Key Highlights
- The attacker behind the Coldcard exploit has transferred approximately 45% of bitcoin stolen in Wave 3, Galaxy Research reports.
- Approximately 97.09 BTC, valued at roughly $7.8 million, has been laundered via CoinJoin transactions.
- Galaxy Research calculates that 82% of total stolen Coldcard bitcoin stays within addresses controlled by the attacker.
- Discovery of an additional vault could increase overall losses to approximately 1,806 BTC, valued at nearly $143.9 million.
- The breach stems from a 2021 firmware vulnerability that compromised seed generation on specific Coldcard devices.
- Galaxy Research previously connected the stolen funds to roughly 190 victims and over 8,600 blockchain addresses.
The individual exploiting Coldcard hardware wallets has transferred additional stolen bitcoin from the third wave of attacks. Galaxy Research confirms the operator has now relocated 45% of Wave 3 assets.
Galaxy Research reports the attacker deployed CoinJoin transactions on Sunday following an earlier exchange of stolen bitcoin for ether via THORChain on September 2. To date, 97.09 BTC, valued at approximately $7.8 million based on Monday’s market rates, has been processed.
Attacker Prioritizes Largest Vaults for Fund Transfers
Galaxy Research indicates the Coldcard attacker follows a strategy of targeting the largest vaults initially. Wallets numbered 1 through 11 have been emptied already, the research firm confirms.
The following 10 untouched vaults contain 30.81 BTC combined. Smaller vaults numbered 61 through 293 house an additional 33.77 BTC. Galaxy Research states that 82% of all bitcoin stolen from Coldcard devices remains in addresses the attacker initially controlled.
The remainder has been transferred through transactions associated with money laundering operations. Galaxy Research maintains ongoing surveillance of the addresses and transaction patterns related to these thefts.
2021 Firmware Vulnerability Weakened Wallet Security
The attacks commenced on July 30 and trace back to a firmware vulnerability Coinkite distributed in 2021. This defect impacted how certain Coldcard devices created wallet seeds.
The diminished randomness made specific private seed phrases vulnerable to brute-force attacks. Threat actors could subsequently empty single-signature wallet addresses while never physically accessing the hardware device.
By mid-August, Galaxy Research had confirmed approximately 1,779 BTC stolen from 190 individuals. The research firm additionally traced the thefts across more than 8,600 addresses.
Updated Loss Estimates Include New Vault Discovery
Galaxy Research reports the Coldcard attacker recently co-spent from a previously unidentified vault comprising 58 addresses. The research firm believes these addresses probably connect to additional Coldcard victims.
Factoring in that vault would elevate the total estimated theft to 1,806 BTC. Based on current market values, the stolen Bitcoin represents approximately $143.9 million.
Galaxy Research has also raised the prospect of a fourth attack wave. The firm has yet to verify whether another wave has occurred. Monitoring continues as additional stolen Bitcoin exits known attacker-controlled addresses.
The recent transfers leave the majority of identified funds stationary, while researchers persist in tracing movements connected to the Coldcard wallet breaches across multiple blockchains.





