Coldcard Hacker Moves 45% of Third-Wave Stolen Bitcoin as Losses Climb to $143.9 Million
Key Takeaways
- •The hacker has moved approximately 45% of the Bitcoin stolen in the third wave of the Coldcard attack, using CoinJoin mixing after earlier converting funds to ETH through THORChain.
- •The breach originated from a 2021 Coinkite firmware flaw that limited randomness in seed generation, allowing brute-force attacks on certain wallet seeds.
- •Galaxy Research estimates that around 1,779 BTC was stolen from roughly 190 victims across more than 8,600 addresses by mid-August.
- •Total losses could rise to 1,806 BTC, worth about $143.9 million, after the attacker co-spent funds from an additional vault holding 58 victim addresses.
- •Approximately 82% of the stolen Bitcoin remains in the hacker's original address, keeping most of the funds traceable for now, though Galaxy has flagged a possible but unconfirmed fourth wave of attacks.

The Coldcard Wallet hack has entered a new phase, with the attacker behind the breaches having moved roughly 45% of the Bitcoin stolen in the third wave of attacks, according to Galaxy Research (post).
Galaxy Research noted that the hacker continues to transfer large amounts of the stolen BTC. After previously moving a portion of the funds through THORChain and exchanging them for ETH on September 2, the attacker has now turned to CoinJoins to obscure the trail of the stolen funds. CoinJoin is a privacy technique that mixes a user's transactions with those of other participants, making it significantly harder for blockchain analysts to trace individual coins — a common obstacle for investigators and exchanges attempting to freeze illicit proceeds.
Approximately 97.09 BTC, worth an estimated $7.8 million, has already been spent from the impacted vaults.
Attacker Targets Largest Vaults First
According to Galaxy, the hacker appears to be draining the stolen Bitcoin based on vault size, working from the vaults holding the most coins down to those holding the least. Vaults #1 through #11 have already been moved by the attacker. The next 10 vaults, which remain untouched, hold roughly 30.81 BTC, while vaults #61 to #293 contain a combined 33.77 BTC.
Only a small fraction of the stolen money has been transferred to other wallets. Galaxy estimates that 82% of the Bitcoin stolen in the broader Coldcard hack still sits in the original address controlled by the hacker. The fact that the majority of funds remain unmoved matters for victims and observers: clustering in a single address keeps the loot traceable for now, while laundering techniques such as cross-chain swaps and mixing gradually erode that visibility.
Firmware Bug Linked to the Hack
The Coldcard Wallet hack began on July 30 and was tied to a flaw in firmware supplied by Coinkite in 2021. The vulnerability stemmed from a limitation in the randomness used when Coldcard devices generated wallet seeds, leaving certain seeds open to brute-force attacks. As a result, hackers were able to derive private seed phrases and withdraw Bitcoin from compromised single-signature addresses. Seed entropy failures are among the most severe classes of hardware wallet flaws, because they undermine the device's core function — generating keys that only the owner could know — and affected users had no straightforward way to detect that their seeds were weaker than expected.
By mid-August, Galaxy Research estimated that approximately 1,779 BTC had been stolen from roughly 190 victims across more than 8,600 addresses.
Losses Could Reach $143.9 Million
The total damage from the Coldcard hack may exceed earlier expectations. Galaxy indicated that the hacker co-spent funds from an additional vault containing 58 addresses belonging to Coldcard victims, which would raise the number of lost coins to 1,806 BTC. At current rates, the lost Bitcoin is worth approximately $143.9 million.
Galaxy has also raised the possibility of another set of related cyberattacks, referred to as "Wave 4," though the firm has not confirmed the existence of a fourth wave. Whether further waves materialize, and whether exchanges or chain-analytics firms manage to flag the mixed funds, will shape how much of the stolen Bitcoin can ultimately be traced or recovered.
The continued movement of the stolen Bitcoin indicates that the attack on Coldcard is still active, with the hacker employing tactics such as cross-chain swaps and CoinJoin to obscure the trail.
Related: Galaxy Research: Coldcard Exploit Abates as Total Losses Climb to at Least 1,700 BTC