According to Galaxy Research, 97.09 BTC, valued at approximately $7.7 million, has been withdrawn from the Wave 3 vaults.
The funds were first moved through THORChain on September 2 and subsequently routed through CoinJoin transactions over the weekend.
Despite these movements, 82% of the Bitcoin stolen in the overall Coldcard exploit remains untouched.
The perpetrator responsible for the third wave of thefts from Coldcard hardware wallets has transferred 97.09 BTC, which represents roughly 45% of that wave’s proceeds and equates to approximately $7.7 million based on Monday’s market rates, as reported by Galaxy Research.
The initial transaction occurred on September 2, when approximately 20.5 BTC from the primary vault was transferred through THORChain and subsequently emerged as Ethereum. In contrast, the funds moved on Sunday night were directed into CoinJoin rounds, a Bitcoin privacy method that combines transactions from multiple participants to obscure the link between inputs and outputs. Only 20.56 BTC successfully reached the Ethereum network. An additional 57.24 BTC remains unspent as CoinJoin change within a single address, and Galaxy indicates that the trail continues for an estimated extra 19 BTC.
Coldcard ‘Wave 3’ exploiter continues to move funds
In wave 3, the exploiter created 293 2-of-2 multisig vaults for each victim’s coins.
The first movements on 9/2 sent coins over THORChain to Ethereum.
— Galaxy Research (@glxyresearch) September 7, 2026
These vaults were constructed by the attacker themselves. Galaxy reported that the operator established 293 two-of-two multisig addresses and has been systematically processing them according to size. Eleven have already been emptied. The following ten collectively contain 30.81 BTC, while the 233 smallest addresses hold 33.77 BTC.
BitcoinBTC · USD
$79,443−0.61%
24H7D1M1YYTD
12:15 PM06:15 PM12:15 AM06:00 AM12:00 PM
$80.4k$80.0k$79.7k$79.3k
24h HighHigh$80,494
24h LowLow$79,081
VolVol$832.2M
Market projectionsOdds by Myriad
A flaw shipped in 2021
The thefts originated from a firmware vulnerability introduced by Coinkite in March 2021. This flaw redirected seed generation away from the device’s dedicated hardware random-number generator and instead relied on a software alternative, reducing key strength from 128 bits of entropy to as little as 40 bits. As a result, attackers were able to reconstruct private keys offline and drain single-signature addresses without requiring physical access to the hardware. The initial sweeps commenced on July 30.
Coinkite has since overhauled the firmware, with the current versions being Mk4/Mk5 5.6.2 and Q 1.5.2Q. These updates mandate that owners generate their own randomness through methods such as key presses, dice rolls, or coin flips. However, a software update cannot retroactively fix a seed that was generated under the flawed version. Consequently, any user whose wallet was created using the affected firmware must generate a new seed and migrate their funds to it. Coinkite CEO Rodolfo Novak issued a public apology in an open letter on July 31, acknowledging that the company would need to “earn back our users’ trust.” A comprehensive technical postmortem is still being prepared.
Myriad: Bitcoin next price move? Click to make your prediction.
Monday’s thread also identified a previously unknown vault supplied by 58 addresses. While Galaxy has classified the origin as undetermined, the prevailing assumption is that it represents another Coldcard victim. If confirmed, this would increase the publicly documented total for the exploit to approximately 1,806 BTC, equivalent to $143.9 million. Additionally, Galaxy reported in August that it is tracking an unconfirmed fourth wave comprising 638.5 BTC, which would push the overall total beyond 2,400 BTC. No attacker sweeps have been observed since August 6. Across all waves, 82% of the stolen coins remain in their original positions.