Coldcard attacker moves 45% of stolen Bitcoin through THORChain and CoinJoin, Galaxy reports

52 minutes ago 19

The hacker behind the third wave of Coldcard hardware wallet exploits has started cashing out, routing approximately 97.09 BTC, worth about $7.8 million, through cross-chain swaps and mixing services over a five-day window. Galaxy Research flagged the movement on September 7, noting it represents roughly 45% of the Wave 3 stolen funds.

The funds first hit THORChain on September 2, where they were swapped into Ether. By September 5 and 6, additional portions had been run through CoinJoin transactions, a Bitcoin privacy technique that bundles multiple users’ transactions together to obscure the trail. The attacker appears to be working through the largest vaults first, a prioritization strategy that suggests deliberate planning rather than panicked liquidation.

A firmware flaw five years in the making

A firmware update shipped by Coinkite in March 2021 (version 4.0.1 onward) introduced a bug that caused Coldcard devices, primarily the Mk3 and later models, to default to a software-based pseudo-random number generator when creating wallet seeds. The hardware random number generator was effectively bypassed.

The result: seeds generated with only 40 to 72 bits of effective entropy. For context, modern cryptographic standards typically call for 128 to 256 bits. Skilled attackers could reconstruct private keys entirely offline through brute-force computation.

Coinkite eventually patched the firmware, but any wallet seed generated during the vulnerable window remains compromised regardless of whether the device itself has been updated. The company has urged affected users to generate entirely new seeds and migrate their funds.

The full scope: 1,789 BTC across 8,865 addresses

Galaxy Research, led by analyst Alex Thorn, has been tracking the Coldcard exploit chain since the attacks began on July 30, 2026. Total confirmed losses stand at approximately 1,789 BTC, valued at around $114.7 million at the time of theft. More than 8,865 addresses have been affected, with the median victim losing more than 1 BTC. An additional cluster of 58 addresses has been identified that could push total losses to roughly 1,806 BTC.

The attacks came in waves. The first wave alone extracted 1,082.65 BTC in just 41 minutes, a staggering pace that points to automated scripts scanning the blockchain for weak keys. Galaxy’s research suggests at least 15 different attackers were involved across the waves, which ran from July 30 through August 6. Activity dropped sharply after that.

Of the total haul, 82% of stolen Bitcoin remains sitting in attacker-controlled wallets. Only 18% has shown movement consistent with laundering. Galaxy’s team has engaged directly with over 190 victims and shared identified attacker addresses with law enforcement agencies and industry partners.

THORChain’s uncomfortable spotlight

The attacker’s choice of THORChain as a laundering vehicle is notable but not surprising. The decentralized cross-chain liquidity protocol enables swaps between native assets on different blockchains without requiring a centralized intermediary. THORChain’s permissionless architecture means it can’t freeze or reverse transactions the way a centralized exchange can.

The subsequent use of CoinJoin adds another layer of obfuscation. By mixing the converted funds with legitimate Bitcoin transactions, the attacker makes chain analysis significantly harder, though not impossible. Firms like Chainalysis and Elliptic have developed increasingly sophisticated tools for de-mixing CoinJoin outputs, and law enforcement has successfully traced CoinJoin-laundered funds in prior cases.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article