Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
BTC$78,554▼ 0.49%ETH$2,489▲ 0.23%SOL$103.40▼ 0.15%TOTAL CRYPTO$2.7T▼ 2.13%S&P 5007,673.52▼ 1.08%NASDAQ26,421.41▼ 1.01%DOW52,786.07▼ 2.31%GOLD4,395.00▲ 1.25%WTI94.24▲ 20.54%BRENT99.36▲ 18.92%EUR/USD1.1629▲ 0.90%USD/JPY153.75▼ 2.94%DXY98.84▼ 0.77%

Coldcard Hacker Moves $7.7M in Stolen Bitcoin Through Mixers

The attacker behind the Coldcard Wave 3 thefts has laundered 97.09 BTC, about 45% of the haul, via THORChain and CoinJoin, Galaxy Research reports.

PartnerSurfshark VPN

The hacker behind the third wave of Coldcard hardware wallet thefts has moved 97.09 BTC, worth about $7.7 million, out of stolen vaults through THORChain swaps and CoinJoin transactions, Galaxy Research said Sunday. That is roughly 45% of the bitcoin taken in the Wave 3 attacks.

The total theft across all attack waves now stands near 1,806 BTC, close to $144 million at current prices. Galaxy identified an additional 58-address victim vault, raising the loss estimate again. About 82% of the exploited funds remain in attacker-controlled addresses, which means more sell pressure is likely as the laundering continues.

How the money moved

Galaxy’s on-chain tracking shows three distinct rounds. First, the attacker routed about 20.5 BTC from the largest vault through THORChain, a decentralized exchange that swaps bitcoin for assets on other chains. The proceeds landed on Ethereum. Two days later, 15.48 BTC from the second-largest vault went into a CoinJoin transaction, which combines bitcoin from many users so inputs cannot be matched to outputs. On Sept. 6, another 61.12 BTC from 10 vaults followed the same CoinJoin route.

The attacker is working through the vaults in order of size and has now emptied the 11 largest. The next 10 hold 30.81 BTC combined. Vaults ranked 61 through 293 hold another 33.77 BTC in aggregate, small amounts that add up once prices rise.

A firmware flaw from 2021

The thefts trace back to a weakness in Coinkite’s firmware that dates to 2021. Randomness during seed phrase generation was compromised, which let the attacker brute-force the private keys behind single-signature wallets. The attacker then created 293 two-of-two multisignature vaults, one per victim, to hold the stolen coins. The vaults are not victims’ own wallets. Moving the bitcoin requires two keys, both held by the thief.

Coinkite has shipped new firmware, but that does not fix already-compromised wallets. Galaxy and Coinkite both tell affected users to generate fresh seeds on trusted devices and move any remaining funds. Anyone who set up a Coldcard between 2021 and the flaw’s disclosure this year and still holds coins on an old seed should assume the seed is burned.

Why it took so long

The slow drain reflects how brute-forced keys work. The attacker does not need to rush. The keys are known forever, so the thief can empty vaults gradually, watching liquidity conditions and avoiding tripping exchange monitoring. Five days of measured laundering fits that playbook: small THORChain swaps to cross chains first, then CoinJoins to break the trace before any exchange deposit.

Tracing is getting harder, not easier. THORChain moves value across chains without a centralized intermediary that could freeze anything. CoinJoin has been used by thieves and privacy-conscious users alike for years. Galaxy’s researchers still pieced the flow together from public chain data, but recovered funds in cases like this are rare, and victims should not expect much back.

The market backdrop

The laundering lands during a soft week for bitcoin. BTC traded near $79,300 on Tuesday after briefly dipping to $78,680, and about $179 million in crypto positions were liquidated over 24 hours, per CoinGlass, with longs taking most of the damage. Sooner or later some of the attacker’s 97 moved coins and the remaining $100 million in vaults will hit the market, though five-figure daily flows are unlikely to move a market this size.

What it means for hardware wallet users

The episode lands on an industry already arguing about supply chain security. A hardware wallet’s entire promise is that keys are generated and stored offline on trusted hardware. A seed generation flaw breaks that promise at the deepest level, because the user does everything right and the wallet still mints a predictable key.

Practical takeaways are unglamorous. Buy devices from the manufacturer, not resellers. Verify firmware signatures. Generate seeds with dice or another independent entropy source if the wallet supports it. Never assume an old seed is safe just because the coins have sat untouched for years. The Coldcard attacker is proof that a four-year-old flaw still pays.

SourcesCoinDesk, Sept. 7-8, 2026; Galaxy Research on-chain analysis, Sept. 7, 2026; Crypto Briefing; KuCoin News; CoinGlass liquidation data, Sept. 8, 2026.
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch Polkadot Weighs dotUSD Stablecoin With $3M Liquidity Pool Read →