Coldcard Attacker Moves 45% of Wave 3 Bitcoin Through CoinJoin

icon36Crypto
Share
AI summary iconSummary
Bitcoin breaking news: Based on 36 Crypto, the Coldcard attacker has moved 45% of Wave 3 Bitcoin. Galaxy Research reported the Wave 3 operator sent 97.09 BTC, about $7.8 million, via CoinJoin. The exploit used a 2021 firmware flaw that reduced seed randomness. Galaxy tied 1,806 BTC, worth $143.9 million, to the breach, with 82% still in attacker addresses. Bitcoin news outlets are tracking the movement closely.

Summary

  • Coldcard attacker moved 97.09 BTC through CoinJoin, representing 45% of assets stolen during the third identified wave within the campaign.
  • A 2021 firmware flaw weakened wallet seed randomness, allowing attackers to brute-force private phrases and drain single-signature Bitcoin wallets remotely.
  • Galaxy linked 1,806 BTC worth $143.9 million to the exploit, while 82% remains inside original attacker-controlled addresses under blockchain monitoring.


The attacker behind the Coldcard hardware wallet exploits has moved 45% of the Bitcoin stolen during the third attack wave. According to Galaxy Research, the Wave 3 operator transferred 97.09 Bitcoin (BTC), worth approximately $7.8 million.


The exploiter processed those assets through CoinJoin transactions, making the movement of stolen funds harder to trace. CoinJoin combines several Bitcoin payments within one transaction, reducing the visibility of links between senders and recipients.


However, Galaxy’s analysis indicates that the attacker follows a calculated order when selecting compromised wallets. The operator has targeted the affected vaults according to their balances, beginning with wallets holding the largest amounts.


Vaults ranked between one and eleven have already recorded movements linked to the laundering operation. Meanwhile, the next ten untouched vaults contain a combined 30.81 BTC, based on Galaxy’s findings.


Another group of smaller vaults, ranked between 61 and 293, collectively holds 33.77 BTC. This transfer pattern provides investigators with possible indicators regarding which compromised wallets the attacker could target.


Before using CoinJoin, the exploiter converted stolen Bitcoin (BTC) into Ethereum (ETH) through THORChain on September 2. THORChain allows users to exchange assets across different blockchains without relying on a centralized cryptocurrency exchange.


The conversion marked another effort to separate the stolen assets from their original Coldcard addresses. Galaxy reported that 82% of all stolen funds still remain inside the attacker’s original wallets. Consequently, only 18% has moved through transactions that appear connected to laundering or asset conversion activities.


Also Read: PYTH Price Prediction 2026–2030: Can Pyth Network Reach $0.20 Soon?


Coldcard Firmware Bug Weakened Wallet Seed Generation

The Coldcard thefts began on July 30 and originated from a firmware flaw that Coinkite shipped in 2021. The vulnerability affected the method that certain Coldcard devices used to generate wallet seeds for their owners.


These devices produced seed phrases with insufficient randomness, weakening the security protecting corresponding private keys. Attackers could therefore brute-force vulnerable seed phrases and identify the Bitcoin addresses linked to those phrases.


Significantly, the attackers drained single-signature wallets without physically obtaining or interacting with the affected Coldcard devices. By mid-August, Galaxy had connected approximately 1,779 stolen BTC to 190 victims and more than 8,600 addresses.


Researchers grouped the incidents into separate attack waves using transaction behavior, compromised addresses, and wallet movement patterns. Galaxy also identified the possibility of a fourth attack wave, although the research firm has not confirmed it.


Previously Unknown Vault Raises Estimated Bitcoin Losses

Moreover, the Wave 3 exploiter combined funds from a previously unknown vault containing 58 addresses. Galaxy believes those addresses likely belong to additional Coldcard victims affected by the same seed-generation weakness.


Adding that vault would raise the estimated theft to 1,806 BTC, worth approximately $143.9 million. The revised figure expands both the suspected victim pool and the scale of Bitcoin linked to the exploit.


Blockchain researchers can still observe movements from identified addresses, although CoinJoin complicates direct transaction attribution. Investigators may examine transfer timing, shared inputs, recurring amounts, and connections between wallets to follow the stolen assets.


The attacker’s preference for larger vaults also reveals an organized approach toward moving and laundering compromised holdings. Most stolen Bitcoin remains inside known attacker-controlled addresses, leaving a substantial amount visible to blockchain investigators. Nevertheless, further movements could affect remaining vaults as the operator processes funds from larger balances toward smaller wallets.


Also Read: Liquid Hackers Offer to Return Most of 4,000 BTC Once Vulnerability Is Fixed


The post Coldcard Attacker Moves 45% of Wave 3 Bitcoin Through CoinJoin appeared first on 36Crypto.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.