BlocktoBlockto
Coldcard Hardware Wallet Attacker Moves Nearly Half of Latest Stolen Funds
TECH

Photo: Illustrative

Coldcard Hardware Wallet Attacker Moves Nearly Half of Latest Stolen Funds

The individual behind the ongoing Coldcard hardware wallet exploits has moved 45% of the bitcoin taken during the third wave of attacks, according to Galaxy Research. The attacker previously converted a portion of stolen bitcoin into ether through THORChain earlier this month, before shifting strategy and running additional funds through CoinJoin transactions over the weekend. So far, more than 97 bitcoin, worth close to $7.8 million, has been spent.

Laurisa
By Laurisa

Junior Author · September 7, 2026

2 min
Key takeaways
The individual behind the ongoing Coldcard hardware wallet exploits has moved 45% of the bitcoin taken during the third wave of attacks, according to Galaxy Research.
The attacker previously converted a portion of stolen bitcoin into ether through THORChain earlier this month, before shifting strategy and running additional funds through CoinJoin transactions over the weekend.
So far, more than 97 bitcoin, worth close to $7.8 million, has been spent.

The individual behind the ongoing Coldcard hardware wallet exploits has moved 45% of the bitcoin taken during the third wave of attacks, according to Galaxy Research. The attacker previously converted a portion of stolen bitcoin into ether through THORChain earlier this month, before shifting strategy and running additional funds through CoinJoin transactions over the weekend. So far, more than 97 bitcoin, worth close to $7.8 million, has been spent.

Funds Being Moved in Order of Size

Galaxy noted that the attacker has been withdrawing stolen coins from largest to smallest vaults, having already cleared the eleven largest holdings. The next set of untouched vaults holds nearly 31 bitcoin, while a larger group of smaller vaults collectively contains close to 34 bitcoin. Despite the recent activity, the majority of stolen funds, roughly 82%, remain untouched in the original attacker-controlled wallets.

Root Cause Traces Back to 2021 Firmware Flaw

The thefts, which began in late July, stem from a firmware issue introduced by Coinkite in 2021 that weakened the randomness used to generate wallet seeds.

This flaw allowed attackers to brute force private keys and drain single signature wallets without physically accessing the devices. By mid-August, researchers had traced roughly 1,779 bitcoin stolen from 190 victims across more than 8,600 addresses, with a newly identified vault potentially pushing total losses to around 1,806 bitcoin, valued near $143.9 million at current prices. Researchers have not ruled out the possibility of a fourth wave of attacks.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.