Coldcard Hacker Moves $7.7M, Nearly Half of Third-Wave Bitcoin Haul

Coldcard Hacker Moves $7.7M, Nearly Half of Third-Wave Bitcoin Haul

In brief Galaxy Research said Monday that 97.09 BTC, worth about $7.7 million, has left the Wave 3 vaults. The coins went out through THORChain on September 2 and into CoinJoin rounds over the weekend. Across the whole Coldcard exploit, 82% of the stolen Bitcoin has still not moved. The attacker behind the third wave of thefts from Coldcard hardware wallets has moved 97.09 BTC, roughly 45% of that wave's haul and about $7.7 million at Monday's prices, according to Galaxy Research.The first exit came on September 2, when around 20.5 BTC from the largest vault went through THORChain and came out as Ethereum. The coins spent on Sunday night went into CoinJoin rounds instead, a Bitcoin privacy technique that pools transactions from multiple users to break the trail between inputs and outputs. Only 20.56 BTC actually reached Ethereum. Another 57.24 BTC is sitting unspent as CoinJoin change in a single address, and Galaxy says its trail ends on roughly 19 BTC more. Coldcard ‘Wave 3’ exploiter continues to move funds In wave 3, the exploiter created 293 2-of-2 multisig vaults for each victim’s coins. The first movements on 9/2 sent coins over THORChain to Ethereum. Tonight’s movements are going into coinjoins rounds. pic.twitter.com/H7HIpcI7ah — Galaxy Research (@glxyresearch) September 7, 2026The vaults are the attacker's own construction. Galaxy said the operator built 293 two-of-two multisig addresses and has been working through them in order of size. Eleven are now empty. The next ten hold 30.81 BTC between them, and the 233 smallest hold 33.77 BTC.A flaw shipped in 2021The thefts trace to a firmware bug Coinkite introduced in March 2021, which rerouted seed generation off the device's hardware random-number chip and onto a software stand-in, collapsing key strength from 128 bits of entropy to as low as 40. That let attackers reconstruct private keys offline and drain single-signature addresses without ever touching the hardware. The sweeps began on July 30.Coinkite has overhauled the firmware, now at Mk4/Mk5 5.6.2 and Q 1.5.2Q, requiring owners to supply their own randomness through key presses, dice rolls or coin flips. An update still cannot repair a seed generated under the flawed version, and anyone whose wallet was created on affected firmware has to generate a fresh seed and move their coins to it. Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31, writing that the company would have to "earn back our users' trust." A full technical postmortem is still in preparation.Myriad: Bitcoin next price move? Click to make your prediction.Monday's thread also flagged a previously unknown vault fed by 58 addresses. Galaxy marks its cause as open but believes it another Coldcard victim, which would lift its published total for the exploit to about 1,806 BTC, or $143.9 million. Galaxy said in August it was also carrying an unconfirmed fourth wave of 638.5 BTC, which would take the total past 2,400, and had logged no attacker sweeps since August 6. Across all waves, 82% of the coins remain where the attackers first put them.Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.

Original Source

Read the full article at Decrypt →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.