
AI-generated summary
The vulnerability in Coldcard wallets was fixed by Coinkite with an update, but this update does not work automatically in old wallets, which allows hackers to continue using the vulnerability.
Coldcard hacker, who has kept most of his BTC in his original address, except for very small transfers, has started to increase his transfers in recent days. According to Galaxy Research, the attacker empties the wallets he created, known as "vaults", from large to small, depending on the amount of BTC in them. It seems that the hacker or hackers started to transfer the Bitcoins they stole, especially in the 3rd wave.
The first big move is on September 2…
The hacker, who created various wallets to store the BTCs he stole, created a total of 294 "vaults". Now it appears that these safes are slowly being emptied. The attacker has managed to completely empty 11 safes in total so far.
The attacker, who started his first large transfer on September 2, moved 20.5 BTC that day and transferred these BTCs to the Ethereum network by passing them through ThorChain.
On September 5, another 15.4 BTC was released from the second largest vault.
Yesterday, on September 6, a total of 61.12 more BTC was removed from 10 different safes. And thus, 90.7 BTC worth a total of $ 7.7 million was released from the attacker's safes.
There is also Coinjoin
It was also stated that the attacker used Bitcoin hiding platforms other than Thorchain. It could not be seen which platforms were used in this style, which is referred to as the Coinjoin technique.
As it is known, Coinkite company, the manufacturer of Coldcard company, fixed the error by releasing a new update, but this change does not work automatically in old wallets. So this error remains there.
Approximately 82% of the 1806 BTC stolen in total are still in the wallets to which they were first sent.
AI outlook — possibilities, not facts
The hacker will continue to transfer BTC from more vaults.
Likely · Within weeks

A security attack was detected on Bitget exchange, which resulted in $351.6 million worth of cryptocurrency transfers. The attack affected the hot wallet infrastructure, cold wallets remained secure. Bitget's user protection fund is $464 million and losses can be covered within this fund. Withdrawals have been stopped, investments and transactions continue.

Circle has officially launched the Arc blockchain network, with institutions like BlackRock and Visa as validators. While the network, where transaction fees are paid with USDC, includes DeFi protocols such as Uniswap and Aave, artificial intelligence-focused development tools are also offered.

The United Arab Emirates decided to move the 'Digital Vault' infrastructure of the UAEPASS digital identity system, which has millions of users, to the Avalanche blockchain network in order to speed up document verification processes and increase security.

The Ethereum Foundation aims to make all three layers of the network: transaction processing, consensus, and data quantum-resistant by the end of 2029. The Foundation stated that the preparations coincide with Google, Microsoft and Cloudflare.

Ethereum developers have presented the EIP-8141 proposal, which will allow users to make transactions on the network without holding ETH in their wallets. This improvement is planned to be added to the Hegota update and is expected to happen in August next year. Gas fees may be paid by other accounts or sponsors.

A hacker attack took place on the Liquid network developed by Blockstream and 4 thousand of the 4200 Bitcoins in reserve were stolen. The attackers claimed to be 'white-hat' hackers and required the error to be corrected in order for the funds to be returned. The incident is being followed up on a daily basis.