All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Crypto & Digital Assets

Coldcard attacker moves 45% of stolen Bitcoin via THORChain, CoinJoin

Created at 7 Sep · 9:46 AM1 source↑ Market-relevant
IN SHORT

The exploiter behind the third wave of the Coldcard wallet hack has moved approximately 45% of their Bitcoin, routing funds through THORChain or into CoinJoin transactions for laundering, according to Galaxy Research. Across all Coldcard exploits, 82% of stolen Bitcoin remains in original addresses.

Key Numbers

45%stolen Bitcoin moved by third-wave attacker
82%stolen Bitcoin remaining in original addresses
18%stolen Bitcoin moved for laundering
293multisignature vaults created by attacker
11largest vaults from which funds have been moved
$293 millionKelp DAO hack
$280 millionDrift protocol hack

Who's Involved

Galaxy Research
provided analysis on Bitcoin movements
Coldcard
wallet targeted in exploit
THORChain
platform used for fund routing

↳ Why This Matters

The movement of stolen Bitcoin indicates ongoing efforts to launder illicit funds, highlighting the challenges in tracing and recovering assets lost in cryptocurrency exploits. The analysis provides insights into the methods used by attackers and the effectiveness of privacy-enhancing techniques.

Key facts

  • The exploiter of the Coldcard wallet has moved about 45% of stolen Bitcoin.
  • Funds were moved through THORChain to Ethereum and into CoinJoin transactions.
  • The attacker used 293 multisignature vaults to hold victim funds.
  • 82% of all stolen Bitcoin across all Coldcard exploits remains in original addresses.
  • 18% of stolen Bitcoin has been moved, apparently for laundering.

The exploiter behind the third wave of the Coldcard wallet hack has moved approximately 45% of their Bitcoin haul, routing the funds through THORChain or into CoinJoin transactions, according to Galaxy Research. In an update on Monday, Galaxy stated that the exploiter began moving funds to Ethereum via THORChain on September 2. The latest transactions involved sending Bitcoin into CoinJoin rounds, a method that combines multiple users' payments into a single transaction to obscure the origin of funds.

Galaxy reported that the third-wave exploiter had established 293 two-of-two multisignature vaults to secure victims' coins and was moving funds from the largest vaults in descending order. Funds from the 11 largest vaults have now been transferred. These transactions also enabled Galaxy to identify a previously unknown vault, which likely held another Coldcard victim's funds, though the cause of that loss remains unconfirmed.

Across all identified waves of the Coldcard exploit, approximately 82% of the stolen Bitcoin remains in the original attacker-controlled addresses, while 18% has been moved, apparently for laundering purposes, Galaxy noted. The Coldcard exploit is ranked as the third-largest exploit in 2026, following the $293 million Kelp DAO hack and the $280 million Drift protocol hack, according to DefiLlama.

Frequently asked questions

CoinJoin is a privacy-enhancing technique that combines multiple users' Bitcoin transactions into a single, larger transaction, making it more difficult to trace the origin and destination of individual payments.

THORChain is a cross-chain liquidity protocol that allows users to swap cryptocurrencies across different blockchains without the need for wrapped tokens.

A multisignature vault, or multisig wallet, requires multiple private keys to authorize a transaction, enhancing security by distributing control and requiring consensus.

What Happens Next

01Further analysis of remaining funds in original addresses.
02Monitoring of any further fund movements by the exploiter.

How It Developed

The exploiter behind the third wave of the Coldcard wallet hack began moving funds on Sept. 2.
Funds were routed through THORChain to Ethereum and into CoinJoin transactions.
The attacker created 293 multisignature vaults to hold victims' coins.
Funds from the 11 largest vaults have been moved.
A previously unknown vault was identified due to the transactions.
Approximately 82% of all stolen Bitcoin remains in original addresses, with 18% moved for laundering.

Sources

T1
Coldcard third-wave attacker moves 45% of stolen BitcoinGalaxy said 82% of Bitcoin stolen across all Coldcard attacks remains in the original addresses, with 18% moved in apparent laundering.Cointelegraph

Related Stories

Blockstream's Liquid Network Drained of 4000 BTC in Alleged Hack
7 Sep · 4:36 AM
Vitalik Buterin Dismisses AI Threat to Bitcoin Security
7 Sep · 8:00 AM
Fomo surpasses Pump.fun in daily revenue on Solana
7 Sep · 7:56 AM