Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Coldcard Hacker Moves $7.7M in Bitcoin Through Privacy Mixers

The attacker behind the third wave of Coldcard hardware wallet thefts has moved 97.09 BTC through THORChain and CoinJoin rounds, representing roughly 45% of that wave's stolen funds. Across all waves of the exploit, 82% of the stolen Bitcoin remains unmoved.
1 hour ago 7 views
Coldcard Hacker Moves $7.7M in Bitcoin Through Privacy Mixers

The operator behind the third wave of thefts from Coldcard hardware wallets has moved 97.09 BTC, valued at approximately $7.7 million, according to Galaxy Research. The movement began on September 2, when around 20.5 BTC from the largest vault was sent through THORChain and converted to Ethereum.

Additional funds moved over the weekend into CoinJoin rounds, a Bitcoin privacy technique that pools transactions from multiple users to obscure the connection between inputs and outputs. Galaxy Research noted that 57.24 BTC remains unspent as CoinJoin change in a single address, with trails ending on approximately 19 BTC more.

Vault Structure and Remaining Funds

The attacker constructed 293 two-of-two multisig addresses, each holding victims' coins. Eleven vaults have been emptied, while the next ten contain 30.81 BTC combined. The remaining 233 smallest vaults hold 33.77 BTC in total.

Root Cause: 2021 Firmware Flaw

The thefts originate from a firmware bug introduced by Coinkite in March 2021. The flaw rerouted seed generation from the device's hardware random-number generator to a software substitute, reducing key entropy from 128 bits to as low as 40 bits. This enabled attackers to reconstruct private keys offline and drain single-signature addresses without physical access to the hardware.

Sweeps began on July 30. Coinkite has released updated firmware versions Mk4/Mk5 5.6.2 and Q 1.5.2Q, which require users to supply their own randomness through key presses, dice rolls, or coin flips. However, seeds generated under the flawed firmware cannot be repaired; affected users must generate new seeds and transfer coins to fresh addresses.

Coinkite CEO Rodolfo Novak issued an apology on July 31, stating the company would need to earn back user trust. A full technical postmortem remains in preparation.

Scale of the Exploit

Galaxy Research identified a previously unknown vault fed by 58 addresses, which it believes represents another Coldcard victim. This finding brings the published total for the exploit to approximately 1,806 BTC, or $143.9 million. Galaxy also noted an unconfirmed fourth wave containing 638.5 BTC, which would push the total past 2,400 BTC. No attacker sweeps have been logged since August 6.

Across all waves of the exploit, 82% of the stolen Bitcoin remains where attackers originally placed it.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $79,463.44-0.66% EthereumETH $2,492.09-0.44% Tether USDUSDT $0.9998-0.01% BNBBNB $745.51-1.64% XRPXRP $1.40-1.32% USDCUSDC $0.99990.00% SolanaSOL $105.23-1.26% TRONTRX $0.3362+0.31% HyperliquidHYPE $88.22-1.00% ZcashZEC $1,193.82+1.42%
Prices by Coinranking. Informational only.