On July 30, attackers drained 594.477 BTC from 500 Bitcoin wallets in a coordinated operation.
The funds were first consolidated into a single address before 562.019 BTC were moved to a second wallet. BitOK traced the entire flow of funds.
All 500 transactions were executed within just 15 minutes. BitOK analysts identified several common characteristics:
• funds from different wallets were consolidated into a single address;
• almost all transactions were confirmed within four consecutive Bitcoin blocks;
• the transactions shared the same structure and similar fee patterns.
Taken together, these indicators point to a single, carefully coordinated operation.
The leading hypothesis is a vulnerability affecting seed phrase generation in certain versions of the COLDCARD firmware. Such a flaw could have allowed attackers to recover seed phrases and gain access to affected wallets.
In one of our previous posts, we explained that the problem may not lie in the seed phrase itself, but in the way it was generated. That's why high-quality randomness during seed generation is critical to wallet security.
The complete flow of funds is shown in the graph above.
Website | Telegram | BitOK bot


