
Coldcard Exploiter Moves 45% of Wave 3 Loot as Stolen Bitcoin Enters CoinJoins
Across all attack waves, 82% of stolen coins remain in attacker-controlled addresses, while 18% have been moved for laundering.

Across all attack waves, 82% of stolen coins remain in attacker-controlled addresses, while 18% have been moved for laundering.

Is the Coldcard exploit slowly and steadily turning into a large-scale Bitcoin laundering operation?

The perpetrator of the third wave attack against the Coldcard wallet has escalated the pace of transferring funds, reports Galaxy Research. The exploiters have transferred approximately 45% of the Bitcoin stolen from the third wave so far. These transfers indicate a pattern of using methods that make blockchain tracking difficult.

The attacker built 293 separate vaults for the stolen Bitcoin and is emptying them in order of size, largest first.

The incident highlights vulnerabilities in crypto security, emphasizing the need for robust safeguards and collaboration to prevent future breaches.

Galaxy said 82% of Bitcoin stolen across all Coldcard attacks remains in the original addresses, with 18% moved in apparent laundering.


As of mid-August, Galaxy said it had identified roughly 1,779 BTC stolen from 190 victims and more than 8,600 addresses.

Bitquery traced 20.45 BTC through 34 Sept. 2–3 swaps, and the main destination later held roughly 5 ETH less.

A Coldcard attacker moved about 10% of stolen Bitcoin through THORChain into ETH as researchers traced a new Ethereum destination.

The third-wave Coldcard exploiter moved about 10% of stolen funds through THORChain as researchers traced the assets to a new Ethereum address.

Following the Coldcard exploit that occurred 30 days ago in July, the episode and others that followed appear to have rattled many long-term holders, as August brought an enormous wave of dormant coins moving to new addresses. According to the latest metrics, 6,427.59 dormant BTC worth $507 million moved for the first time in years […]

Bitcoin Magazine Coinkite’s Coldcard Bug Exposed Single-Sig Risk. Multi-Vendor Multisig Is the New Bitcoin Custody Baseline Coinkite now forces dice rolls and key-press entropy on new Coldcard seeds. The lasting lesson from the July–August 2026 thefts is not to abandon self-custody — it is to stop generating every key on one vendor. This post Coinkite’s Coldcard Bug Exposed Single-Sig Risk. Multi-Vendor Multisig Is the New Bitcoin Custody Baseline first appeared on Bitcoin Magazine and is written by Juan Galt .

The Coldcard crisis has also tested hardware wallet manufacturers’ abilities to deal with sharply increased sales, as instead of giving up on self-custody, many Bitcoiners rushed to new devices while wallet teams prepared for the new AI-powered (in)security reality. Of the 13 hardware wallet manufacturers Bitcoin.com News contacted for comment, Trezor, Bitbox, and Onekey confirmed […]

BlackRock reduced the minimum for BTC in-kind conversions from $25M to $1M.

More than 87% of the Bitcoin attributed to the Coldcard hack has remained unmoved, leaving 1,561 BTC under attacker control after researchers linked the exploit to $114.7 million in losses. Galaxy Research has traced 1,789.28 BTC stolen from 8,865 addresses…

Galaxy Research’s latest tally shows that more than half of 221 Coldcard hack victim reports involved individual losses exceeding 1 Bitcoin.

Firmware 5.6.1 and 1.5.1Q harden new wallet creation but cannot repair a seed made on an affected release.

Coinkite has released new Coldcard firmware that forces users to provide their own randomness when generating new wallet seeds.

Coinkite's latest firmware requires users to add their own randomness when generating wallet seeds and fixes additional security issues uncovered during a three-week review.