange. It means you should build a more resilient self-custody setup.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.