Coldcard third-wave attacker moves 45% of stolen Bitcoin
The operator of the third wave of Coldcard wallet attacks has begun moving approximately 45% of stolen Bitcoin through privacy-mixing services including THORChain and CoinJoin, according to blockchain analysis by Galaxy Research. The attacker systematically relocated funds from the largest of 293 multisignature vaults created to hold victims' assets, while the majority of stolen funds remain stationary in original addresses.

Why It Matters
This development demonstrates ongoing attempts to obscure stolen cryptocurrency through sophisticated laundering techniques, and highlights how blockchain analysis can sometimes identify previously unknown victims of major hacks. The Coldcard exploit represents one of 2026's most significant cryptocurrency thefts, underscoring persistent security vulnerabilities in hardware wallet ecosystems.
Key Facts
- Percentage of stolen Bitcoin moved: 45%
- Total Bitcoin still in original addresses: 82%
- Multisignature vaults created by attacker: 293
- Largest vaults with moved funds: 11
- 2026 rank by damage: Third-largest exploit
The third wave of attacks on Coldcard hardware wallets has entered a new phase as the attacker begins converting stolen digital assets into more difficult-to-trace forms. Galaxy Research documented the movement of funds beginning September 2, with Bitcoin being routed through cross-chain bridges to Ethereum and subsequently processed through CoinJoin mixing protocols designed to obscure transaction trails.
The attacker's methodology suggests a systematic approach to converting stolen assets. Analysis shows the perpetrator created nearly 300 two-of-two multisignature vaults to segregate victims' funds and has been methodically extracting Bitcoin from these vaults starting with the largest holdings. To date, funds from the 11 most substantial vaults have been successfully relocated, though the vast majority of stolen cryptocurrency remains unmoved in addresses controlled by the attacker.
The ongoing movement of these funds has produced secondary investigative benefits, as blockchain analysts were able to identify a previously unconfirmed Coldcard victim through monitoring these transactions. The discovery process demonstrates how studying attacker behavior patterns can sometimes reveal new affected parties, even as the perpetrators attempt to hide their activities.
Across all phases of the Coldcard compromise, approximately 82% of the total stolen Bitcoin remains untouched in original addresses, with only 18% having been moved through apparent laundering channels. This distinction suggests the attacker may be proceeding cautiously, potentially waiting for market conditions or preparing larger-scale conversion operations. The Coldcard exploit has firmly established itself as the third-costliest hack of 2026, trailing only the Kelp DAO incident and the Drift protocol breach in terms of financial impact.
Keep Reading

Bitcoin’s golden cross is here

Hunter Biden wants to launch a LAPTOP memecoin. Crypto traders hate it already

Bit2Me sets up specialized unit to help law enforcement track down crypto assets
