Coldcard hacker moves $7.7 million in Bitcoin, draining 45% of stolen funds

Sep 07, 2026 20:08 Written by Yasir Arafat bitcoin coldcard thief vault seed
Coldcard hacker moves $7.7 million in Bitcoin, draining 45% of stolen funds

Attacker moves $7.7 million in Bitcoin

The hacker behind the third wave of Coldcard hardware‑wallet thefts transferred 97.09 BTC, worth about $7.7 million, out of the largest victim vaults. The move represents roughly 45 % of the Bitcoin taken in this attack series.

Key points

  • 97.09 BTC moved in three rounds using THORChain and CoinJoin.
  • Largest 11 vaults (out of 293) have been emptied.
  • Remaining vaults hold about 94.58 BTC in total.
  • Coinkite released firmware that cannot fix compromised seeds; users must create new seeds.

Galaxy Research analysis

Galaxy Research, a blockchain analytics firm, tracked the transactions. On Sept. 2 the attacker sent 20.5 BTC through THORChain, a decentralized exchange that swaps assets across blockchains, landing on Ethereum. On Sept. 5 a CoinJoin transaction mixed 15.48 BTC, and on Sept. 6 another CoinJoin mixed 61.12 BTC from ten vaults. CoinJoin mixes many users’ coins to hide the link between inputs and outputs.

Confirmed details

  • The attacker has drained the 11 largest vaults tied to the third wave.
  • Vaults are not the victims’ own wallets; they were created by the attacker using a two‑of‑two multisignature setup.
  • Overall, the third wave involves about 1,806 BTC (≈ $143.9 million).
  • Approximately 82 % of the stolen Bitcoin remains at attacker‑controlled addresses; 18 % has been moved using privacy tools.

Uncertainties

  • One unidentified vault, funded by 58 addresses, may be linked to another Coldcard victim, but its origin is not confirmed.
  • The exact number of vaults could increase to 294 if the unidentified vault is included.

Why it matters

The theft exploits a firmware flaw that weakened the randomness used by Coldcard devices to generate wallet seeds, the private codes that control funds. Because the flaw cannot be fixed by a simple update, affected users must create new seeds and move their Bitcoin to secure wallets.

Next steps for users

Coinkite, the maker of Coldcard, released a firmware update that prevents new wallets from being compromised. However, the update does not repair existing vulnerable seeds. Users who own affected wallets are advised to generate new seeds on a secure device and transfer their funds to new addresses.

Sources

YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!