Attacker Moves 45% of Stolen Coldcard Bitcoin Through THORChain and CoinJoin
The perpetrator behind the third wave of Coldcard hardware wallet exploits has begun laundering 97.09 BTC, representing 45% of the funds stolen in that specific wave.

The hacker responsible for the third wave of Coldcard exploits has moved approximately 97.09 BTC, valued at about $7.8 million, using cross-chain swaps and mixing services. Galaxy Research reported that this activity occurred over a five-day period, with the funds being processed through THORChain and CoinJoin.
According to Galaxy Research, the movement of these funds began on September 2 when assets were swapped into Ether via THORChain. By September 5 and 6, the attacker utilized CoinJoin to further obscure the transaction trail. The attacker appears to be prioritizing the largest vaults, suggesting a calculated approach to liquidation.
The vulnerability stems from a firmware update released by Coinkite in March 2021. This update caused Coldcard devices to use a software-based pseudo-random number generator, resulting in wallet seeds with insufficient entropy. Although Coinkite has since patched the firmware, seeds generated during the vulnerable period remain compromised, and the company has advised users to migrate funds to new seeds.
Galaxy Research has tracked the exploit chain since July 30, 2026, identifying total losses of approximately 1,789 BTC across 8,865 addresses. While 18% of the stolen funds have shown movement consistent with laundering, 82% remains in attacker-controlled wallets. Galaxy Research has shared identified addresses with law enforcement and industry partners.
Stay ahead
Join our Telegram Channel
Free real-time crypto news and price alerts, the moment they break.
- Breaking News
- Price Alerts
- Market Insights



