Coldcard Exploiter Moves 45% of Stolen Bitcoin Amid Laundering Efforts
The exploiter behind the third wave of attacks on Coldcard wallets has moved 45% of the stolen coins, according to Galaxy Research. The funds were transferred either through THORChain to Ethereum or into Coinjoin, in an effort to launder the assets.
The attack began on July 30, 2026, and targeted Coldcard wallets with a firmware flaw that had existed for years. The issue came from a March 2021 update and a build error, which weakened seed security from 128 bits to as low as 40 bits on older devices.
The exploiter created 293 2-of-2 multisig vaults for victims' coins during Wave 3. Ranks 1 through 11 have already been moved, while the next 10 unmoved vaults contain 30.81 BTC ($79,205.00).