Coldcard hacker moves $7.7 million in Bitcoin, draining 45% of stolen funds
Attacker moves $7.7 million in Bitcoin
The hacker behind the third wave of Coldcard hardware‑wallet thefts transferred 97.09 BTC, worth about $7.7 million, out of the largest victim vaults. The move represents roughly 45 % of the Bitcoin taken in this attack series.
Key points
- 97.09 BTC moved in three rounds using THORChain and CoinJoin.
- Largest 11 vaults (out of 293) have been emptied.
- Remaining vaults hold about 94.58 BTC in total.
- Coinkite released firmware that cannot fix compromised seeds; users must create new seeds.
Galaxy Research analysis
Galaxy Research, a blockchain analytics firm, tracked the transactions. On Sept. 2 the attacker sent 20.5 BTC through THORChain, a decentralized exchange that swaps assets across blockchains, landing on Ethereum. On Sept. 5 a CoinJoin transaction mixed 15.48 BTC, and on Sept. 6 another CoinJoin mixed 61.12 BTC from ten vaults. CoinJoin mixes many users’ coins to hide the link between inputs and outputs.
Confirmed details
- The attacker has drained the 11 largest vaults tied to the third wave.
- Vaults are not the victims’ own wallets; they were created by the attacker using a two‑of‑two multisignature setup.
- Overall, the third wave involves about 1,806 BTC (≈ $143.9 million).
- Approximately 82 % of the stolen Bitcoin remains at attacker‑controlled addresses; 18 % has been moved using privacy tools.
Uncertainties
- One unidentified vault, funded by 58 addresses, may be linked to another Coldcard victim, but its origin is not confirmed.
- The exact number of vaults could increase to 294 if the unidentified vault is included.
Why it matters
The theft exploits a firmware flaw that weakened the randomness used by Coldcard devices to generate wallet seeds, the private codes that control funds. Because the flaw cannot be fixed by a simple update, affected users must create new seeds and move their Bitcoin to secure wallets.
Next steps for users
Coinkite, the maker of Coldcard, released a firmware update that prevents new wallets from being compromised. However, the update does not repair existing vulnerable seeds. Users who own affected wallets are advised to generate new seeds on a secure device and transfer their funds to new addresses.