Topics: Business News, News, Education
**Alex Thorn** (0:00)
8,300 addresses worth 1,720 Bitcoin, worth about $112 million at this moment. These people did everything right. They weren't speculating. They weren't chasing risk down the risk tail. These are people that have been saving for a long time.
**Natalie Brunell** (0:13)
What do you expect the hackers to do?
**Alex Thorn** (0:15)
The Bitfinex hacker sat on billions of dollars of Bitcoin for like five years before they screwed up and ultimately got caught. So you could see them do literally nothing for a long time. That's totally possible. I mean, it's CoinKite's fault at its core. They introduced the bug out of hubris and anger that another project was using their source code. Eventually all vulnerable Coldcard generated Bitcoins will be stolen. If you do not move them, they will be stolen.
**Natalie Brunell** (0:45)
Let's talk about the chances that people could actually get their money back.
Hey everyone, welcome back to the show. Joining me this week is Alex Thorn. He is the head of Firmwide Research at Galaxy Digital, which has been tracking the Coldcard hack since the very beginning. Alex, thanks for joining me.
**Alex Thorn** (1:07)
Hey Natalie, thanks for having me on. Great to be on.
**Natalie Brunell** (1:10)
Well, I feel like it's been a wild couple of weeks in Bitcoin. Let's go ahead and start with an update on the Coldcard hack because, as I mentioned off the top, Galaxy was analyzing this on-chain basically right away, seeing the attacks, seeing the funds flow out of the addresses.
Can you talk to me about how you guys even got a handle on this at the beginning, and what you saw that made you realize this isn't some normal crypto wallet theft?
**Alex Thorn** (1:36)
Yeah, we started tracking this Friday, the 31st of July, which was the second day that funds started being exfiltrated through this exploit.
Basically, engineers at Block, Inc., which makes Square and Cash App and Spiral and the Bitkey, big payments company and Bitcoin company, they had identified a burst of suspicious transactions that looked like it might be theft. That was the first that people had drawn lines around what had already been some emerging victim reports and tried to catalog what it was. The pattern they identified, we now call wave one in this exploit. I was actually in DC throwing a reception at Pubkey DC on Thursday, July 30th. When this really started to come out, I think CoinKite published their first security advisory around 6 or 7 PM Eastern on Thursday, July 30th. I get home on Friday and I have a very powerful Bitcoin analytics stack of software running on top of one of my Bitcoin nodes. I said, why don't I take the pattern that block engineers identified and run it against the node and see whether I can spit out all the addresses? Can I really identify the pattern? Absolutely could. I started tweeting about that. Then really what happened is victims started messaging me and saying, I also lost funds in this exploit, it appears. I opened up my Bitcoin wallet that I used a cold card with and saw unauthorized transaction, sending my money away.
What happened is a lot of those victim reports were not part of the wave one pattern and it was because of those reports that we identified waves two and three and then later at this point, those waves, we call them waves because they're big isolated bursts of thefts all at once, right? And they look like, you know, we can't confirm that wave one, two and three are all the same attacker. I suspect waves one and two are the same attacker and that wave three may be a second attacker. But since then, I've been publishing about this and encouraging victims to come forward because without the victim reports, there's no way to actually identify these exploit funds. I'm now tracking separate patterns beyond those waves all the way through footprint A through Z and now around the corner to AC. So, you know, 29 other patterns of attack.
Again, all based on victims coming forward and saying, I lost my funds, I went into my wallet, they were stolen, and the reason it relies on victim reports or other crypto thefts don't necessarily is if you think about like a crypto exchange or smart contracts or bridges in DeFi often have been hacked, they are a centralized honeypot of all these coins, a centralized exchange, for example. So when it's hacked, we can all see the funds flow from that centralized point and be dispersed out across the blockchain. We don't have to trace them upstream. We know where they emanate from. The whole forensic exercise is tracing where they go. Right here because the funds don't start in a centralized point. They start in hundreds or thousands of people's individual wallets that otherwise had no connection to each other. We actually can't just say, oh, there's the stolen funds. We need victims to say, I also had a Coldcard and mine were stolen. Then when we aggregate a lot of those reports, sometimes we can find patterns between the reports that make us think, oh, person A, person B, and person C might have actually all been stolen in the same attack. It's not really one attack. It's many different attacks against many distributed people. That's what makes it such a complicated forensic exercise. I mean, I will say it's also a fascinating data exercise compared to like, oh, you know, like Bybit was hacked and all this ETH was drained from this one wallet.
43 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID