Coldcard Attacker Moves $7.7M in Bitcoin (BTC) From Wave 3 Vaults

Coldcard attacker has moved 97.09 BTC (~$7.7M) from Wave 3 vaults via THORChain and CoinJoin; 82% of the stolen Bitcoin remains unmoved on-chain.

(11:36 AM UTC)
4 min read
AI SummaryAI
  • Coldcard attacker moved 97.09 BTC, about $7.7 million, from Wave 3 vaults
  • First exit on September 2 sent roughly 20.5 BTC over THORChain to Ethereum
  • March 2021 firmware bug cut seed entropy from 128 bits to as low as 40
  • Total documented Coldcard exploit loss estimated at 1,806 BTC, about $143.9 million
v3xn8bwc

97 BTC Leaves Wave 3 Vaults

The attacker behind the Coldcard hardware-wallet thefts has moved 97.09 Bitcoin (BTC) out of the exploit's third wave — roughly 45% of that haul, worth about $7.7 million at Monday's prices — in a sequence of staged exits that Galaxy Research traced on-chain and laid out in a Monday research thread. The first movement came on September 2, when approximately 20.5 BTC left the largest vault through THORChain, the cross-chain swap protocol, and resurfaced as Ethereum-side assets, the same class of cross-chain instruments as wrapped Bitcoin; only 20.56 BTC actually completed the hop, with the difference absorbed along the route. Over the weekend the tactics changed: Sunday-night spending went into CoinJoin rounds, a privacy technique that pools transactions from multiple users into one block so inputs cannot be matched to outputs. Of the coins sent that way, 57.24 BTC sits unspent as CoinJoin change in a single address, and the tracking trail ends on roughly 19 BTC more. The vault architecture is the attacker's own construction — the thief created 293 two-of-two multisig vaults, one per victim, and has been emptying them strictly in order of size, a whale-grade siphon that targets the largest balance first. Eleven vaults are now empty, the next ten hold 30.81 BTC between them, and the 233 smallest still hold 33.77 BTC. The pattern resolves into three withdrawals: 20.5 BTC on September 2, 15.48 BTC into CoinJoin on September 5, and 61.12 BTC pooled from ten vaults on September 6. No sweep had been logged since August 6 before this weekend's burst, so after a month of stillness the operator has resumed cash-out activity on what looks like a fixed liquidation schedule rather than opportunistic testing.

Root Cause: A 2021 Seed-Generation Defect

The technical root of the theft sits in firmware Coinkite shipped in March 2021. That release rerouted seed generation off the device's hardware random-number chip onto a software stand-in, collapsing key strength from 128 bits of entropy to as low as 40. With entropy that thin, the attacker could reconstruct private keys offline and drain single-signature addresses without ever physically touching a device; the sweeps began on July 30. Coinkite's remediation is real but limited. Overhauled firmware — Mk4/Mk5 5.6.2 and Q 1.5.2Q — now forces owners to supply their own randomness through key presses, dice rolls or coin flips. The update, however, cannot repair a seed created under the flawed version: anyone whose wallet was generated on affected firmware has to produce a fresh seed and move every coin to it, a chore complicated for users who lost original backups or spread holdings across multiple old wallets. Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31, writing that the company would have to “earn back our users' trust,” and a full technical postmortem is still in preparation. The published loss figure may still grow. Monday's tracking flagged a previously unknown vault fed by 58 addresses, marked unconfirmed but formatted like the others; if it proves to be another Coldcard victim, the exploit's documented total rises to about 1,806 BTC, or $143.9 million. Galaxy has also carried an unconfirmed fourth wave of 638.5 BTC since August, which would take the cumulative figure past 2,400 BTC. Across all confirmed waves, 82% of the stolen coins remain where the attacker first placed them, with only 18% moved so far.

82% of the Stolen BTC Still Untouched

Our reading of the on-chain ledger points to an operator executing a plan, not improvising: the strict largest-first vault order and the mid-stream switch from THORChain to CoinJoin show familiarity with both cross-chain routing and privacy tooling. The practical tells for the next move are already visible — the 57.24 BTC of unspent CoinJoin change parked in one address, the 233 smaller vaults still loaded, and a possible fourth wave of 638.5 BTC that remains unconfirmed. With 82% of the haul stationary, we expect further sweeps, and holders of affected Mk3 devices who continue to HODL on a flawed seed remain exposed no matter what the Bitcoin market does next.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.