Galaxy Research said on Sept. 7 that the attacker behind the Coldcard “Wave 3” incident is still moving stolen funds.
According to the firm, the attacker created 293 separate 2-of-2 multisig vaults in this phase, with each vault corresponding to a victim’s assets. The first batch of funds was bridged to Ethereum through THORChain on Sept. 2. The latest round of transfers has now started entering the CoinJoin mixing process.
Largest vaults are being processed first
Galaxy Research said the Wave 3 attacker is moving funds in order of stolen amount, starting with the largest holdings. So far, vaults ranked No. 1 through No. 11 have been moved.
The next 10 vaults that have not yet been moved hold a combined 30.81 BTC. Vaults ranked No. 61 through No. 293 hold a combined 33.77 BTC.
At this point, about 45% of the assets stolen in the exploit have been moved, with funds either routed to Ethereum through THORChain or sent into CoinJoin transactions.
A previously unknown vault was also identified
The transfers also revealed a previously unknown vault. In that case, 58 addresses spent funds using the same 2-of-2 multisig structure seen in Wave 3, and the Wave 3 attacker then forwarded those funds to a hop address used to fund CoinJoin.
The onchain analysis team currently labels that vault as 「cause = open」, but said it likely also belongs to Coldcard victims. If so, the number of vaults involved in Wave 3 could rise to 294, and the previously reported total stolen in the Coldcard exploit could increase to about 1,806 BTC.
Most stolen BTC remains at the attacker’s initial addresses
Galaxy Research said about 82% of the stolen BTC remains at addresses initially controlled by the attacker, while about 18% has been moved. The destination pattern suggests the funds may be going through a laundering process.

