The hacker linked to the third wave of attacks on Coldcard wallets has moved 45% of the stolen bitcoins, according to Galaxy Research. The funds were transferred via THORChain to Ethereum or into CoinJoins, apparently to launder the loot. During Wave 3, the attacker created 293 2-of-2 multisig vaults for victims’ coins. Approximately 82% of the stolen funds remain in attacker-controlled addresses, while 18% have already been moved as part of an apparent laundering effort. The attack, which exploited a firmware flaw introduced by a March 2021 update, weakened key security from 128 to 40 bits on older devices, allowing attackers to brute-force keys remotely.
Source: Read the original article

