The attacker behind the third wave of Coldcard hardware wallet thefts has moved 45% of the stolen bitcoin, running 97.09 BTC, worth about $7.8 million at Monday prices, through CoinJoin transactions on Sunday, according to Galaxy Research.
The movement follows a Sept. 2 swap of stolen coins to ether through THORChain. Galaxy said the exploiter is working through the haul in size order, largest vaults first. Ranks 1 through 11 have already been moved. The next 10 untouched vaults hold 30.81 BTC, while smaller vaults ranked 61 to 293 hold a combined 33.77 BTC.
Where the money sits
Across all waves of the Coldcard thefts, 82% of the exploited funds remain in the original attacker-controlled addresses, Galaxy said. The rest has been moved for laundering purposes. The research firm also flagged a previously unknown vault of 58 addresses, likely belonging to Coldcard victims, whose coins were co-spent with the known haul.
Counting that vault brings total losses to 1,806 BTC, roughly $143.9 million at current prices, stolen from 190 victims across more than 8,600 addresses. Galaxy had earlier put the figure at about 1,779 BTC as of mid-August, so the scope of the theft keeps growing as investigators trace more addresses.
A bug shipped in 2021
The thefts began July 30 and trace back to a firmware bug Coinkite shipped in 2021. The flaw reduced the randomness used when Coldcard devices generated wallet seeds. That let attackers brute-force private seed phrases and drain single-signature addresses without ever touching the device.
The problem went unnoticed for years because the devices still worked normally. A wallet generated on an affected unit looked and behaved like any other. Only when researchers started mapping clusters of drained addresses did the pattern emerge, and even then the link to seed generation took time to establish.
Coinkite has since patched the firmware, but owners of older devices were urged to move funds to freshly generated wallets. Galaxy raised the possibility of a fourth wave of attacks in August but has not confirmed one.
Laundering pattern
The two laundering routes seen so far, CoinJoin mixing and a THORChain cross-chain swap into ether, are the standard playbook for cashing out stolen bitcoin. CoinJoin breaks the link between inputs and outputs on the bitcoin chain, while a cross-chain swap moves value to an ecosystem where the original theft is harder to trace.
The pace of the cash-out suggests the attacker is not in a hurry. Five days separated the THORChain swap from the Sunday CoinJoin run, and 82% of the total haul has not moved at all. Large holders of stolen coins often wait months before touching funds, since coins that sit still are harder to flag and exchanges that freeze deposits on known theft labels act quickly.
Galaxy continues to track the movement of stolen funds and identify affected addresses. The firm publishes updates through its research account on X.
What it means for owners
The scale of the incident, nearly $144 million across hundreds of victims, makes it one of the larger hardware-wallet-related thefts on record. Unlike an exchange hack, there is no custodian to file claims with. Losses fall directly on individual owners, most of whom bought the devices precisely because they wanted self-custody.
The episode also revives an old argument in bitcoin security circles. Multisig setups and passphrase-protected wallets would have blunted this attack, since a brute-forced seed alone would not have been enough to reconstruct the funds. Single-signature users carried the losses here.
It also raises questions about supply chain trust. A hardware wallet is supposed to be the safest place to keep keys, and the failure here was not a phishing site or a fake device but a genuine product shipped by a legitimate maker five years earlier. Users who bought a Coldcard in 2022 and never updated firmware had no way to know their seed was weaker than advertised.
For anyone still running an old Coldcard firmware, the practical step is unchanged: generate a new wallet on updated hardware, move the coins, and treat the old seed as compromised regardless of whether the address has been touched yet. The same advice applies to any device that generated a seed while the buggy code was in circulation.

discussion