Galaxy: Coldcard Wave 3 attacker has moved 45% of stolen Bitcoin

AI Market Summary
Galaxy Research reports the Coldcard Wave 3 attacker has already spent 97.09 BTC and is actively laundering via CoinJoin, after earlier routing BTC into ETH through THORChain. The findings raise the estimated total stolen to as much as 1,806 BTC if newly linked addresses are included, while most funds remain parked in attacker-controlled wallets. Ongoing coin movement can elevate near-term sell-side and compliance risk across BTC venues.
Impact level
● Medium
Affected assets
BTC/USDT-1.06%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Galaxy Research said the attacker responsible for the third wave of Coldcard Bitcoin wallet thefts has already moved 45% of the funds taken in that phase. The firm estimates 97.09 BTC—about $7.8 million at Monday's prices—has been spent so far. Galaxy said on X that the latest activity involved CoinJoin transactions on Sunday. It followed a Sept. 2 transaction in which the exploiter swapped stolen Bitcoin into Ethereum via THORChain. Galaxy added that the operator continues to move the stolen coins. Tracking by the research firm indicates the attacker is sweeping funds from the largest vaults first. Vaults ranked 1 through 11 have already been moved. The next 10 untouched vaults hold a combined 30.81 BTC, while 33.77 BTC is distributed across smaller vaults ranked 61 through 293. In a Monday update, Galaxy also tied the operator to a previously unidentified vault consisting of 58 addresses that it believes are linked to Coldcard victims. Including those addresses would lift the total stolen across the Coldcard attacks to 1,806 BTC, valued at about $143.9 million at current prices. Galaxy said roughly 82% of the stolen funds remain in the original attacker-controlled addresses, with the rest moved in apparent laundering activity. The thefts began July 30 and stem from a firmware bug Coinkite shipped in 2021. Galaxy said the flaw reduced the randomness used when Coldcard devices generated wallet seeds, allowing attackers to brute-force private seed phrases and drain single-signature addresses without physical access to the devices. By mid-August, Galaxy had identified about 1,779 BTC stolen from 190 victims and more than 8,600 addresses. The firm has also flagged the possibility of a fourth wave of thefts, though it has not confirmed one. Disclaimer: This content is for informational purposes only and is not financial advice. Views expressed may reflect the author's opinions and do not represent The Crypto Basic. Readers should conduct their own research before making investment decisions. The Crypto Basic is not responsible for any financial losses.