Coldcard Hacker Moves $7.7M, Nearly Half of Third-Wave Bitcoin Haul
An attacker who exploited a Coldcard hardware wallet vulnerability has moved approximately $7.7 million in stolen Bitcoin from the third wave of thefts, representing nearly half of that wave's total haul. The perpetrator has constructed 293 separate vaults for the stolen funds and is systematically emptying them by size, with the majority of stolen Bitcoin across all waves still remaining unmoved.

Why It Matters
This ongoing movement of stolen cryptocurrency demonstrates both the attacker's methodical approach to laundering the proceeds and the persistent security risks facing hardware wallet users even after patches are released. The incident underscores the long-term impact of the 2021 firmware flaw, as victims must proactively generate new seeds and migrate their holdings to secure their assets.
Key Facts
- Amount moved from Wave 3: 97.09 BTC (approximately $7.7 million)
- Percentage of Wave 3 haul moved: 45%
- Total vaults created by attacker: 293 two-of-two multisig addresses
- Vaults currently emptied: 11
- Estimated total stolen across all waves: Approximately 2,400 BTC ($190+ million including unconfirmed fourth wave)
The Coldcard hardware wallet exploit continues to unfold as the attacker behind the third wave of thefts has transferred nearly half of that wave's stolen Bitcoin through privacy-mixing techniques. According to Galaxy Research, 97.09 BTC left the victim vaults on September 2 and over the weekend, with the first batch routed through THORChain to Ethereum while subsequent transactions entered CoinJoin rounds—a privacy protocol that obscures transaction trails by pooling multiple users' transactions together.
The attacker's methodology reveals a calculated approach to laundering the stolen cryptocurrency. Rather than emptying all vaults simultaneously, the perpetrator created 293 separate two-of-two multisig vaults and has been systematically draining them from largest to smallest. To date, eleven vaults have been completely emptied, with the next ten containing 30.81 BTC and the remaining 233 holding 33.77 BTC combined. This measured approach contrasts sharply with the vulnerability that enabled the thefts in the first place.
The exploits trace back to a critical firmware flaw that Coinkite, Coldcard's manufacturer, shipped in March 2021. The bug redirected seed generation from the device's secure hardware random-number generator to a software substitute, reducing cryptographic entropy from 128 bits to as little as 40 bits. This catastrophic weakness allowed attackers to reconstruct private keys offline and drain single-signature addresses without ever physically accessing the hardware wallets. The thefts began on July 30 and have continued in multiple waves.
Coinkite has released updated firmware requiring users to manually provide randomness through key presses, dice rolls, or coin flips, but the remedy cannot restore seeds generated under the flawed version. Users must generate entirely new seeds and manually transfer their coins to fresh wallets. The company's CEO issued an apology on July 31, acknowledging the need to rebuild user trust, though a comprehensive technical postmortem remains pending. Across all known waves of the exploit, approximately 82% of the stolen Bitcoin has not yet moved, suggesting the attacker may be holding the remainder or planning future movements.
Keep Reading

Swiss stablecoin sandbox enters testing phase, adds two new partners

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

New Bitcoin whales spark sell-side risk as unrealized gains hit $9B
