TLDR
- The Coldcard exploiter has moved about 45% of the assets stolen during Wave 3, according to Galaxy Research.
- Around 97.09 BTC, worth roughly $7.8 million, has already been spent through CoinJoin transactions.
- Galaxy estimates that 82% of all stolen Coldcard funds remain in attacker-controlled addresses.
- A newly identified vault could raise total losses to about 1,806 BTC, worth nearly $143.9 million.
- The attacks trace back to a 2021 firmware bug that weakened seed generation on affected Coldcard devices.
- Galaxy had previously linked the thefts to about 190 victims and more than 8,600 addresses.
The Coldcard exploiter has moved more stolen bitcoin from the third wave of attacks linked to affected hardware wallets. Galaxy said the operator has now moved 45% of assets taken during Wave 3.
Galaxy said the attacker used CoinJoin transactions on Sunday after earlier swapping stolen bitcoin for ether through THORChain on September 2. So far, 97.09 BTC, worth about $7.8 million at Monday’s prices, has been spent.
Coldcard Exploiter Moves Funds by Vault Size
Galaxy said the Coldcard exploiter appears to be moving stolen funds from the largest vaults first. Wallets ranked from 1 to 11 have already been moved, according to the research firm.
Coldcard ‘Wave 3’ exploiter continues to move funds
In wave 3, the exploiter created 293 2-of-2 multisig vaults for each victim’s coins.
The first movements on 9/2 sent coins over THORChain to Ethereum.
Tonight’s movements are going into coinjoins rounds. pic.twitter.com/H7HIpcI7ah
— Galaxy Research (@glxyresearch) September 7, 2026
The next 10 untouched vaults hold 30.81 BTC in total. Smaller vaults ranked from 61 to 293 hold another 33.77 BTC. Galaxy said 82% of all funds stolen from Coldcard devices remain in the original attacker-controlled addresses.
The rest has moved through transactions linked to laundering activity. Galaxy continues to track the addresses and spending patterns connected to the thefts.
Firmware Bug Linked to Wallet Seed Weakness
The thefts began on July 30 and were linked to a firmware bug that Coinkite shipped in 2021. The flaw affected how some Coldcard devices generated wallet seeds.
The reduced randomness made some private seed phrases easier to brute-force. Attackers could then drain single-signature wallet addresses without gaining physical access to the hardware device.
By mid-August, Galaxy had identified about 1,779 BTC stolen from 190 victims. The firm also linked the thefts to more than 8,600 addresses.
Galaxy Raises Total Loss Estimate
Galaxy said the Coldcard exploiter recently co-spent a previously unknown vault made up of 58 addresses. The firm said those addresses are likely linked to additional Coldcard victims.
Including that vault would raise the estimated total theft to 1,806 BTC. At current prices, the stolen Bitcoin is worth about $143.9 million.
Galaxy has also mentioned the possibility of a fourth attack wave. The firm has not confirmed that another wave has taken place. Tracking continues as more stolen Bitcoin leaves known attacker-controlled addresses.
The latest movements leave most of the identified funds unmoved, while researchers continue tracing transfers tied to the Coldcard wallet attacks across chains.







