TechNewsReel
Live

Coldcard 'Wave 3' Hacker Moves 45% of Stolen Bitcoin via THORChain

The attacker is swapping BTC for Ether and using CoinJoin to obscure the trail of a massive hardware wallet breach.

TechNewsReel Newsroom · September 7, 2026

The attacker responsible for the 'Wave 3' exploit of Coldcard hardware wallets has begun moving approximately 45% of the stolen Bitcoin. This shift indicates the exploiter is transitioning from the accumulation phase to active laundering, significantly complicating recovery efforts for victims and law enforcement.

According to Galaxy Research, the operator began swapping stolen Bitcoin for Ether via the THORChain cross-chain bridge on September 2. To further obscure the deterministic trail of the funds on the blockchain, the attacker has also utilized CoinJoin transactions. These movements follow a broader series of attacks that targeted a wide array of Coldcard users.

The Scale of the Breach

The security breach was extensive in both scope and volume. Galaxy Research identified that by mid-August, roughly 1,779 BTC had been stolen from 190 victims across more than 8,600 different addresses. When accounting for all attack waves, the total exploit is estimated at approximately 1,806 BTC.

Recent activity shows the hacker moved approximately $7.7 million to $7.8 million in BTC (97.09 BTC) across three specific rounds. During this process, the attacker drained the 11 largest vaults associated with the third wave of the exploit.

A Breach of Air-Gapped Security

Coldcard has long been regarded as one of the most secure options for Bitcoin storage due to its 'air-gapped' design, which ensures the private keys never touch an internet-connected device. The 'Wave 3' attacks represent a critical failure of this security model, proving that even hardware designed for maximum isolation can be compromised under specific conditions.

The use of THORChain and CoinJoin is a standard tactic for sophisticated actors. By swapping assets across different blockchains and mixing coins with other users, the attacker breaks the transparent link between the original theft and the final destination of the funds.

Industry Implications

This movement of funds is a pivotal moment in the exploit's lifecycle. Once assets enter cross-chain bridges and mixing services, the transparency of the Bitcoin blockchain is intentionally bypassed, making it nearly impossible to freeze or reclaim the assets through traditional means.

For the broader hardware wallet market, the breach underscores a growing reality: no device is entirely immune to sophisticated exploits. The incident forces a re-evaluation of the 'air-gap' as a definitive security guarantee and highlights the necessity for multi-signature setups to mitigate the risk of a single point of failure.

What Remains Unconfirmed

While the movement of funds is clear, the exact method used to compromise the air-gapped devices remains a primary point of concern. It is not yet fully confirmed how the attacker gained access to the private keys of 190 different victims across thousands of addresses. Analysts continue to monitor the remaining 55% of the stolen funds to determine if the attacker will employ further obfuscation techniques or attempt to liquidate the remaining balance through centralized exchanges.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.