Coldcard Hacker Moves $7.7 Million from Third Wave of Hardware Wallet Exploits
An attacker has drained nearly half of the Bitcoin stolen in the third wave of a firmware-driven exploit, utilizing cross-chain swaps to mask the trail.
A hacker linked to the third wave of thefts from Coldcard hardware wallets has moved approximately 45% of the stolen Bitcoin from that specific cluster, totaling 97.09 BTC. The movement, which occurred between September 2 and September 7, 2026, signals an aggressive cash-out phase for one of the year's most significant security breaches.
According to Galaxy Research, the attacker drained 12 separate vaults during this window, moving the funds—valued at roughly $7.7 million—through a combination of THORChain and CoinJoin privacy rounds. The operator is methodically emptying 2-of-2 multisig vaults, targeting them in descending order of size to maximize the efficiency of the theft. These funds are being swapped from Bitcoin to Ether via THORChain to further obfuscate the origin of the assets.
The Firmware Vulnerability
The broader exploit began around July 30, 2026, stemming from a critical firmware bug in Coldcard devices. Manufacturer Coinkite issued a security advisory clarifying that the vulnerability was not a remote takeover, but rather a flaw in the seed generation process. This bug weakened the entropy of the generated seeds, which allowed attackers to regenerate private keys offline.
Security analysis indicates that users were particularly vulnerable if they failed to implement additional security layers, such as a strong BIP-39 passphrase or at least 50 independent dice rolls during setup. While the attack occurred in three distinct waves, Wave 3 was unique for its use of individual 2-of-2 multisig vaults for each victim cluster, adding a layer of complexity to the theft.
Industry Implications
The scale of the breach is immense, with total losses across all three attack waves estimated between 1,789 and 1,806 BTC, valued at approximately $115 million. This incident severely undermines the perceived security of 'cold storage' hardware wallets, which are marketed as the gold standard for long-term asset protection.
Furthermore, the sophistication of the laundering operation highlights a growing challenge for on-chain forensics. By integrating cross-chain swaps and privacy-enhancing tools like CoinJoin, the attacker is demonstrating a high level of technical proficiency designed to bypass traditional tracking efforts and evade exchange-based freezes.
What Remains
As the Wave 3 operator continues to liquidate assets, investigators are monitoring the flow of funds through the Ethereum network. While the technical cause of the exploit has been identified by Coinkite, the full extent of the recovery efforts for affected users remains unclear. The industry now faces a critical reckoning regarding the trust placed in automated seed generation and the necessity of manual entropy sources for high-value storage.