Key facts
- The exploiter of the Coldcard wallet has moved about 45% of stolen Bitcoin.
- Funds were moved through THORChain to Ethereum and into CoinJoin transactions.
- The attacker used 293 multisignature vaults to hold victim funds.
- 82% of all stolen Bitcoin across all Coldcard exploits remains in original addresses.
- 18% of stolen Bitcoin has been moved, apparently for laundering.
The exploiter behind the third wave of the Coldcard wallet hack has moved approximately 45% of their Bitcoin haul, routing the funds through THORChain or into CoinJoin transactions, according to Galaxy Research. In an update on Monday, Galaxy stated that the exploiter began moving funds to Ethereum via THORChain on September 2. The latest transactions involved sending Bitcoin into CoinJoin rounds, a method that combines multiple users' payments into a single transaction to obscure the origin of funds.
Galaxy reported that the third-wave exploiter had established 293 two-of-two multisignature vaults to secure victims' coins and was moving funds from the largest vaults in descending order. Funds from the 11 largest vaults have now been transferred. These transactions also enabled Galaxy to identify a previously unknown vault, which likely held another Coldcard victim's funds, though the cause of that loss remains unconfirmed.
Across all identified waves of the Coldcard exploit, approximately 82% of the stolen Bitcoin remains in the original attacker-controlled addresses, while 18% has been moved, apparently for laundering purposes, Galaxy noted. The Coldcard exploit is ranked as the third-largest exploit in 2026, following the $293 million Kelp DAO hack and the $280 million Drift protocol hack, according to DefiLlama.