Coldcard exploiter moves 45% of stolen Bitcoin from Wave 3 attacks
Attacker moves 45% of stolen Bitcoin
The hacker behind recent Coldcard hardware‑wallet exploits has transferred 45 % of the Bitcoin taken in the third wave of attacks, according to research firm Galaxy Research.
Key numbers
- ~1,779 BTC stolen from 190 victims (mid‑August estimate)
- ~8,600 addresses involved
- 97.09 BTC (~$7.8 million) spent so far via CoinJoin transactions
- 82 % of total stolen funds still sit in attacker‑controlled addresses
- Potential total loss could rise to 1,806 BTC (~$143.9 million) if a newly identified vault is included
Galaxy Research findings
Galaxy said the attacker is moving the coins in order of size, starting with the largest vaults. The first eleven vaults have already been emptied, the next ten larger vaults hold about 30.81 BTC, and the smaller vaults (ranks 61‑293) hold about 33.77 BTC combined.
How the Coldcard bug works
The thefts began on July 30 and stem from a 2021 firmware bug in Coldcard devices made by Coinkite. The bug reduced the randomness used to generate wallet seed phrases, allowing attackers to brute‑force the private keys and drain single‑signature addresses without ever touching the hardware wallet.
Open questions
Galaxy mentioned the possible emergence of a “Wave 4” attack but has not confirmed it. The firm also noted a previously unknown vault of 58 addresses that likely belong to Coldcard victims; counting this vault would raise the total loss figure.
Why it matters
Coldcard is a popular hardware wallet that stores private keys offline. A successful exploit shows that firmware bugs can compromise even offline‑storage devices, highlighting the need for rigorous code audits and timely updates.