Latest News

Coldcard Exploiter Moves 97 BTC Through THORChain and…

How Is The Coldcard Attacker Moving The Stolen Bitcoin?

The attacker behind the third wave of thefts from Coldcard hardware wallets has moved 97.09 BTC worth about $7.7 million, using both THORChain and CoinJoin transactions as investigators track how the stolen funds are being dispersed.

Galaxy Research said the amount represents roughly 45% of the bitcoin taken during Wave 3.

The first major movement came on Sept. 2, when the attacker routed about 20.5 BTC from the largest attacker-controlled vault through decentralized exchange THORChain. The proceeds ultimately arrived on Ethereum.

The operator then switched tactics. On Sept. 5, 15.48 BTC from the second-largest vault was sent into a CoinJoin transaction. Another 61.12 BTC from 10 vaults followed the next day.

CoinJoin combines bitcoin transactions from multiple participants, making it harder for outside observers to determine which outputs correspond to specific original inputs. The technique does not make transactions invisible, but it can complicate blockchain tracing considerably.

Galaxy said the attacker appears to be working through the Wave 3 vaults in descending order of size. The 11 largest have now been emptied.

How Much Bitcoin Is Still Sitting In The Vaults?

The next 10 untouched vaults contain a combined 30.81 BTC, according to Galaxy. Much of the remaining bitcoin is spread across considerably smaller balances.

Vaults ranked 61 through 293 hold just 33.77 BTC in total, showing how heavily the stolen funds were concentrated among the largest addresses created by the attacker.

The vaults should not be confused with victims’ original hardware wallets. Galaxy said the exploiter created separate vaults for stolen funds, generally assigning one vault to each victim’s coins.

Those vaults used a two-of-two multisignature structure, meaning two keys are required to authorize spending.

Investigators also identified a previously unknown vault funded by 58 addresses that used the same two-of-two setup. Galaxy said it was probably connected to another Coldcard victim, although the source remains unconfirmed.

If that vault is included, Wave 3 would rise to 294 vaults and the wider Coldcard exploit would total about 1,806 BTC, worth roughly $143.9 million at current prices.

Investor Takeaway

The attacker is now actively moving the largest Wave 3 balances, but most of the bitcoin stolen across the entire Coldcard exploit remains parked at addresses investigators already associate with the attacker. The next risk is whether more of those funds begin moving through swaps, mixers or other routes that make recovery and tracing harder.

How Much Of The Total Theft Has Moved?

Across all identified waves, Galaxy estimates that about 82% of the stolen bitcoin remains at the original attacker-controlled addresses.

The remaining 18% has already moved through transactions that appear designed to make the trail harder to follow.

That distinction matters because the percentage moved from Wave 3 is much higher. With roughly 45% of that wave already spent, the attacker appears to be concentrating recent activity on the newest group of stolen assets while leaving much of the wider haul untouched.

By mid-August, Galaxy had identified approximately 1,779 BTC stolen from 190 victims and more than 8,600 addresses. The newly identified vault could increase both the number of affected vaults and the total losses attributed to the campaign.

Researchers have also raised the possibility of another wave of thefts, although no fourth wave has been confirmed.

What Caused The Coldcard Exploit?

The thefts began on July 30 and were traced to a firmware flaw affecting Coldcard devices manufactured by Coinkite.

The vulnerability weakened the randomness used when devices generated wallet seeds. That reduced the difficulty of reconstructing some private seed phrases through brute-force techniques, allowing attackers to drain vulnerable single-signature addresses without physically accessing the hardware wallet.

The underlying bug originated in firmware released years earlier, leaving affected users exposed even though the compromised devices themselves had not necessarily been stolen or tampered with.

Coinkite has since released corrected firmware, but installing the update is not enough for users whose existing seeds were generated under the vulnerable process.

The company has advised affected users to generate entirely new seeds and move their bitcoin to addresses derived from them. Once a seed is potentially compromised, a firmware patch cannot restore its secrecy.

For Coldcard users, that makes seed replacement more important than the software update itself. For investigators, the immediate focus has shifted to the attacker’s transaction activity as the largest Wave 3 balances continue leaving the vault structure used to hold the stolen bitcoin.

You may also like