Coldcard exploiter moves 45% of funds stolen from ‘Wave 3’ attacks, Galaxy says
The hacker responsible for exploiting Coldcard bitcoin hardware wallets has moved approximately 45% of stolen assets originating from the third wave of attacks, according to research from Galaxy Research. On-chain tracking reveals that the exploiter has begun actively laundering the stolen bitcoin, moving the funds through CoinJoin privacy transactions after previously swapping portions to ether via THORChain. To date, approximately 97.09 BTC, valued at roughly $7.8 million, has been moved and spent. The security breach originated from a Coinkite firmware vulnerability dating back to 2021, which compromised randomness during seed phrase generation and enabled brute-force theft across single-signature wallets. Overall, roughly 82% of all exploited assets remain stored in attacker-controlled addresses. Galaxy Research identified that the discovery of an additional 58-address victim vault raises total estimated losses across all attack waves to 1,806 BTC, valued at nearly $144 million. The continued liquidation and laundering of stolen bitcoin may exert localized sell pressure while raising ongoing concerns over hardware wallet security practices.