Galaxy Research said Monday that 97.09 BTC, worth about $7.7 million, has left the Wave 3 vaults.
The coins went out through THORChain on September 2 and into CoinJoin rounds over the weekend.
Across the whole Coldcard exploit, 82% of the stolen Bitcoin has still not moved.
The attacker behind the third wave of thefts from Coldcard hardware wallets has moved 97.09 BTC, roughly 45% of that wave’s haul and about $7.7 million at Monday’s prices, according to Galaxy Research.
The first exit came on September 2, when around 20.5 BTC from the largest vault went through THORChain and came out as Ethereum. The coins spent on Sunday night went into CoinJoin rounds instead, a Bitcoin privacy technique that pools transactions from multiple users to break the trail between inputs and outputs. Only 20.56 BTC actually reached Ethereum. Another 57.24 BTC is sitting unspent as CoinJoin change in a single address, and Galaxy says its trail ends on roughly 19 BTC more.
Coldcard ‘Wave 3’ exploiter continues to move funds
In wave 3, the exploiter created 293 2-of-2 multisig vaults for each victim’s coins.
The first movements on 9/2 sent coins over THORChain to Ethereum.
— Galaxy Research (@glxyresearch) September 7, 2026
The vaults are the attacker’s own construction. Galaxy said the operator built 293 two-of-two multisig addresses and has been working through them in order of size. Eleven are now empty. The next ten hold 30.81 BTC between them, and the 233 smallest hold 33.77 BTC.
BitcoinBTC · USD
$79,402−0.65%
12:00 PM06:00 PM12:00 AM05:45 AM11:45 AM
$80.4k$80.0k$79.7k$79.3k
24h HighHigh$80,494
24h LowLow$79,081
VolVol$831.0M
Market projectionsOdds by Myriad
A flaw shipped in 2021
The thefts trace to a firmware bug Coinkite introduced in March 2021, which rerouted seed generation off the device’s hardware random-number chip and onto a software stand-in, collapsing key strength from 128 bits of entropy to as low as 40. That let attackers reconstruct private keys offline and drain single-signature addresses without ever touching the hardware. The sweeps began on July 30.
Coinkite has overhauled the firmware, now at Mk4/Mk5 5.6.2 and Q 1.5.2Q, requiring owners to supply their own randomness through key presses, dice rolls or coin flips. An update still cannot repair a seed generated under the flawed version, and anyone whose wallet was created on affected firmware has to generate a fresh seed and move their coins to it. Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31, writing that the company would have to “earn back our users’ trust.” A full technical postmortem is still in preparation.
Myriad: Bitcoin next price move? Click to make your prediction.
Monday’s thread also flagged a previously unknown vault fed by 58 addresses. Galaxy marks its cause as open but believes it another Coldcard victim, which would lift its published total for the exploit to about 1,806 BTC, or $143.9 million. Galaxy said in August it was also carrying an unconfirmed fourth wave of 638.5 BTC, which would take the total past 2,400, and had logged no attacker sweeps since August 6. Across all waves, 82% of the coins remain where the attackers first put them.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.