Galaxy Digital Holdings LtdGalaxy Digital's research head Alex Thorn is quoted analyzing the COLDCARD hack, but the news is not about Galaxy's own business.

Alex Thorn, head of research at Galaxy Digital, said on September 3 that in the security breach involving the hardware wallet COLDCARD, the attacker behind the third wave has moved the stolen bitcoin for the first time. The attacker exchanged part of the stolen funds for Ethereum through THORChain, a cross-chain decentralized exchange (DEX). Moving funds from Bitcoin to Ethereum suggests a possible attempt to launder the money. According to Thorn, this is the first time stolen funds have moved from their original addresses across the series of attacks, which are classified into waves one through three. About 90% of the funds stolen in the third wave remain unmoved at this time. Additionally, although the attacker has faced issues such as some transactions being refunded during the exchange on THORChain, they have repeatedly attempted to exchange the remaining funds. Thorn said he has traced the funds routed through THORChain to new Ethereum addresses and shared that information with relevant authorities and cryptocurrency-related companies. Coinkite, the developer of COLDCARD, disclosed a firmware flaw in seed generation on July 30, and the attacker is believed to have regenerated private keys from weak seeds to steal funds. According to a tally published by Thorn on August 24, a total of 1,789.28 BTC, worth approximately $114.7 million (about 18.4 billion yen) at the time of the theft, was stolen from 8,865 addresses in the series of attacks.
Galaxy Digital Holdings LtdGalaxy Digital's research head Alex Thorn is quoted analyzing the COLDCARD hack, but the news is not about Galaxy's own business.
Coinkite's COLDCARD firmware flaw in seed generation let attackers regenerate weak-seed private keys and steal 1,789 BTC.