Bitcoin: 45% of BTC stolen in Coldcard wave 3 moved
The attacker behind Coldcard’s third wave moved 45% of the stolen BTC, or 97.09 BTC, via THORChain and CoinJoin, according to Galaxy Research.

The attacker linked to the third wave of thefts targeting Coldcard hardware wallets has moved around 45% of the bitcoins stolen in this sequence, according to Galaxy Research. In total, 97.09 BTC, worth approximately $7.8 million, have already left the vaults tracked by researchers via THORChain and then CoinJoin transactions. Across the entire Coldcard incident, around 82% of the identified BTC remain on addresses controlled by the attackers.
The hacker starts with the largest vaults
Galaxy Research had already identified 293 2-of-2 multisignature vaults created as part of the third wave. The attacker now appears to be emptying them methodically, starting with the largest. The 11 biggest have already been moved.
This new stage extends the Coldcard incident that Bref Crypto was already following in August, when thousands of older bitcoins began changing addresses after the vulnerability was discovered.
The next-largest vaults still contain around 30.81 BTC, while the smaller ones, ranked from 61 to 293 by Galaxy, hold a total of 33.77 BTC. The third wave is therefore far from empty.
On-chain monitoring also identified a previously unknown vault consolidating funds from 58 addresses. Galaxy believes it could belong to another Coldcard victim, although it cannot yet confirm the exact source of the loss.
If this new batch is ultimately included in the calculation, the total attributed to the incident could reach approximately 1,806 BTC, or nearly $144 million at current prices.
THORChain followed by CoinJoin now complicates tracking
The first major movement took place on September 2. Around 20.5 BTC were sent to THORChain, a protocol that enables assets to be exchanged directly across different blockchains. Some of the bitcoins were therefore converted into Ether and then sent to new Ethereum addresses.
The subsequent movements used a different method.
On September 5 and 6, the attacker began using CoinJoin, a technique that combines transactions from multiple participants to make it more difficult to identify the exact origin and destination of the funds.
CoinJoin is not, in itself, a criminal tool. It is also used to improve Bitcoin users’ privacy. In this specific case, however, Galaxy considers these movements an attempt to obscure the traceability of the stolen funds.
This difficulty is well known to investigators. Malware targeting crypto wallets and accounts often first seeks to obtain credentials or keys, after which attackers make multiple transfers across protocols to complicate tracking.
Bitcoin nevertheless has one distinctive feature: every movement remains publicly visible. The identity behind an address may be unknown, but the transaction is not.
The vulnerability still affects the seeds, not Bitcoin
The technical point remains essential: Bitcoin itself was not compromised.
In its official security update, Coinkite explains that the incident resulted from a firmware bug introduced into Coldcard’s seed-generation process. Some devices produced recovery phrases with less entropy, and therefore less randomness, than expected. The attackers were then able to reconstruct certain private keys offline, without physically hacking the devices.
The distinction may seem technical, but it changes everything. A sufficiently random seed is supposed to provide such a vast search space that a brute-force attack becomes unrealistic. Reducing that entropy mechanically reduces the number of combinations that must be tested.
Coinkite now recommends firmware versions 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q as the standard releases. However, the company stresses one point: updating the firmware does not repair an already-created vulnerable seed. Affected users must generate a new seed and transfer the funds to it.
This lesson extends beyond Coldcard. BitBox also recently had to fix two severe vulnerabilities in its hardware wallets. BTCPay Server, for its part, offered up to 3 BTC to recover stolen funds after another vulnerability.
Self-custody eliminates the risk of an exchange going bankrupt or arbitrarily freezing withdrawals. It does, however, shift responsibility to the software, hardware and quality of the keys used.
Coldcard now offers a costly demonstration of this principle: Bitcoin’s rules held, but the tool responsible for generating some of the keys did not meet the same standard.


