Finst

Coldcard Hacker Moves $7.7 Million in Bitcoin

Galaxy Research says the attacker used THORChain and CoinJoin to hide the trail. Coldcard has now released a firmware fix, but affected users need to create new seeds.

Coldcard Hacker Moves $7.7 Million in Bitcoin

Key Takeaways

  • The hacker behind the third Coldcard theft wave moved 97.09 BTC, worth about $7.7 million, through two different routes.
  • Galaxy Research said the attacker moved bitcoin through THORChain, CoinJoin, and multiple vaults, making the flow of funds harder to track.
  • The bug was in Coldcard firmware with weak seed generation; affected users need to create new seeds and move their funds.

The hacker behind the third wave of thefts from Coldcard hardware wallets moved 97.09 BTC, worth about $7.7 million (€6.6 million), through two different routes. That is nearly 45% of the bitcoin stolen in this attack wave, according to Galaxy Research.

Moves Through THORChain

Galaxy said the attacker sent about 20.5 BTC from the largest vault through THORChain on September 2, after which the proceeds ended up on Ethereum. Two days later, 15.48 BTC from the second-largest vault followed through a CoinJoin transaction. On September 6, another 61.12 BTC was moved from ten vaults.

CoinJoin bundles bitcoin transactions from multiple users, making it harder to link specific inputs to later outputs. That makes it tougher for researchers to follow the flow of funds, especially when multiple routes are used at the same time.

What Galaxy Saw

According to Galaxy, the attacker is working through the 293 vaults in order of size, and the 11 largest have now been emptied. The next 10 vaults still hold a combined 30.81 BTC, while vaults 61 through 293 together hold 33.77 BTC. Galaxy also stressed that these vaults do not belong to the victims themselves, but were created by the attacker using a two-of-two multisignature setup.

The company also said that an earlier unidentified vault, funded from 58 addresses, is likely tied to another Coldcard victim as well, although that has not been confirmed yet. If that vault is counted, Wave 3 comes to 294 vaults and the broader exploit rises to about 1,806 BTC, worth roughly $143.9 million (€124 million).

Why This Matters for Users

The case shows how vulnerable hardware wallets can be when seed generation does not work properly. The bug was in Coldcard firmware that weakened the randomness of the seed, allowing attackers to reconstruct private keys offline. Coinkite has now released a fixed firmware version, but it warns that affected users need to create new seeds and move their funds, because an update alone does not restore seeds that were already compromised.

Galaxy also said that about 82% of the stolen bitcoin across all waves is still sitting in addresses controlled by the attacker. About 18% has been moved in transactions meant to hide where the funds came from.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.