The perpetrator behind the third wave of the Coldcard hardware wallet breach moved 97.09 BTC worth $7.7 million on Monday, representing 45% of the total loot stolen in this wave. Initial laundering activity began on Sept. 2, when the attacker routed roughly 20.5 BTC through THORChain and exited into Ethereum, with 20.56 BTC successfully arriving on the Ethereum network.
The remaining Bitcoin was moved Sunday night into CoinJoin rounds. CoinJoin is a Bitcoin privacy technique that mixes transactions from multiple users to break on-chain tracking trails. Following the mixing process, 57.24 BTC is currently sitting unspent as change at a single address. Galaxy Research estimates the trail for an additional 19+ BTC concludes at this point.
The attacker set up 293 2-of-2 multisig wallets, each assigned to an individual victim, and has been draining them sequentially starting with the largest balances. So far, 11 wallets have been completely drained. The next 10 targeted wallets hold 30.81 BTC, while the 233 wallets with the smallest balances contain 33.77 BTC.
Root Cause Traced to 2021 Update
The vulnerability traces back to Coinkite firmware released in March 2021. That update shifted the seed generation process from a hardware random number generator chip to software, reducing entropy from 128 bits down to as low as 40 bits.
Wallet draining activity began on July 30, 2026. Coinkite has since released updated firmware for Mk4 and Mk5 models (version 5.6.2) as well as the Q model (version 1.5.2Q). The updated software requires users to supply their own entropy through keypresses, dice rolls, or coin flips.
The update cannot repair seeds that were already created under older firmware versions. Wallet owners must generate a new seed and immediately transfer their funds. Coinkite CEO Rodolfo Novak issued an apology letter on July 31, while a comprehensive technical report on the incident remains underway.
Scale of Losses Continues to Grow
Research by Galaxy identified an unidentified vault holding 58 addresses strongly believed to belong to other Coldcard exploit victims. This finding lifts total confirmed exploit losses to 1,806 BTC, equivalent to $143.9 million.
Losses could escalate further. Indications point to an unconfirmed fourth wave of 638.5 BTC, which would push total stolen funds past 2,400 BTC. No further movements have been observed from the attacker since Aug. 6.
Despite the massive sums on the move, the attacker’s laundering pace has been slow. About 82% of all coins stolen across every wave remains in the initial deposit addresses where the attacker first placed them.
Via Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




