According to Bitcoin News monitoring, research by @PraveenPerera reveals that attackers of Coldcard users appear to have systematically targeted addresses by Bitcoin holdings, extracting UTXOs by amount. A critical discovery shows that a single address containing 225 spendable UTXOs had exactly 200 extracted—matching the default 200-record limit of a blockchain API—suggesting the attacker's tool failed to load additional pages, leaving behind 0.16 BTC including 25 early UTXOs.
Most significantly, researchers cannot recreate the seed phrases behind 132.95 BTC across the 153 compromised addresses, despite evidence that attackers obtained the complete seeds. At least 75 BTC remains on other addresses derived from the same seeds. The inability to reproduce these seeds raises the possibility that attackers accessed undisclosed device data or additional metadata beyond the seed phrase itself.