Coldcard hacker moves $7.7M of stolen Bitcoin by systematically draining 293 separate vaults.
Security & Exploits ·
The attacker behind the third wave of Coldcard hardware wallet thefts has moved 97.09 BTC—approximately $7.7 million and roughly 45% of that wave's total stolen amount—according to Galaxy Research. The first transfer occurred on September 2, when approximately 20.5 BTC from the largest vault was routed through THORChain and converted to Ethereum. Subsequent movements over the weekend went through CoinJoin, a privacy technique that mixes Bitcoin transactions from multiple parties to obscure transaction trails.
The attacker constructed 293 two-of-two multisig vaults to hold the stolen coins and has been systematically emptying them by size, starting with the largest. As of Monday's analysis, eleven vaults were completely drained, ten vaults held 30.81 BTC combined, and the remaining 233 held 33.77 BTC. Of the approximately 20 BTC routed through CoinJoin, 20.56 BTC reached Ethereum while another 57.24 BTC remained as unspent change in a single address.
The thefts originated from a firmware vulnerability introduced in March 2021 that degraded cryptographic randomness from 128 bits to as low as 40, enabling offline key reconstruction. Galaxy flagged a previously undiscovered vault fed by 58 addresses, potentially lifting the total exploited amount to roughly 1.806 BTC or $143.9 million. Notably, 82% of all stolen Bitcoin across every identified wave remains unmoved, and no attacker sweeps have been logged since August 6.