Contact Us

Following the Bitcoin: Inside Keystone’s Independent Analysis of the Coldcard Exploit

Case study

When a flaw in a hardware wallet put more than 1,300 Bitcoin at risk, Keystone independently analyzed publicly available blockchain data to trace the movement of funds, and separate strong evidence from informed suspicion.

Overview

A hardware wallet is designed to keep cryptocurrency safe even when everything around it is connected to the internet. But in the Coldcard incident, the vulnerability emerged before a transaction was ever signed: it was embedded in the process used to create the private keys themselves.

Beginning July 30, attackers drained Bitcoin from addresses associated with certain versions of Coldcard hardware wallets. The attacks unfolded in waves, with Galaxy Research estimating that losses had reached approximately $130 million by August 4.

Challenge
Client
Root cause

A weakness at the point of creation

Cryptocurrency wallets rely on entropy (the randomness used to generate a seed phrase and its private keys.) With sufficient entropy, guessing a private key is effectively impossible.

According to Coldcard’s security advisory, a firmware defect weakened this process for seeds created on affected devices. Rather than drawing entirely from a strong hardware source of randomness, the flawed process relied partly on more predictable device and timing information.

That significantly reduced the number of possible keys. Attackers with sufficient information and computing resources could generate candidate keys offline, compare the resulting addresses with the public Bitcoin ledger, and take control of any matches. They did not need physical access to the wallet, or even for the device to be online.

Coldcard has released fixed firmware, but the company cautions that an update cannot repair a seed created using affected firmware. Users must generate a new seed and migrate their assets.

Analysis

Following the funds

Galaxy Research initially published seven Bitcoin addresses believed to be associated with the attackers. Keystone publicly reported  addresses as the starting point for an independent analysis.

Using Dune and SQL, we extracted every transaction involving the identified addresses beginning July 29. From there, we reconstructed how Bitcoin moved from older, previously idle wallets into newly created addresses and through subsequent points of consolidation.

Figure 1: The chronological movement of funds among tracked addresses. Orange lines represent transfers between addresses; external inflows are grouped in blue. These connections do not, by themselves, establish common ownership.

The transactions shared a recognizable draining signature: multiple inputs from the same older address moved to a single new address, with no change returned to the original owner. This pattern helped us identify additional addresses of interest, several of which were later connected to the original set through direct transactions.

Figure 2: Reconstructed balances across tracked addresses from July 30 through August 10. Several early addresses were quickly emptied, while substantial balances accumulated in later destinations.

We also examined addresses used together as inputs in a transaction—a common indication that they are controlled by the same entity. Applying that heuristic to addresses publicly reported as belonging to victims surfaced several additional wallets that appeared to have been compromised.

The techniques were straightforward. Interpreting the results was not.

Conclusion

What the blockchain cannot tell us

Scanning for the same pattern produced several hundred additional potential victims, broadly consistent with public reporting. But a matching transaction pattern is not proof.

Once the vulnerability became known, legitimate users had every reason to move their Bitcoin. On the blockchain, a protective migration can initially look almost identical to a theft: an old wallet is emptied and its balance moves to a new address.

Connections to addresses publicly attributed to the attackers., later consolidation, exchange deposits, cross-chain transfers, timing, and common inputs can strengthen an inference. Until those links emerge, however, investigators must account for false positives.

That distinction is central to cryptocurrency investigations. The blockchain provides an unusually transparent record of asset movements, but transactions alone do not establish ownership or intent.

Keystone’s crypto investigations practice combines blockchain analytics with technical investigation and evidentiary discipline. Whether the matter involves an exploit, fraud, asset tracing, sanctions exposure, or a dispute over ownership, our goal is to turn complex on-chain activity into a clear account of what happened, what the evidence supports, and where the investigation should go next.

The blockchain may be public. Understanding the story it tells is a different matter.

Keystone experts
No items found.
Case Studies
Contact

To learn more about Keystone's approach to approach to technical investigations or expertise in crypto, contact science@keystone.com.

Topline highlights

1  /  2
No items found.
Case studies

How we help our clients achieve their business goals.

No items found.