๐Ÿ“… Tuesday, 8 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Hacker Coldcard Mulai Cuci $7,7 Juta Lewat CoinJoin - Tapi 82% Curian Masih Menganggur di Alamat Pertama

Coldcard Hacker Begins Laundering $7.7M via CoinJoin - But 82% of Stolen Funds Still Sit in Initial Addresses

The perpetrator behind the third wave of the Coldcard hardware wallet breach moved 97.09 BTC worth $7.7 million on Monday, representing 45% of the total loot stolen in this wave. Initial laundering activity began on Sept. 2, when the attacker routed roughly 20.5 BTC through THORChain and exited into Ethereum, with 20.56 BTC successfully arriving on the Ethereum network.

The remaining Bitcoin was moved Sunday night into CoinJoin rounds. CoinJoin is a Bitcoin privacy technique that mixes transactions from multiple users to break on-chain tracking trails. Following the mixing process, 57.24 BTC is currently sitting unspent as change at a single address. Galaxy Research estimates the trail for an additional 19+ BTC concludes at this point.

The attacker set up 293 2-of-2 multisig wallets, each assigned to an individual victim, and has been draining them sequentially starting with the largest balances. So far, 11 wallets have been completely drained. The next 10 targeted wallets hold 30.81 BTC, while the 233 wallets with the smallest balances contain 33.77 BTC.

Root Cause Traced to 2021 Update

The vulnerability traces back to Coinkite firmware released in March 2021. That update shifted the seed generation process from a hardware random number generator chip to software, reducing entropy from 128 bits down to as low as 40 bits.

Wallet draining activity began on July 30, 2026. Coinkite has since released updated firmware for Mk4 and Mk5 models (version 5.6.2) as well as the Q model (version 1.5.2Q). The updated software requires users to supply their own entropy through keypresses, dice rolls, or coin flips.

The update cannot repair seeds that were already created under older firmware versions. Wallet owners must generate a new seed and immediately transfer their funds. Coinkite CEO Rodolfo Novak issued an apology letter on July 31, while a comprehensive technical report on the incident remains underway.

Scale of Losses Continues to Grow

Research by Galaxy identified an unidentified vault holding 58 addresses strongly believed to belong to other Coldcard exploit victims. This finding lifts total confirmed exploit losses to 1,806 BTC, equivalent to $143.9 million.

Losses could escalate further. Indications point to an unconfirmed fourth wave of 638.5 BTC, which would push total stolen funds past 2,400 BTC. No further movements have been observed from the attacker since Aug. 6.

Despite the massive sums on the move, the attacker’s laundering pace has been slow. About 82% of all coins stolen across every wave remains in the initial deposit addresses where the attacker first placed them.

Via Decrypt.

Read also: Tether Erases Traces of Orionx Investment - Chilean Exchange Closes Permanently After $7M in Customer Assets Vanish


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share