Galaxy Research disclosed that recently, there has been on-chain activity involving the third wave of stolen funds from the Coldcard hardware wallet. Researchers noted that the attacker has transferred 97.09 BTC, equivalent to approximately $7.7 million at Monday’s price, accounting for about 45% of the total stolen in the third wave.
Funds are transferred in two directions.
On September 2, the attacker first transferred approximately 20.5 BTC from the largest vault address, then swapped them for Ethereum via THORChain. By the weekend, another batch of funds entered a CoinJoin round to obscure the correlation between transaction inputs and outputs.
Galaxy Research stated that the final amount of Bitcoin that reached Ethereum was 20.56 BTC. An additional 57.24 BTC remain at a single address as CoinJoin change, and researchers lost track of approximately another 19 BTC along subsequent paths.
293 addresses processed by size
Researchers stated that during the third wave of attacks, the attackers established 293 2-of-2 multisig vault addresses for victims' funds, processing them in descending order of size. So far, 11 of these addresses have been emptied.
- The next 10 addresses collectively hold 30.81 BTC.
- The remaining 233 smaller addresses collectively hold 33.77 BTC.
- Approximately 82% of the stolen bitcoins remain unmoved throughout the incident.
The vulnerability dates back to the 2021 firmware.
This theft can be traced to a firmware flaw introduced by Coinkite in March 2021. The flaw moved the seed generation process from the device’s hardware random number chip to a software alternative, reducing key entropy from 128 bits to as low as approximately 40 bits.
Researchers say this allows attackers to offline reconstruct private keys and drain funds from single-signature addresses without needing access to the hardware device. Coinkite has since updated its firmware, but seeds generated under older versions cannot be fixed by upgrading alone; affected users must generate new seeds and transfer their assets.
Total scale may continue to be revised upward
Galaxy Research also mentioned a previously unreported treasury address funded by 58 addresses. Researchers have not yet confirmed its origin but believe it may also contain funds from Coldcard victims.
If this assessment is correct, the total stolen amount publicly recorded by Galaxy Research would rise to approximately 1,806 bitcoins, equivalent to about $143.9 million at the price cited in the article. The firm previously mentioned an unconfirmed fourth wave of funds amounting to 638.5 bitcoins; if verified, the total scale of the incident would exceed 2,400 bitcoins.


