On-chain activity has resumed in the Coldcard hardware wallet theft after more than a month of silence. Blockchain analytics firm Galaxy Digital said the attacker has moved about 45% of the stolen funds tied to the so-called Wave 3 tranche, or 97.09 BTC, worth about $7.8 million based on Monday prices. The tracking was first disclosed by The Block, citing a Galaxy report.
The attacker moved funds from the largest addresses first
Galaxy said the withdrawals followed a distinct pattern. Funds were moved in descending order based on address balances, and the addresses ranked No. 1 through No. 11 have now been emptied.
According to Galaxy’s on-chain analysis, the funds were swapped into ether through cross-chain protocol THORChain on Sept. 2. They were then further broken up through CoinJoin mixing transactions on Sunday.
Most of the stolen funds have not moved. Galaxy said about 82% remains in addresses controlled by the attacker. Addresses ranked No. 12 through No. 21 still hold 30.81 BTC, while addresses ranked No. 61 through No. 293 collectively hold 33.77 BTC and have not been touched. In other words, the attacker has so far moved the larger positions first, while most of the remaining stolen funds are still sitting in place.
Galaxy identified a previously uncounted vault
During the investigation, Galaxy said it found a hidden vault that had not been included in earlier estimates. The firm linked it through co-spend analysis and said the vault contained 58 addresses that likely also belonged to Coldcard victims.
After adding those addresses, the known loss in the case was revised up to about 1,806 BTC, worth roughly $143.9 million at current prices. Galaxy said the incident now affects 190 victims and more than 8,600 addresses.
The firm also said a possible Wave 4 cannot be ruled out, although that has not been confirmed.
The root cause traces back to a 2021 firmware flaw
The theft stemmed from a randomness flaw in 2021 firmware used by early Coldcard devices. Because wallet seeds were generated with insufficient entropy, the attacker was able to brute-force private key seeds and drain addresses using single-signature setups.
Chain News had previously reported that the thefts can be traced back to July 30. Estimated losses at one point exceeded $150 million, and the withdrawals were split into multiple waves over time.
For self-custody users holding older Coldcard devices, the key issue remains whether their seeds fall within the affected generation range. The incident is also continuing to test market confidence in hardware wallets and self-custody.

