Coldcard Exploiter Moves 45% of Wave 3 Stolen Bitcoin Through CoinJoin

54 minute ago 5 sources negative

Key takeaways:

  • CoinJoin usage signals sophisticated laundering, increasing regulatory pressure on Bitcoin privacy tools.
  • THORChain's role in laundering may attract scrutiny affecting cross-chain protocol activity.
  • Remaining 82% of stolen BTC could overhang market if launderers accelerate movements.

The attacker behind the Coldcard hardware wallet exploits has moved 45% of the Bitcoin stolen during the third attack wave, according to Galaxy Research. The Wave 3 operator transferred 97.09 BTC, worth approximately $7.8 million, through CoinJoin transactions on Sunday. CoinJoin combines multiple Bitcoin payments into a single transaction, making the movement of stolen funds harder to trace.

Before using CoinJoin, the exploiter converted stolen Bitcoin into Ethereum through THORChain on September 2. Galaxy said the attacker appears to be moving funds from the largest vaults first, with vaults ranked from 1 to 11 already moved. The next 10 untouched vaults hold 30.81 BTC, while smaller vaults ranked from 61 to 293 hold another 33.77 BTC.

The thefts began on July 30 and were linked to a firmware bug that Coinkite shipped in 2021. The flaw weakened seed generation on some Coldcard devices, reducing randomness and making private seed phrases easier to brute-force. Attackers could then drain single-signature wallet addresses without gaining physical access to the hardware device. By mid-August, Galaxy had identified about 1,779 BTC stolen from 190 victims and linked the thefts to more than 8,600 addresses.

Galaxy raised its total loss estimate after identifying a previously unknown vault made up of 58 addresses, likely tied to additional Coldcard victims. Including that vault would bring the estimated total theft to 1,806 BTC, worth approximately $143.9 million. Galaxy said 82% of all stolen Coldcard funds remain in original attacker-controlled addresses, while the rest has moved through transactions linked to laundering activity. The firm also mentioned the possibility of a fourth attack wave, though it has not been confirmed.

Previously on the topic:
Sep 3, 2026, 1:55 p.m.
Coldcard Hacker Swaps Stolen Bitcoin for Ether via THORChain
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.