Coldcard Hacker Moves 97 BTC In Third Wave Of Wallet Thefts
Key Takeaways
- A Coldcard hacker moved 97.09 BTC ($7.7 million), about 45% of the third wave’s stolen funds, using CoinJoin and THORChain to obscure the trail.
- The attacker has now drained the 11 largest of 293 vaults tied to this wave, working through them in order of size.
- Coinkite’s firmware fix only prevents future seed weaknesses; already-compromised wallets require generating new seeds and moving funds entirely.
An attacker behind a third wave of thefts from Coldcard hardware wallets has moved 97.09 bitcoin, worth $7.7 million, through two separate obfuscation methods since Sept. 2. That amount represents roughly 45% of the bitcoin taken in this wave. Galaxy Research said in a post on X that the attacker has now drained the 11 largest vaults tied to the theft.
How The Attacker Moved The Funds
Galaxy Research said the attacker routed about 20.5 BTC from the largest vault through decentralized exchange THORChain on Sept. 2, with the proceeds landing on Ethereum. The attacker then sent 15.48 BTC from the second-largest vault into a CoinJoin transaction on Sept. 5, followed by 61.12 BTC from 10 additional vaults the next day.
CoinJoin combines bitcoin transactions from multiple users into a single transaction, making it harder to trace which inputs correspond to which outputs.
Routing funds through THORChain and onto a separate blockchain adds a further layer of separation between the stolen bitcoin and its original source.
Galaxy said the attacker has been working through the theft’s 293 vaults in order of size and has now emptied the 11 largest. The next 10 vaults by size hold a combined 30.81 BTC, while vaults ranked 61 through 293 contain 33.77 BTC in total, according to the firm.
Vaults Were Created By The Attacker, Not Victims
The vaults involved in the theft are not the victims’ original wallets. Galaxy said the attacker created a separate vault for each victim’s coins, using a two-of-two multisignature setup that requires two keys to move the funds. A previously unidentified vault, funded by 58 addresses, was structured the same way.
Galaxy said that vault was probably linked to another Coldcard victim, though its exact origin remains unconfirmed. Including it would raise the total number of vaults tied to this wave to 294 and bring the wider exploit, across all waves, to roughly 1,806 BTC, worth about $143.9 million.
Across all waves of the theft, about 82% of the stolen bitcoin remains at its original attacker-controlled addresses. The remaining 18% has moved in transactions that appear designed to obscure the funds’ trail, Galaxy said.
Root Cause Traces To A Firmware Flaw
The thefts began July 30, after attackers exploited a firmware flaw that weakened the randomness Coldcard devices used to generate wallet seeds.
A wallet seed is the core secret from which a device derives its private keys, so weak randomness in that process can let an attacker predict or reconstruct seeds that should be unguessable.
Concerns about the scope of the exploit had grown in the weeks before this wave, as reports of a possible fourth sweep of affected vaults began to circulate alongside estimates that total losses could approach $114 million.
Coinkite’s Fix Does Not Repair Already-Compromised Wallets
Coinkite, the maker of Coldcard, has released firmware that fixes the underlying seed generation flaw. The company said the fix applies only to future seed generation and cannot repair wallets that were already compromised before the update.
As a result, Coinkite said affected users must generate entirely new seeds and move their funds to new wallets rather than relying on the firmware update alone to secure their existing holdings. Any funds left on a compromised seed remain exposed to the same weakness that allowed the original thefts, regardless of whether the device itself has since been updated.