HomeMarket News

Coldcard Attacker Moves 45% of Wave 3 Bitcoin Through CoinJoin

Coldcard Attacker Moves 45% of Wave 3 Bitcoin Through CoinJoin

Summary

  • Coldcard attacker moved 97.09 BTC through CoinJoin, representing 45% of assets stolen during the third identified wave within the campaign.
  • A 2021 firmware flaw weakened wallet seed randomness, allowing attackers to brute-force private phrases and drain single-signature Bitcoin wallets remotely.
  • Galaxy linked 1,806 BTC worth $143.9 million to the exploit, while 82% remains inside original attacker-controlled addresses under blockchain monitoring.

 


The attacker behind the Coldcard hardware wallet exploits has moved 45% of the Bitcoin stolen during the third attack wave. According to Galaxy Research, the Wave 3 operator transferred 97.09 Bitcoin (BTC), worth approximately $7.8 million.


The exploiter processed those assets through CoinJoin transactions, making the movement of stolen funds harder to trace. CoinJoin combines several Bitcoin payments within one transaction, reducing the visibility of links between senders and recipients.


However, Galaxy’s analysis indicates that the attacker follows a calculated order when selecting compromised wallets. The operator has targeted the affected vaults according to their balances, beginning with wallets holding the largest amounts.


Vaults ranked between one and eleven have already recorded movements linked to the laundering operation. Meanwhile, the next ten untouched vaults contain a combined 30.81 BTC, based on Galaxy’s findings.


Another group of smaller vaults, ranked between 61 and 293, collectively holds 33.77 BTC. This transfer pattern provides investigators with possible indicators regarding which compromised wallets the attacker could target.


Before using CoinJoin, the exploiter converted stolen Bitcoin (BTC) into Ethereum (ETH) through THORChain on September 2. THORChain allows users to exchange assets across different blockchains without relying on a centralized cryptocurrency exchange.


The conversion marked another effort to separate the stolen assets from their original Coldcard addresses. Galaxy reported that 82% of all stolen funds still remain inside the attacker’s original wallets. Consequently, only 18% has moved through transactions that appear connected to laundering or asset conversion activities.


Also Read: PYTH Price Prediction 2026–2030: Can Pyth Network Reach $0.20 Soon?


Coldcard Firmware Bug Weakened Wallet Seed Generation

The Coldcard thefts began on July 30 and originated from a firmware flaw that Coinkite shipped in 2021. The vulnerability affected the method that certain Coldcard devices used to generate wallet seeds for their owners.


These devices produced seed phrases with insufficient randomness, weakening the security protecting corresponding private keys. Attackers could therefore brute-force vulnerable seed phrases and identify the Bitcoin addresses linked to those phrases.


Significantly, the attackers drained single-signature wallets without physically obtaining or interacting with the affected Coldcard devices. By mid-August, Galaxy had connected approximately 1,779 stolen BTC to 190 victims and more than 8,600 addresses.


Researchers grouped the incidents into separate attack waves using transaction behavior, compromised addresses, and wallet movement patterns. Galaxy also identified the possibility of a fourth attack wave, although the research firm has not confirmed it.


Previously Unknown Vault Raises Estimated Bitcoin Losses

Moreover, the Wave 3 exploiter combined funds from a previously unknown vault containing 58 addresses. Galaxy believes those addresses likely belong to additional Coldcard victims affected by the same seed-generation weakness.


Adding that vault would raise the estimated theft to 1,806 BTC, worth approximately $143.9 million. The revised figure expands both the suspected victim pool and the scale of Bitcoin linked to the exploit.


Blockchain researchers can still observe movements from identified addresses, although CoinJoin complicates direct transaction attribution. Investigators may examine transfer timing, shared inputs, recurring amounts, and connections between wallets to follow the stolen assets.


The attacker’s preference for larger vaults also reveals an organized approach toward moving and laundering compromised holdings. Most stolen Bitcoin remains inside known attacker-controlled addresses, leaving a substantial amount visible to blockchain investigators. Nevertheless, further movements could affect remaining vaults as the operator processes funds from larger balances toward smaller wallets.


Also Read: Liquid Hackers Offer to Return Most of 4,000 BTC Once Vulnerability Is Fixed