NewsCryptoColdcard Wave 3 Exploiter Moves Stolen Funds Through CoinJoin

Coldcard Wave 3 Exploiter Moves Stolen Funds Through CoinJoin

Author: CryptoNewsNet·

Key Takeaways

  • Galaxy Research's Sept. 7 update reported that the Coldcard Wave 3 exploiter created 293 two-of-two multisignature vaults holding victims' bitcoin.
  • The first movements in this wave occurred on Sept. 2, when coins were routed through THORChain and arrived on Ethereum, with later transfers entering CoinJoin rounds.
  • Galaxy did not state a final amount moved or confirm that every attacker-created vault had been emptied.
  • Routing funds through THORChain and CoinJoin complicates transaction-graph analysis, but it does not by itself demonstrate that the proceeds have been successfully laundered.
  • Users with compromised wallet generation must create a new seed with corrected software or trusted hardware, since installing firmware cannot make an exposed recovery phrase secret again.
Coldcard Wave 3 Exploiter Moves Stolen Funds Through CoinJoin

Coldcard Wave 3 Exploiter Moves Stolen Funds Through CoinJoin

The attacker linked to the third wave of Coldcard wallet thefts has begun moving additional bitcoin, routing earlier transfers through THORChain onto Ethereum and directing newer movements into CoinJoin rounds. Galaxy Research documented the activity in a Sept. 7 on-chain update, reporting that the exploiter had created 293 two-of-two multisignature vaults holding victims' coins.

The update records wallet behavior rather than the attacker's identity or intent. Routing funds through cross-chain infrastructure and collaborative Bitcoin transactions can complicate tracing, but it does not by itself demonstrate that the proceeds have been successfully laundered.

Wave 3 Funds Begin Leaving Their Vaults

According to Galaxy, the first movements in this wave occurred on Sept. 2, when coins were sent through THORChain and arrived on Ethereum. The research firm subsequently observed later transfers entering CoinJoin rounds. Its public post did not state a final amount moved or confirm that every vault had been emptied.

A CoinJoin combines inputs and outputs from multiple participants into a single Bitcoin transaction. The construction has long been used by privacy wallets such as Wasabi and Samourai, whose coordination services became focal points for law-enforcement action in recent years — a reminder that mixing, while legal in many jurisdictions, draws heightened scrutiny. The structure makes straightforward transaction-graph analysis more difficult, because an observer cannot simply assume that each input maps to a specific output. Investigators can still rely on timing, amounts, and later spending behavior, though confidence in attribution may decline.

The Latest Movement Follows the Larger Coldcard Incident

Coldcard, built by Canada-based Coinkite, is a popular air-gapped hardware signer among bitcoin self-custody users, which is why the exploit waves have resonated widely in that community. Galaxy had previously connected the third wave to hundreds of attacker-created vaults. Earlier reporting on the Coldcard exploit and the affected bitcoin described a broader theft involving compromised wallet generation, in which vulnerable seeds could be derived by an attacker. The newest transfers shift the case from largely stationary holdings to an active tracing problem.

THORChain and CoinJoin play distinct roles in that path. THORChain enables swaps across native assets without wrapped intermediaries, while CoinJoin operates within Bitcoin by combining transactions. Neither tool is inherently malicious; their relevance here stems from their observed use by addresses Galaxy associates with the exploiter.

Wallet Remediation Remains Separate from Fund Tracing

Following stolen funds does not repair a compromised seed. Users affected by weak wallet generation must create a fresh seed using corrected software or trusted hardware and transfer their remaining assets. Simply installing new firmware cannot make an already exposed recovery phrase secret again.

Galaxy's update gives investigators a new sequence to monitor, but recovery is not guaranteed. Any definitive claim about attribution, the amount mixed, or the destination of the swapped assets will require additional on-chain evidence and potentially information from the services that receive the funds. For affected users and exchanges, the practical next step is watching whether swapped Ethereum-side assets reach services with identification requirements, which has historically been a choke point in comparable tracing cases.