2 days ago2 min readColdcard hacker moved the funds through THORChain and CoinJoinRiepilogoThe Coldcard hacker moved $7.7M in BTC (97.09 total) across three rounds, using THORChain and CoinJoins to obscure the trail of stolen funds.The attacker has successfully drained the 11 largest vaults from the third wave of thefts, part of a wider exploit totaling roughly 1,806 BTC.Affected users must generate new seeds and move funds, as Coinkite’s new firmware cannot repair wallets already compromised by the seed generation flaw.The attacker behind the third wave of thefts from Coldcard hardware wallets moved 97.09 BTC ($7.7 million), roughly 45% of the bitcoin taken, through two separate methods.Galaxy Research said the attacker routed about 20.5 BTC from its largest vault through decentralized exchange THORChain on Sept. 2, with the proceeds landing on Ethereum. It then sent 15.48 BTC from the second-largest vault into a CoinJoin transaction on Sept. 5, followed by another 61.12 BTC from 10 vaults the next day.CoinJoin combines bitcoin transactions from multiple users, making it harder to link specific inputs with their eventual outputs.Galaxy said the attacker has been working through the 293 vaults in order of size and has now emptied the 11 largest. The next 10 hold 30.81 BTC, while vaults ranked 61 through 293 contain a combined 33.77 BTC.The vaults are not victims' own wallets. Galaxy said the exploiter created them, one for each victim's coins, using a two-of-two multisignature setup that requires two keys to move the bitcoin. The previously unidentified vault, funded by 58 addresses, used the same format.Galaxy said the vault was probably linked to another Coldcard victim, though its origin remains unconfirmed. Including it would raise Wave 3 to 294 vaults and bring the wider exploit to about 1,806 BTC, worth roughly $143.9 million.About 82% of the bitcoin taken across all waves remains at its original attacker-controlled addresses, while 18% has moved in transactions that appear designed to obscure the funds' trail, Galaxy said.The thefts began July 30 after attackers exploited a firmware flaw that weakened the randomness used by Coldcard devices to generate wallet seeds.Coinkite has released fixed firmware, but said affected users must create new seeds and move their funds because an update alone cannot repair compromised ones.AI Disclaimer: Parts of this article were generated with the assistance from AI tools and reviewed by our editorial team to ensure accuracy and adherence to our standards. For more information, see CoinDesk's full AI Policy.12345678910
Coldcard hacker moves $7.7 million in BTC, 45% of bitcoin stolen in third attack wave
The attacker has now drained the 11 largest vaults tied to the third wave of Coldcard thefts, Galaxy Research said.







