Coldcard Hacker Moves 45% of Stolen Bitcoin via THORChain and CoinJoin
Security

Coldcard Hacker Moves 45% of Stolen Bitcoin via THORChain and CoinJoin

September 7, 20264 min read

The attacker behind the third wave of Coldcard wallet hacks has started moving the stolen Bitcoin. According to research firm Galaxy Research, roughly 45% of the funds from this wave have already changed hands. For hardware wallet owners, the case is another reminder that offline storage alone does not guarantee full safety of funds.

What happened to Coldcard wallets?

Coldcard, a hardware wallet for storing Bitcoin, is popular among users who prioritize maximum privacy and full independence from the internet. The device operates offline and signs transactions without a network connection, which until recently made it one of the safer options for cold storage.

In spring 2026 researchers spotted a string of attacks on device owners, and the wave that surfaced in September marks the third such incident. Each wave relied on a different compromise vector, but the outcome stayed the same. Victims' private keys ended up in attackers' hands, and funds moved out with no way to reverse the transaction.

Galaxy Research says the third-wave attacker set up 293 two-of-two multisig vaults to hold victims' coins. Splitting the stolen funds across hundreds of separate wallets made the haul far harder to trace and avoided one large transfer that would have immediately caught exchange analysts' attention.

How is the hacker covering their tracks?

Key point: The attacker is routing Bitcoin into Ethereum through the THORChain bridge and passing part of the funds through CoinJoin transactions to blur the trail.

On September 2 the attacker began moving funds through THORChain, a protocol for swapping assets across blockchains without a centralized exchange. The protocol has repeatedly drawn attention from blockchain investigators because it lets anyone convert assets instantly without registration or KYC checks.

Part of the Bitcoin then passed through CoinJoin, a technique that bundles several users' payments into one shared transaction to make the transfer chain harder to follow. The technology itself was built to protect ordinary users' privacy rather than to launder stolen funds, which is exactly why it cannot be banned outright at the Bitcoin protocol level.

The withdrawals are not random. The attacker is draining the largest vaults first, working down in order of size, while smaller wallets remain untouched for now.

  • Step one: funds move from the multisig vaults to intermediate addresses.
  • Part of the amount gets converted into Ethereum through THORChain.
  • Another part runs through CoinJoin rounds to mix with unrelated transactions.
  • Galaxy analysts track each transfer and publish updates in real time.

How much money is at stake?

Decrypt estimates the attacker has pulled out about $7.7 million since the withdrawals began, close to half of the entire third-wave haul. Funds from the 11 largest vaults have already been emptied, and analysts expect mid-sized vaults to be next.

Scale of the 2026 Coldcard hacks
Moved from the third wave~45% ($7.7M)
Multisig vaults created293
Still sitting at attacker addresses (all waves)~82%
Rank among 2026 exploits3rd (per DefiLlama)

Tellingly, the share of funds already moved in the third wave is far higher than the average across all Coldcard waves combined, where only 18% of stolen coins have shifted. The gap shows this particular attacker is moving much more aggressively than earlier ones and is not waiting for attention to fade.

The biggest exploit of the year so far remains the Kelp DAO hack ($293 million), followed by the Drift protocol hack ($280 million). The Coldcard attacks rank third on that list, though by number of affected wallet owners they may well outpace both protocols.

Why is the exploit being tracked so closely?

Galaxy Research is posting real-time updates, and that is not just researcher curiosity. Tracing the funds through THORChain and CoinJoin helped the team spot another, previously unknown vault. It likely holds another Coldcard victim's coins, though that loss has not been officially confirmed yet.

Publicity works against the attacker here. Every new transaction leaves a trace that blockchain analysts can link back to earlier transfers, even with mixers thrown into the route. Once a wallet finally lands on an exchange's deposit address, the platform's security team already has a list of flagged addresses and can block the withdrawal at the deposit stage.

That is why researchers publish step-by-step updates instead of a single final report. It gives exchanges and victims time to react while the funds are still moving through the network, not after they are already gone for good. Owners who bought a Coldcard before spring 2026 can check their addresses against Galaxy Research's public reports or contact the manufacturer's support if they have not received an official warning yet. Silence from a vendor is not proof that a wallet is safe.

What does this mean for hardware wallet owners?

The Coldcard case is a reminder of something simple. A hardware wallet protects the private key but cannot fix firmware flaws or supply chain attacks on its own. Trezor also disclosed a customer data leak this summer, though without a direct loss of funds from wallets.

For Bitcoin and Ethereum holders, the practical takeaways are simple. Install firmware updates as soon as patches ship, check device integrity at purchase, and avoid keeping an entire balance on a single wallet. Splitting funds across several storage points protects ordinary holders just as much as it complicates life for attackers.

The case also revives an old community debate: whether holding large sums in self-custody still makes sense when even trusted brands slip up. There is no single right answer, but not putting all your eggs in one basket works for wallets just as well as it does for an investment portfolio.

In Coldcard's case, splitting the funds into hundreds of small vaults ended up complicating life for the attacker, not the victims: every transfer now sits under analysts' watch, and fully disappearing into the network looks unlikely.

Share:

Comments

Your email address will not be published. Required fields are marked *

or verify by email