Coldcard hacker moves $7.7M in Bitcoin as laundering operation shifts to CoinJoin rounds
Attacker shifts from hoarding to obfuscation using cross-chain bridges and mixing protocols

The attacker behind the massive Coldcard hardware wallet exploit has begun actively laundering stolen funds, moving 97.09 BTC worth roughly $7.7 million out of a custom-built storage network. Galaxy Research, the blockchain analytics firm tracking the fallout, confirmed the movements represent about 45% of the assets taken during the “Wave 3” phase of the thefts. The laundering campaign started on September 2, when the attacker routed approximately 20.5 BTC from their largest storage vault through THORChain, a decentralized liquidity protocol that enables cross-chain swaps without KYC verification. That initial batch of Bitcoin was converted into native Ethereum.
The roots of the exploit trace back to a firmware update shipped by Coinkite in March 2021. The Canadian-based manufacturer of Coldcard wallets—long favored by high-net-worth Bitcoin holders for its air-gapped design—inadvertently introduced a devastating defect in the seed generation mechanism. The flawed update bypassed the onboard True Random Number Generator chip, rerouting the critical seed-generation process to a weaker software-based stand-in. This collapsed the mathematical strength of generated keys from 128 bits of entropy down to as low as 40 bits, a critically small pool that modern computers can brute-force in hours or days.
Over the weekend following the initial THORChain swap, the exploiter shifted tactics. Instead of continuing to use cross-chain bridges, they routed subsequent batches of stolen Bitcoin into CoinJoin rounds. CoinJoin is a trustless, peer-to-peer mixing methodology that groups multiple transactions into a single transaction, breaking the deterministic on-chain link between sender and receiver. Of the total amount moved during this sequence, only 20.56 BTC has been confirmed to have reached the Ethereum network. A substantial portion—57.24 BTC—remains unspent, sitting as CoinJoin change in a single cryptographic address. The visible transaction trail for the remaining portion, approximately 19 BTC, has gone cold following the mixing rounds.

To manage and secure the massive haul, the hacker engineered a highly structured custody system consisting of 293 distinct two-of-two multisig addresses. In a 2-of-2 multisig configuration, two separate private keys are generated, and both must sign for funds to move. The operator has been systematically draining these custom vaults in order of their balance size. Eleven of the largest multisig vaults have been completely emptied. The next ten largest vaults hold a combined total of 30.81 BTC, while the remaining 233 smallest addresses hold a collective 33.77 BTC.
The attacker reconstructed private keys offline without needing physical access to Coldcard devices or their PIN codes. The coordinate sweeps of compromised wallets began on July 30. Coinkite responded by releasing patches Mk4/Mk5 5.6.2 and Q 1.5.2Q, which implement a strict requirement for manual entropy generation—users must now supply physical randomness by registering key presses, rolling dice, or flipping coins. However, firmware updates cannot retroactively repair seed phrases generated under the flawed 2021 firmware. Anyone who initialized a Coldcard wallet using affected software versions remains permanently vulnerable and must generate an entirely new seed phrase under patched firmware.
Galaxy Research identified a previously undocumented vault fed by 58 unique addresses. While the exact origins of this newly discovered vault remain open to investigation, researchers believe it is tied to another set of compromised Coldcard wallets. The integration of this 58-address vault brings the confirmed total stolen across the exploit to approximately 1,806 BTC, valued at roughly $143.9 million. Coinkite Chief Executive Rodolfo Novak issued a public apology in an open letter on July 31, acknowledging the severity of the software bug and stating the company would have to work to “earn back our users’ trust.” The company is currently preparing a comprehensive technical postmortem.
If an unconfirmed “Fourth Wave” of thefts involving 638.5 BTC is verified, the total losses attributable to the 2021 firmware flaw will exceed 2,400 BTC (more than $190 million). Across all identified phases of the exploit, roughly 82% of the stolen Bitcoin has not moved from the initial addresses where the attacker first deposited them, leaving a massive portion of the illicit haul under continuous observation by global security firms and law enforcement agencies.








