Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Coldcard hacker moves $7.7 million in Bitcoin from third wave of attacks
00

Coldcard hacker moves $7.7 million in Bitcoin from third wave of attacks

Sep 7, 2026

The attacker behind the third wave of Coldcard hardware wallet exploits has moved 97.09 BTC ($7.7 million), representing 45% of the wave's haul, using THORChain and CoinJoin to obscure the trail. The thefts stem from a 2021 Coinkite firmware bug that weakened seed entropy, allowing offline brute-force attacks. Total losses across all waves are estimated at 1,789 to 1,806 BTC ($114.7 million to $143.9 million). Coinkite has patched the flaw but warns that affected users must generate entirely new seeds.

Wave 3 fund movement

  • ▪The attacker behind the third wave of Coldcard hardware wallet exploits moved 97.09 BTC, worth approximately $7.7 million to $7.8 million, representing about 45% of the wave's stolen funds.
  • ▪Across all waves of the Coldcard exploit, approximately 82% of the stolen Bitcoin remains in the original attacker-controlled addresses, while 18% has been moved for laundering.
  • ▪Galaxy Research reported that the Coldcard Wave 3 attacker began moving stolen funds on September 2, 2026.

Firmware entropy flaw

  • ▪Coinkite Chief Executive Rodolfo Novak apologized in an open letter on July 31, 2026, stating that the company would have to earn back its users' trust.
  • ▪The Coldcard thefts stemmed from a firmware bug introduced by Coinkite in March 2021 (version 4.0.1 onward) that bypassed the hardware random number generator.
  • ▪The Coinkite firmware bug caused Coldcard devices to default to a software-based pseudo-random number generator, collapsing key strength from 128 bits of entropy to as low as 40 to 72 bits.
  • ▪Coinkite released updated firmware to patch the flaw, but stated that affected users must generate entirely new seeds and migrate their funds because the update cannot repair already compromised seeds.

Total exploit losses

  • ▪The Coldcard exploit ranks as the third-largest cryptocurrency exploit of 2026, behind the $293 million Kelp DAO hack and the $280 million Drift protocol hack.
  • ▪Total confirmed losses from the Coldcard exploits stand at approximately 1,789 BTC, valued at around $114.7 million at the time of theft, affecting more than 8,865 addresses.
  • ▪Galaxy Research identified a previously unknown vault funded by 58 addresses that likely belongs to another Coldcard victim, which would raise total exploit losses to roughly 1,806 BTC, worth about $143.9 million.

THORChain swaps

  • ▪The Coldcard attacker routed approximately 20.5 BTC from the largest stolen vault through the decentralized exchange THORChain on September 2, 2026, swapping the assets into Ether on Ethereum.
  • ▪THORChain's permissionless, decentralized cross-chain architecture prevents it from freezing or reversing transactions, making it an attractive vehicle for the attacker to swap native assets without a centralized intermediary.

CoinJoin mixing transactions

  • ▪Following the CoinJoin transactions, approximately 57.24 BTC sits unspent as change in a single address, while the trail ends on roughly 19 BTC more.
  • ▪CoinJoin transactions combine Bitcoin payments from multiple users into a single transaction to obscure the trail between inputs and outputs.
  • ▪The Coldcard attacker sent 15.48 BTC from the second-largest vault into a CoinJoin transaction on September 5, 2026, followed by another 61.12 BTC from 10 vaults on September 6, 2026.

Vault drainage strategy

  • ▪The Coldcard attacker has been draining the 293 vaults in descending order of size, successfully emptying the 11 largest vaults.
  • ▪The next 10 untouched vaults in the attacker's size-ordered queue hold 30.81 BTC, while the remaining smaller vaults (ranks 61 through 293) hold a combined 33.77 BTC.
  • ▪The Coldcard exploiter created 293 two-of-two multisignature vaults to hold the stolen funds of individual victims.

Debatable claims

  • ▪Coinkite should financially compensate victims of the Coldcard firmware exploit
  • ▪Decentralized protocols like THORChain should implement transaction-freezing mechanisms to block stolen funds
  • ▪Cryptocurrency mixing services like CoinJoin should be legally banned

5 sources

Cryptobriefing
Coldcard attacker moves 45% of stolen Bitcoin through THORChain and CoinJoin, Galaxy reports
View source article
Coindesk
Coldcard hacker moves $7.7 million in BTC, 45% of bitcoin stolen in third attack wave
View source article
Cointelegraph
Coldcard Third-Wave Attacker Moves 45% of Stolen Bitcoin
View source article
Theblock
Coldcard exploiter moves 45% of funds stolen from 'Wave 3' attacks, Galaxy says
View source article
Decrypt
Coldcard Hacker Moves $7.7M, Nearly Half of Third-Wave Bitcoin Haul - Decrypt
View source article

Story comments

Loading comments…

Related Projects

Galaxy ResearchBitcoin

Topics

Bitcoin privacyBitcoin security & risksCrypto securityBitcoin wallets & custody