Galaxy Research said the attacker tied to the Coldcard “Wave 3” incident is still moving stolen funds. According to the firm, the attacker created 293 separate 2-of-2 multisig vaults, one for each victim’s assets. The first batch of funds was bridged to Ethereum through THORChain, while the latest transfers have started entering the CoinJoin mixing process.
Galaxy Research said the attacker is processing the largest vaults first, ranked by stolen amount, and has already moved vaults No. 1 through No. 11 in sequence. The next 10 vaults that have not yet been moved hold a combined 30.81 BTC, while vaults ranked No. 61 through No. 293 hold a combined 33.77 BTC.
The firm added that about 45% of the assets stolen in the exploit have been moved so far. It also identified a previously unknown vault involving 58 addresses that spent funds in the same 2-of-2 multisig format seen in Wave 3. If that vault also belongs to a Coldcard victim, the total number of affected vaults could rise to 294 and the total stolen amount could increase to about 1,806 BTC.
Galaxy Research said the attacker behind the Coldcard “Wave 3” incident is still moving stolen funds.
According to the firm, the attacker created 293 separate 2-of-2 multisig vaults, each tied to an individual victim’s assets. The first batch of funds was bridged to Ethereum through THORChain. The latest round of transfers has started entering the CoinJoin mixing process.
Galaxy Research said the attacker is handling the largest pools first, ranked by the amount stolen, and has already moved vaults No. 1 through No. 11 in order. The next 10 vaults that have not yet been moved hold a combined 30.81 BTC. Vaults ranked No. 61 through No. 293 hold a combined 33.77 BTC.
So far, about 45% of the assets stolen in the exploit have been moved, with funds either sent to Ethereum through THORChain or routed into CoinJoin transactions. At the same time, about 82% of the stolen BTC remains at addresses initially controlled by the attacker, while about 18% has already been moved. The flow of funds suggests possible laundering activity.
The transfers also revealed a previously unknown vault. In that case, 58 addresses spent funds together using the same 2-of-2 multisig format seen in Wave 3, and the Wave 3 attacker then forwarded the funds to a hop address used to fund CoinJoin.
The on-chain analysis team currently labels that vault as “cause = open,” but said it likely also belongs to a Coldcard victim. If confirmed, the number of vaults involved in Wave 3 could rise to 294, and the previously reported total stolen in the Coldcard exploit could increase to about 1,806 BTC.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.