TL;DR
The third wave of the Coldcard theft continues to unfold as Galaxy Research tracks fresh movements from the exploiter who has begun shifting significant portions of stolen Bitcoin. The latest activity shows the attacker moving 97.09 BTC, worth $7.7 million, through THORChain and CoinJoin transactions, marking a major step in the laundering process. Coldcard remains central to the investigation, with researchers uncovering new vaults and tracing patterns that reveal how the attacker structured the operation.
Coldcard ‘Wave 3’ exploiter continues to move funds
In wave 3, the exploiter created 293 2-of-2 multisig vaults for each victim’s coins.
The first movements on 9/2 sent coins over THORChain to Ethereum.
Tonight’s movements are going into coinjoins rounds. pic.twitter.com/H7HIpcI7ah
— Galaxy Research (@glxyresearch) September 7, 2026
Galaxy said the exploiter started routing funds on Sept. 2, sending 20.5 BTC from the largest vault through THORChain, with proceeds landing on Ethereum. Days later, the attacker shifted 15.48 BTC from the second-largest vault into a CoinJoin transaction, followed by another 61.12 BTC from 10 vaults. CoinJoin mixes payments from multiple users, making it harder to link inputs and outputs, and Galaxy believes these steps were taken to obscure the trail.
Both texts confirm the attacker created 293 two-of-two multisignature vaults to hold victims’ coins. The exploiter has now emptied the 11 largest vaults, and the next 10 contain 30.81 BTC. Vaults ranked 61 through 293 hold a combined 33.77 BTC. Galaxy also identified a previously unknown vault funded by 58 addresses, likely tied to another Coldcard victim, though its origin remains unconfirmed.

Including the newly identified vault, Wave 3 may rise to 294 vaults and push the wider Coldcard exploit to about 1,806 BTC, valued near $143.9 million. Galaxy said about 82% of stolen Bitcoin across all waves remains in attacker-controlled addresses, while 18% has moved in transactions that appear designed to hide the funds’ path.
The thefts began July 30 after attackers exploited a firmware flaw that weakened randomness used by Coldcard devices to generate wallet seeds. Coinkite has released fixed firmware, but affected users must create new seeds and move their funds because an update cannot repair compromised ones. Coldcard remains at the center of one of 2026’s largest crypto security incidents.