Coldcard attacker moves $7.7 million from 293-vault haul
A Coldcard attacker moved $7.7 million (97.09 BTC) from 11 of 293 multisig vaults, using THORChain and CoinJoin, with roughly 118.7 BTC remaining in the third wave.
The sequence covered 11 of 293 two-of-two multisig vaults, according to CoinDesk’s report.
The transfers began with about 20.5 BTC from the largest vault moving through THORChain on Sept. 2, with the proceeds landing on Ethereum. The attacker then sent 15.48 BTC from the second-largest vault into a CoinJoin transaction on Sept. 5, followed by 61.12 BTC from 10 vaults on Sept. 6.
That sequence gives on-chain observers a ranked view of what may move next. The operator built 293 two-of-two multisig addresses for victims’ coins and has been working through them in descending order of size. The next 10 vaults contain 30.81 BTC between them; vaults ranked 61 through 293 contain a combined 33.77 BTC.
The headline percentage is approximate, but the remaining balance can still be estimated. If 97.09 BTC represents 45% of Wave 3, then the implied wave total is 97.09 ÷ 0.45 = 215.76 BTC. Subtracting the moved amount leaves about 118.67 BTC, or roughly 55% of the wave, still unmoved.
That estimate is separate from the broader exploit balance. Across all Coldcard exploit waves, 82% of the stolen Bitcoin remains where the attackers first put it, meaning about 18% has moved. At the current Bitcoin price of $79,137 listed by CoinGecko, the 97.09 BTC moved in Wave 3 works out to about $7.68 million, consistent with the reported $7.7 million figure.
The movement path
The first Wave 3 exit used THORChain to move around 20.5 BTC into Ethereum. Only 20.56 BTC actually reached Ethereum, while another 57.24 BTC is sitting unspent as CoinJoin change in a single address, according to Decrypt’s account.
Galaxy’s trail ends on roughly 19 BTC more. That leaves the exact disposition of the full 97.09 BTC unresolved in the available tracking, even though the aggregate amount moved has been reported. The later transfers into CoinJoin rounds add another layer: the coins have entered transactions designed to pool inputs and outputs, while the change address itself remains unspent.
The 11 emptied vaults represent only about 3.8% of the 293-vault set: 11 ÷ 293 × 100 = 3.75%. They contain about 45% of the wave’s reported haul because the attacker is taking the largest balances first. The remaining vault count is therefore much larger than the emptied set, while its known balance is more fragmented: the 233 smallest vaults hold 33.77 BTC in total.
The next exposure is concrete. If the descending-size sequence continues, the next 10 vaults identified in the tracking hold 30.81 BTC, worth roughly $2.44 million at $79,137 per BTC. That does not establish that those coins will move next, but it identifies the next ranked pool described by the tracking. For holders and counterparties watching addresses tied to the exploit, the main near-term issue is whether the operator continues emptying vaults or leaves the balance in place.
The bug and the remaining risk
The thefts trace to a firmware bug Coinkite introduced in March 2021. The flaw rerouted seed generation away from the device’s hardware random-number chip and onto a software substitute, collapsing key strength from 128 bits of entropy to as low as 40 bits.
Sweeps of the stolen funds began on July 30. Coinkite has since overhauled the firmware, with versions listed as Mk4/Mk5 5.6.2 and Q 1.5.2Q. An update cannot repair a seed generated under the flawed version, however. Affected users must create new seeds and move their funds, leaving users with vulnerable seeds worse off until that migration is completed.
The consequence for holders is therefore operational rather than tied only to the attacker’s latest transaction: fixed firmware does not secure an old seed. Funds generated under the affected version need to be moved to a newly generated seed, while the attacker’s continuing sweeps mean the remaining balances can still become targets.
A previously unidentified vault funded by 58 addresses was also flagged. It used the same two-of-two multisig format, and Galaxy believes it belongs to another Coldcard victim. If included, Wave 3 would rise to 294 vaults and the wider exploit would reach about 1,806 BTC, worth roughly $143.9 million.
Galaxy also said in August that it was carrying an unconfirmed fourth wave of 638.5 BTC, which would push the total past 2,400 BTC.
The current Wave 3 ledger is clearer: 293 vaults were created, 11 have been emptied, 97.09 BTC has moved, and an estimated 118.67 BTC remains based on the reported 45% share. The next balances are already visible in the size ranking.