An attacker tied to the third wave of the Coldcard hardware wallet thefts has moved 97.09 BTC, or about $7.7 million, according to Galaxy Research. The amount represents 45% of the bitcoin stolen in that wave.
Galaxy said the funds were moved in three transactions over the past 48 hours. Its on-chain analysis suggests the attacker is draining vaults from largest to smallest. The 11 biggest vaults have now been emptied. Including the first and second waves, the broader Coldcard exploit has resulted in roughly 1,806 BTC stolen.
Three transfers over 48 hours
Galaxy Research broke the latest movements into three steps:
- The first transfer moved 20.5 BTC out of the largest vault through THORChain.
- The second took place on Sept. 5, when 15.48 BTC from the second-largest vault entered a CoinJoin transaction.
- The third came on Sept. 6, when 61.12 BTC was gathered from 10 vaults and then sent into CoinJoin.
The report described THORChain and CoinJoin as two different methods used to obscure fund flows. THORChain is a cross-chain swap protocol that can move BTC into assets on other networks and back again, while CoinJoin combines transactions from multiple users in the same block to make input-output mapping harder.
293 vaults involved in the third wave
Galaxy said these vaults are not wallet addresses directly held by victims. Instead, after exploiting a flaw in Coldcard seed generation, the attacker created a 2-of-2 multisig vault for each victim and concentrated stolen bitcoin into addresses under the attacker's control.
The third wave involves 293 vaults. Galaxy's breakdown shows:
- The 11 largest vaults have been fully drained.
- Vaults ranked 12th through 21st still hold 30.81 BTC.
- Vaults ranked 61st through 293rd still hold a combined 33.77 BTC.
Galaxy said the pattern points to a largest-first strategy. If one additional vault with the same format, funded by 58 addresses, is counted despite its source not yet being confirmed, the third-wave total would increase to 294 vaults.
Total stolen reaches about 1,806 BTC
Across the first, second, and third waves, the Coldcard incident has reached about 1,806 BTC stolen, or roughly $143.9 million based on the valuation cited in the report. About 82% of the bitcoin remains at addresses initially controlled by the attacker, while 18% has moved. Galaxy said the transaction pattern points to an effort to hide the trail of funds.
Firmware flaw exposed in July
Coldcard is a bitcoin hardware wallet developed by Coinkite and marketed around fully offline operation without reliance on external servers. The underlying issue stems from a firmware vulnerability disclosed on July 30, 2026.
According to the report, the attacker exploited insufficient entropy in the random number generator used by some Coldcard MK3 devices when creating wallet seeds. That weakness meant some private keys could be predicted externally. The report said an attacker did not need physical access to the wallet. Knowing the affected firmware version and device batch could be enough to derive the corresponding private key and steal assets.
Coinkite has published a notice and patched firmware on its official blog. At the same time, the company said wallets already affected cannot be fixed through a firmware update alone. Users must generate a new seed phrase and move assets to a new wallet address. The report added that this can be difficult for some users, especially if original backups have been lost or funds are spread across several older wallets.
Security assumptions around hardware wallets face another test
The case has drawn attention because it challenges the long-held view that cold wallets are the final line of defense for bitcoin holders. The report noted that exchange hacks, smart contract exploits, and bridge thefts have been common in recent years, while hardware wallets have generally retained a stronger security image.
In this case, the problem sits at the random number generation layer. The report said that means attackers may be able to predict private keys at scale without breaching a server or using phishing. It also compared the incident with the entropy issue that hit Trezor in late 2025, saying both cases point to the same risk: hardware wallet security depends heavily on the quality of cryptographic implementation in firmware.
For Coldcard MK3 users, the original report urged checking whether the installed firmware version falls within the affected range. It also said users should review how assets and backups are distributed rather than relying on a single wallet brand.

