The attacker behind the third wave of Coldcard hardware wallet thefts has moved 97.09 BTC, roughly 45% of the bitcoin taken in that wave, using THORChain and CoinJoin. Galaxy Research says the attacker has now drained the 11 largest of 293 compromised vaults, and Coinkite has released fixed firmware that cannot repair wallets already compromised by the flaw.
The attacker behind the third wave of thefts from Coldcard hardware wallets has moved 97.09 BTC, worth $7.7 million — about 45% of the bitcoin taken in that wave — through two separate methods. Galaxy Research tracked the movements across three transactions this month.
Funds routed through THORChain and CoinJoin
Galaxy Research said the attacker routed about 20.5 BTC from its largest vault through decentralized exchange THORChain on Sept. 2, with the proceeds landing on Ethereum. It then sent 15.48 BTC from the second-largest vault into a CoinJoin transaction on Sept. 5, followed by another 61.12 BTC from 10 vaults the next day.
CoinJoin combines bitcoin transactions from multiple users, making it harder to link specific inputs with their eventual outputs. Galaxy said the attacker has been working through the 293 vaults in order of size and has now emptied the 11 largest. The next 10 hold 30.81 BTC, while vaults ranked 61 through 293 contain a combined 33.77 BTC.
Vaults built for each victim, not the victims' own wallets
The vaults are not victims' own wallets — Galaxy said the exploiter created them, one for each victim's coins, using a two-of-two multisignature setup that requires two keys to move the bitcoin. A previously unidentified vault, funded by 58 addresses, used the same format. Galaxy said that vault was probably linked to another Coldcard victim, though its origin remains unconfirmed.
Including it would raise Wave 3 to 294 vaults and bring the wider exploit to about 1,806 BTC, worth roughly $143.9 million. Galaxy said about 82% of the bitcoin taken across all waves remains at its original attacker-controlled addresses, while 18% has moved in transactions that appear designed to obscure the funds' trail.
Fixed firmware can't undo the damage
The thefts began July 30 after attackers exploited a firmware flaw that weakened the randomness Coldcard devices use to generate wallet seeds. Coinkite has released fixed firmware, but said affected users must create new seeds and move their funds, because an update alone cannot repair wallets already compromised by the flaw.
Source: CoinDesk
Trading involves risk.