Tracking the Coldcard Hackers: Inside the $120M Bitcoin Theft with Alex Thorn — Key Takeaways

YouTube
Tracking the Coldcard Hackers: Inside the $120M Bitcoin Theft with Alex Thorn
Bitcoin Magazine1h 9mAug 7, 2026
Watch the originalBlock Inc. engineers traced Wave 1's attacker to a paid account at a centralized Bitcoin node/RPC provider, meaning law enforcement may already know the attacker's identity — and Wave 1 holds 1,082 BTC that remains untouched.
Key takeaways
Victims must preserve Cold Card devices and establish KYC paper trail now to prove ownership later
Victims must preserve Cold Card devices and establish KYC paper trail now to prove ownership later
- All vulnerable private keys will eventually be public; anyone could claim ownership — early formal victimhood filing is the only defense.
- If drained coins were funded from a KYC exchange, victims should immediately email that exchange to preserve account records for litigation.
Cold card firmware bug introduced March 17, 2021 went undetected for 4+ years
Cold card firmware bug introduced March 17, 2021 went undetected for 4+ years
- Bug affects on-device key generation on MK2/3/4/5/Q firmware from that date; code change caused RNG to fall back to nothing.
- Coin Kite's repository flagged as sloppy: minimal commenting, commits merged to main without review.
At least 3 confirmed attack waves with distinct on-chain signatures, implying multiple threat actors
At least 3 confirmed attack waves with distinct on-chain signatures, implying multiple threat actors
- Waves 1 & 2 pool victims into a few collector addresses (plausibly same actor, ~1,150 BTC combined); Wave 3 uses 293 separate P2WSH addresses, one per victim.
- Researcher Alex Thorne has catalogued footprints A through P, each a distinct attack pattern identified via victim reports.
This Dig holds 4 more insights, 4 flashcards, and 3 quotes — free with your trial.
Unlock this Dig freeStart free with 100 credits · No card, no expiry
In this video
- 1mColdcard Exploit: How the Investigation Began
- 9mWhich Coldcard Devices Are Vulnerable
- 15mTracking the Attackers: Waves, Footprints & 1,600 Stolen BTC
- 24mWhite Hats, Victim Reports & How to Prove Ownership
- 28mIs Coinkite Liable? Negligence vs. Malice in the Firmware Bug
- 32mBitcoin's Soul-Searching Moment: Trust & Self-Custody Culture
- 38mMultisig & Collaborative Custody Explained
- 43mAI-Powered Attackers: The First Salvo of the Clanker Wars
- 51mOpen-Source AI, Encryption Battles & Internet Freedom
- 58mQuantum Threats, Market Impact & Final Advice for Victims
This page is a partial, transformative summary produced by Homestake. All rights to the original content remain with its creator — please support them at the source link above.



