The exploiter behind the third wave of the Coldcard hack has transferred approximately 45% of their Bitcoin haul. The transactions were routed through THORChain and CoinJoin mixers, according to a report from Galaxy Research published on September 7, 2026.
https:/twitter.com/glxyresearch/status/2096785347929608296
The fund dispersal began on September 2, 2026. On that date, the actor moved capital to Ethereum through THORChain cross-chain swaps, following a prior conversion to Ether that had previously transferred 10% of the funds taken during this third attack wave.
Subsequent transactions directed remaining Bitcoin into CoinJoin rounds. CoinJoin combines multiple users’ payments into a single consolidated transaction. This structure obscures ownership trails on the Bitcoin ledger, making tracing between input addresses and eventual withdrawal wallets far more complex.
CoinJoin rounds typically process standardized denominations across consecutive mixing cycles. Large volume holders must complete dozens of sequential stages, which explains why the attacker prioritized processing the largest balances first during the initial laundering phase.
To store the stolen assets, the attacker configured 293 two-of-two multisignature vaults. Blockchain analysts observed that outflows occurred in descending order of vault size. As of September 7, 2026, the 11 largest vaults under this operator’s control have been completely emptied.
These 293 vaults utilized a two-of-two multisignature scheme where the exploiter controlled both private keys. This arrangement required two signatures to authorize any outgoing transaction, allowing the actor to segregate stolen coins across individual wallets prior to initiating mixing activity.
Tracing these transactions led investigators to identify a previously unmapped vault. Galaxy determined that this storage unit likely held assets belonging to another Coldcard victim, though the exact technical vector behind that specific drainage remains unconfirmed by official security advisories.
Partial liquidation of consolidated assets
Despite these movements, most stolen capital remains untouched. Across all identified waves of the Coldcard exploit, 82% of the stolen Bitcoin remains in the original attacker-controlled addresses. Only 18% has been moved through laundering channels as of September 2026.
The vulnerability stemmed from firmware 4.0.1, released by Coinkite in March 2021. A code configuration issue caused seed generation to use a fallback software random number generator. This dropped entropy on affected devices to 40 bits, exposing keys to offline brute-force calculation without physical access.
Starting July 30, 2026, attackers drained roughly 1,816 BTC across more than 5,200 addresses. Coinkite issued firmware patches on July 31, 2026, clarifying that updating firmware protects future generation but requires users with vulnerable seeds to migrate assets to newly created wallets.
Security breach scale in annual rankings
The Coldcard breach ranks as the third-largest cryptocurrency exploit of 2026. It trails behind the Kelp DAO security exploit, which accounted for $293 million in losses, and the $280 million incident that affected Drift Protocol in 2026.
Those comparative figures come from the exploit database from DefiLlama, which monitors smart contract breaches and digital asset theft. The platform’s records indicate that total crypto ecosystem losses exceeded $1.2 billion across 276 separate incidents during the first nine months of 2026.
For now, 282 secondary vaults remain untouched under the third-wave attacker’s control. Cybersecurity researchers have shared details of more than 600 associated addresses with federal investigators and compliance platforms to identify future consolidation attempts or liquidity offramps.
On-chain analysis teams continue reviewing transaction signatures to verify whether the successive theft waves represent a coordinated group or separate actors taking advantage of the publicized firmware vulnerability. Distinct transaction construction between phases points to potential operational differences.
Recovery options remain dependent on ongoing tracking across cross-chain bridges and potential freezes if funds touch regulated centralized service providers.
This article is for informational purposes only and does not constitute financial advice.

