Coldcard attacker moves 97.09 BTC in third wave as 11 largest vaults are drained

Coldcard attacker moves 97.09 BTC in third wave as 11 largest vaults are drained

N
News Editor
2026-09-07 10:07:37
New on-chain movements tied to the Coldcard wallet exploit show the attacker has moved 97.09 BTC in the third wave of thefts, according to Galaxy Research. The transfers took place over the past 48 hours in three separate transactions and account for about 45% of the bitcoin stolen in that wave. Galaxy said the attacker appears to be emptying vaults in descending order of size, with the 11 largest vaults now fully drained. The report said the third wave involves 293 vaults, which Galaxy describes as attacker-controlled 2-of-2 multisig structures created after exploiting a flaw in Coldcard seed generation. If one additional vault with the same format but an unconfirmed origin is included, the total would rise to 294. Across all three waves, the broader Coldcard incident has reached about 1,806 BTC stolen, with roughly 82% of the funds still sitting at addresses initially controlled by the attacker and 18% already moved. The underlying issue traces back to a firmware vulnerability disclosed on July 30, 2026, affecting Coldcard MK3 devices. Coinkite has released patched firmware, but said wallets already exposed cannot be fixed through an update alone and users must create a new seed phrase and move funds to fresh addresses.

An attacker tied to the third wave of the Coldcard hardware wallet thefts has moved 97.09 BTC, or about $7.7 million, according to Galaxy Research. The amount represents 45% of the bitcoin stolen in that wave.

Galaxy said the funds were moved in three transactions over the past 48 hours. Its on-chain analysis suggests the attacker is draining vaults from largest to smallest. The 11 biggest vaults have now been emptied. Including the first and second waves, the broader Coldcard exploit has resulted in roughly 1,806 BTC stolen.

Three transfers over 48 hours

Galaxy Research broke the latest movements into three steps:

  • The first transfer moved 20.5 BTC out of the largest vault through THORChain.
  • The second took place on Sept. 5, when 15.48 BTC from the second-largest vault entered a CoinJoin transaction.
  • The third came on Sept. 6, when 61.12 BTC was gathered from 10 vaults and then sent into CoinJoin.

The report described THORChain and CoinJoin as two different methods used to obscure fund flows. THORChain is a cross-chain swap protocol that can move BTC into assets on other networks and back again, while CoinJoin combines transactions from multiple users in the same block to make input-output mapping harder.

293 vaults involved in the third wave

Galaxy said these vaults are not wallet addresses directly held by victims. Instead, after exploiting a flaw in Coldcard seed generation, the attacker created a 2-of-2 multisig vault for each victim and concentrated stolen bitcoin into addresses under the attacker's control.

The third wave involves 293 vaults. Galaxy's breakdown shows:

  • The 11 largest vaults have been fully drained.
  • Vaults ranked 12th through 21st still hold 30.81 BTC.
  • Vaults ranked 61st through 293rd still hold a combined 33.77 BTC.

Galaxy said the pattern points to a largest-first strategy. If one additional vault with the same format, funded by 58 addresses, is counted despite its source not yet being confirmed, the third-wave total would increase to 294 vaults.

Total stolen reaches about 1,806 BTC

Across the first, second, and third waves, the Coldcard incident has reached about 1,806 BTC stolen, or roughly $143.9 million based on the valuation cited in the report. About 82% of the bitcoin remains at addresses initially controlled by the attacker, while 18% has moved. Galaxy said the transaction pattern points to an effort to hide the trail of funds.

Firmware flaw exposed in July

Coldcard is a bitcoin hardware wallet developed by Coinkite and marketed around fully offline operation without reliance on external servers. The underlying issue stems from a firmware vulnerability disclosed on July 30, 2026.

According to the report, the attacker exploited insufficient entropy in the random number generator used by some Coldcard MK3 devices when creating wallet seeds. That weakness meant some private keys could be predicted externally. The report said an attacker did not need physical access to the wallet. Knowing the affected firmware version and device batch could be enough to derive the corresponding private key and steal assets.

Coinkite has published a notice and patched firmware on its official blog. At the same time, the company said wallets already affected cannot be fixed through a firmware update alone. Users must generate a new seed phrase and move assets to a new wallet address. The report added that this can be difficult for some users, especially if original backups have been lost or funds are spread across several older wallets.

Security assumptions around hardware wallets face another test

The case has drawn attention because it challenges the long-held view that cold wallets are the final line of defense for bitcoin holders. The report noted that exchange hacks, smart contract exploits, and bridge thefts have been common in recent years, while hardware wallets have generally retained a stronger security image.

In this case, the problem sits at the random number generation layer. The report said that means attackers may be able to predict private keys at scale without breaching a server or using phishing. It also compared the incident with the entropy issue that hit Trezor in late 2025, saying both cases point to the same risk: hardware wallet security depends heavily on the quality of cryptographic implementation in firmware.

For Coldcard MK3 users, the original report urged checking whether the installed firmware version falls within the affected range. It also said users should review how assets and backups are distributed rather than relying on a single wallet brand.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.