Summary
- Galaxy Research reported that 97.09 BTC, valued at approximately $7.7 million, has been moved from the Wave 3 vaults.
- The transfer occurred via THORChain on September 2, followed by CoinJoin rounds over the weekend.
- Despite these movements, 82% of the total Bitcoin stolen during the Coldcard exploit remains untouched.
The perpetrator behind the third round of thefts from Coldcard hardware wallets has shifted 97.09 BTC, which constitutes about 45% of the Bitcoin obtained in this wave, equating to roughly $7.7 million at current market rates, as noted by Galaxy Research.
The initial transfer took place on September 2, when approximately 20.5 BTC was moved from the largest vault through THORChain and converted into Ethereum. The later transactions on Sunday night were directed into CoinJoin rounds, a Bitcoin privacy method that aggregates transactions from multiple parties to obscure the origin and destination of funds. Of the transferred amount, only 20.56 BTC successfully reached Ethereum, while an additional 57.24 BTC remains unspent as CoinJoin change in a single wallet, with Galaxy suggesting that the trail ends with about 19 BTC still unaccounted for.
The Coldcard ‘Wave 3’ exploiter continues to transfer funds.
In the third wave, the attacker established 293 2-of-2 multisig vaults for the coins of each victim.
The first transfers on 9/2 sent coins through THORChain to Ethereum.
The recent transfers are going into CoinJoin rounds. pic.twitter.com/H7HIpcI7ah
— Galaxy Research (@glxyresearch) September 7, 2026
The vaults involved were set up by the attacker. Galaxy indicated that the operator created 293 two-of-two multisig addresses and has been processing them based on their size. Currently, eleven of these vaults are empty, while the next ten contain a total of 30.81 BTC, and the remaining 233 smaller vaults hold 33.77 BTC.
Origin of the Exploit
The thefts stem from a firmware vulnerability introduced by Coinkite in March 2021, which diverted seed generation from the device’s hardware random-number generator to a software alternative, significantly reducing key strength from 128 bits to as low as 40 bits. This flaw allowed attackers to reconstruct private keys offline, enabling them to drain single-signature addresses without accessing the hardware directly. The initial thefts commenced on July 30.
Coinkite has since revamped its firmware, now at Mk4/Mk5 5.6.2 and Q 1.5.2Q, requiring users to generate their own randomness through manual methods like key presses, dice rolls, or coin flips. However, an update cannot rectify seeds generated under the flawed firmware; users must create a new seed and transfer their coins accordingly. Coinkite's CEO Rodolfo Novak issued an apology in an open letter on July 31, stating the company must "earn back our users' trust." A comprehensive technical analysis is still forthcoming.
Myriad: Predict Bitcoin's next price movement.On Monday, Galaxy's thread also highlighted a previously unidentified vault sourced from 58 addresses. Galaxy suspects this may belong to another Coldcard victim, potentially increasing the total reported losses from the exploit to about 1,806 BTC, or $143.9 million. In August, Galaxy mentioned an unverified fourth wave involving 638.5 BTC, which could push total losses beyond 2,400 BTC, with no confirmed attacks reported since August 6. Throughout all waves, 82% of the stolen Bitcoin remains in the original locations where the attackers stored them.
