*Galaxy Digital is out with an update on coins they think are part of those stolen due yo faulty entropy from Coldcards:
LOSSES FROM COLDCARD HACK EXCEED $100M
High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents.
If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC).
More in the thread below ๐
This graphic shows every event we've identified, positioned by when it began and sized by how many addresses it drained. The three mass waves dominate the picture; the lettered footprints of are the smaller markers.
Wave 4 remains unconfirmed by any victim, though we suspect it's real with medium-high confidence.
Wave 1 was first observed by engineers at @blocks, but we have fully confirmed it based on victim reports.
We discovered Waves 2 and 3 based on victim reports, and continue to receive multiple victim confirmations.
Most victims appear in only one wave, though some appear in two.
In total, 73 individual victims have reached out to @intangiblecoins for help tracing their coins. With help from victim reports, we have identified 14 additional footprints. These could be many different attackers individually exploiting the now-known vulnerability.
While we have also identified a potential Wave 4, we have yet to receive specific victim confirmation of inclusion in this wave. Including it would bring the total to 2055 BTC ($130m).
We believe with medium-high confidence that Wave 4 is substantially comprised of an attacker, but we have not promoted it into our top-line numbers because we lack sufficient victim confirmation.
We have been providing confirmed attacker and victim addresses to US federal law enforcement authorities, crypto exchanges, crypto compliance & cyber investigation companies and groups, and other relevant parties.
90% of stolen coins have not moved. 100% of coins in Waves 1, 2, and 3 have not moved. It is essential that we continue to identify additional attacker addresses, especially as new, opportunistic attackers emerge, so that we can report their addresses to authorities.
The attack is ONGOING. If you are using a Coldcard and unsure whether it's safe, migrate your funds to a safe address at a custodian/exchange or a fresh seed.
If you are a victim, please DM @intangiblecoins and share your drained addresses and attacker TXIDs. He can help you with tracing and providing information that will be useful to reporting your loss to authorities.
Stay safe and stay positive. There are still hopes for recovery. Thanks to many of the great people working behind the scenes to help victims, identify attackers, audit and harden codebases, and help people keep their coins safe. You know who you are. ๐งก
Pales in comparison to Mt. Gox still, right?
Although, dollar value wise, I'm not sure.
1,500 coins Vs 800,000
https://twiiit.com/glxyresearch/status/2084411904924045370