The hacker behind the third wave of Coldcard hardware wallet exploits has started cashing out, routing approximately 97.09 BTC, worth about $7.8 million, through cross-chain swaps and mixing services over a five-day window. Galaxy Research flagged the movement on September 7, noting it represents roughly 45% of the Wave 3 stolen funds.
The funds first hit THORChain on September 2, where they were swapped into Ether. By September 5 and 6, additional portions had been run through CoinJoin transactions, a Bitcoin privacy technique that bundles multiple users’ transactions together to obscure the trail. The attacker appears to be working through the largest vaults first, a prioritization strategy that suggests deliberate planning rather than panicked liquidation.
A firmware flaw five years in the making
A firmware update shipped by Coinkite in March 2021 (version 4.0.1 onward) introduced a bug that caused Coldcard devices, primarily the Mk3 and later models, to default to a software-based pseudo-random number generator when creating wallet seeds. The hardware random number generator was effectively bypassed.
The result: seeds generated with only 40 to 72 bits of effective entropy. For context, modern cryptographic standards typically call for 128 to 256 bits. Skilled attackers could reconstruct private keys entirely offline through brute-force computation.






