Coldcard Wave 3 Attacker Moves 45% of Stolen Bitcoin

Galaxy Research traces THORChain and CoinJoin activity as most broader exploit funds remain unmoved
TL;DR
- Galaxy Research said the Coldcard Wave 3 attacker resumed moving stolen Bitcoin through THORChain and CoinJoin transactions.
- The exploiter is working through hundreds of attacker-created multisig vaults from the largest balances downward.
- Most Bitcoin linked to the broader Coldcard exploit remains in its original attacker-controlled addresses, while a possible fourth wave remains unconfirmed.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Galaxy Research said on September 7, 2026, that the attacker behind the third wave of Coldcard wallet thefts had spent 97.09 BTC, representing about 45% of the Bitcoin stolen in Wave 3. The cited Monday valuations placed that amount at approximately $7.7 million and $7.8 million under separate price snapshots. The activity marked a renewed movement of already stolen funds rather than another confirmed theft wave, with the attacker using both cross-chain conversion and Bitcoin-native transaction mixing to move the proceeds.

How the Wave 3 funds moved
The first major movement occurred on September 2, when roughly 20.5 BTC from the largest vault was sent through THORChain and converted into Ethereum. More precise transaction accounting showed 20.56 BTC ultimately reached Ethereum. Subsequent activity took a different route, with funds entering CoinJoin rounds, a Bitcoin privacy technique that combines transactions from multiple participants to make links between inputs and outputs harder to trace. Another 57.24 BTC remained unspent as CoinJoin change in a single address, while Galaxy Research said the observable trail ended on roughly 19 BTC more.
Galaxy Research wrote, “Coldcard ‘Wave 3’ exploiter continues to move funds,” and said the latest transfers were “going into coinjoins rounds.” The research firm said the operator had created a structured series of multisig vaults for the stolen coins and was spending them according to balance size, beginning with the largest holdings rather than moving the funds randomly.
The Wave 3 movement does not represent the same share of the overall Coldcard theft. Galaxy Research said approximately 82% of Bitcoin stolen across all identified waves was still sitting in the original attacker-controlled addresses, while the remaining 18% had already moved in transactions associated with efforts to launder the stolen funds.
Recent spending also exposed an additional vault that Galaxy Research said had been “co-spent” and was funded by 58 addresses likely associated with Coldcard victims. Galaxy marked the cause of that cluster as open but believed it represented another Coldcard victim. Including it would lift Galaxy Research’s published exploit total to about 1,806 BTC, valued at $143.9 million at the cited snapshot.
Galaxy Research’s earlier mid-August accounting had identified roughly 1,779 BTC stolen from 190 victims across more than 8,600 addresses. The research firm was also carrying an unconfirmed fourth wave of 638.5 BTC in August. If eventually attributed to the Coldcard compromise, that cluster would take the aggregate above 2,400 BTC. Galaxy Research had not confirmed that fourth wave, however, and had previously recorded no attacker sweeps since August 6.
Firmware flaw weakened Coldcard seed generation
The theft campaign began on July 30, 2026, and traced back to a firmware flaw introduced by Coinkite in March 2021. The issue redirected seed generation away from the Coldcard device’s hardware random-number source and toward a weaker software-based generator. That reduced seed security from an expected 128 bits of entropy to as little as 40 bits on some older devices, allowing attackers to reconstruct vulnerable private keys offline and drain single-signature addresses without physically accessing the hardware wallets.
Coinkite later overhauled the affected firmware, with updated versions listed as Mk4/Mk5 5.6.2 and Q 1.5.2Q. The revised setup requires users to contribute additional randomness through key presses, dice rolls or coin flips. Updating the firmware cannot repair a seed that was originally generated under the flawed version, so affected wallet owners must create a fresh seed and transfer their Bitcoin to addresses derived from it.
Coinkite chief executive Rodolfo Novak apologized in an open letter dated July 31, writing that the company would have to “earn back our users' trust.” A full technical postmortem remained in preparation at the time covered by the information.
Bitcoin activity increased after the exploit
Bitcoin network activity rose sharply after the exploit as affected users moved and consolidated holdings to reduce exposure, pushing active addresses to an eight-month high. The incident had negligible apparent effect on Bitcoin’s market value during that period, with the asset instead rallying to near $82,000 in August before later pulling back to around $79,500 at the time of the coverage.
The latest movements show the Wave 3 operator continuing to work through attacker-created vaults while using different transaction routes for stolen funds. Galaxy Research’s accounting distinguishes those active movements from the broader Coldcard exploit, where most of the stolen Bitcoin remained in its original attacker-controlled locations and the additional fourth-wave cluster had not been confirmed.
This article has been refined and enhanced by ChatGPT.