The perpetrator behind the third wave of breaches against Coldcard hardware wallets has transferred 97.09 BTC, valued at $7.7 million and representing nearly 45% of the stolen bitcoin, utilizing two distinct techniques.
Galaxy Research reported that the malicious actor channeled roughly 20.5 BTC originating from its primary vault via the decentralized exchange THORChain on September 2, with the assets ultimately arriving on Ethereum.
Subsequently, the offender transferred 15.48 BTC from the second-biggest vault into a CoinJoin operation on September 5, which was succeeded by another 61.12 BTC drawn from 10 vaults the following day.
CoinJoin merges transaction data from numerous bitcoin participants, complicating efforts to trace specific funding sources to their final destinations.
Galaxy noted that the wrongdoer has been systematically addressing the 293 vaults by descending magnitude, having already cleared the top 11 largest ones. The subsequent 10 vaults preserve 30.81 BTC, whereas vaults positioned 61 to 293 collectively store 33.77 BTC.
These repositories are distinct from the individual wallets of the victims. Galaxy explained that the hacker established them individually for every victim’s cryptocurrency utilizing a two-of-two multisig configuration demanding two distinct keys to transfer the bitcoin. The previously unrecognized vault, supported by 58 addresses, deployed this identical architecture.
Galaxy indicated that this particular vault likely connected to another Coldcard victim, though its exact genesis is still unverified. Incorporating it would expand Wave 3 to 294 vaults and elevate the overarching exploit scope to approximately 1,806 BTC, valued at about $143.9 million.
Roughly 82% of the cryptocurrency pilfered throughout all iterations stays localized within initial hacker-controlled wallets, whereas 18% has shifted through transfers seemingly intended to obfuscate the movement of capital, according to Galaxy.
The breaches commenced on July 30 after exploiters took advantage of a firmware vulnerability that compromised the entropy required by Coldcard gadgets to formulate wallet recovery seeds.
Coinkite has launched patched firmware, yet emphasized that impacted individuals are required to establish fresh seeds and transfer their assets because a mere software upgrade cannot mend already compromised keys.
Originally published at https://www.coindesk.com/business/2026/09/07/coldcard-hacker-moves-45-of-bitcoin-stolen-in-third-attack-wave.