Coldcard Bitcoin exploit: hacker launders $7.8M as 82% stays frozen
A hacker who exploited a critical flaw in Coldcard hardware wallets has started moving stolen funds through cross-chain swaps and privacy mixers, according to blockchain analytics firm Galaxy Research. The Coldcard Bitcoin exploit, which has drained roughly 1,789 BTC from thousands of addresses since late July, is now entering a new and more troubling phase: the laundering stage.
Summary
Key takeaways
- An attacker exploited a Coldcard firmware bug to steal approximately 1,789 BTC starting July 30, 2026, according to Galaxy Research.
- At least 15 different attackers took part across multiple waves between July 30 and August 6.
- The Wave 3 hacker has laundered about 97.09 BTC (roughly $7.8 million) through THORChain and CoinJoin over five days, or about 45% of that wave’s stolen funds.
- Overall, 82% of all stolen Bitcoin remains parked in attacker-controlled wallets, while only 18% has moved in a way consistent with laundering.
- The root cause was a March 2021 Coinkite firmware bug that weakened wallet seed randomness, allowing offline brute-force attacks on private keys.
Coldcard Firmware Vulnerability and Bitcoin Theft
The entire episode traces back to a coding error that sat undiscovered for years before attackers found a way to weaponize it. Coinkite, the maker of Coldcard hardware wallets, shipped a firmware update in March 2021 that inadvertently broke how the devices generated wallet seeds, and that single bug is what made the recent theft possible.
March 2021 Firmware Bug and Seed Entropy Weakness
Starting with version 4.0.1, Coldcard devices — mainly the Mk3 and later models — began defaulting to a software-based pseudo-random number generator instead of relying on the hardware’s dedicated randomness source. The practical effect was that seeds were generated with only 40 to 72 bits of effective entropy, far below the 128 to 256 bits considered standard under modern cryptographic practice. That gap between what was expected and what was actually delivered is what turned a routine software update into a five-year ticking clock.
Attack Methodology and Exploit Timeline
Because the weakened seeds could be reconstructed mathematically, attackers with enough computing power were able to brute-force private keys entirely offline, without ever touching a victim’s physical device. Any wallet seed created during that vulnerable firmware window remained exposed, no matter how securely the owner had stored the device itself. The thefts tied to this flaw began on July 30, 2026, and Coinkite has since patched the bug and urged every affected user to generate a brand-new seed rather than trust the old one, since simply updating the firmware does not retroactively fix credentials already compromised.
Galaxy Research Investigation and Attacker Profile
Galaxy Research, led by analyst Alex Thorn, has been the primary outfit tracking the fallout in real time, and its numbers give the clearest picture yet of just how widespread the damage has been.
Tracking Multiple Waves and Attackers
The firm identified at least 15 separate attackers operating across several distinct waves between July 30 and August 6, after which activity dropped off sharply. The first wave alone extracted 1,082.65 BTC in just 41 minutes, a pace that strongly suggests automated scripts were scanning the blockchain for weak keys rather than any single manual effort. That kind of speed matters: it shows the vulnerability wasn’t exploited by one patient actor but discovered and raced against by multiple parties almost simultaneously.
Scale of Theft and Address Impact
Galaxy’s tally puts total confirmed losses at approximately 1,789 BTC, worth around $114.7 million at the time of the thefts, spread across more than 8,865 addresses, with the median victim losing more than 1 BTC. A newly identified cluster of 58 addresses, believed to be additional Coldcard victims, could push the running total to roughly 1,806 BTC. Galaxy said it has engaged directly with more than 190 victims and shared identified attacker addresses with law enforcement agencies and industry partners, though the firm has not confirmed whether a fourth wave is underway.
Laundering of Stolen Bitcoin via THORChain and CoinJoin
The Wave 3 attacker has now begun cashing out, and the method chosen says a lot about how sophisticated actors try to stay ahead of blockchain tracing tools. Galaxy flagged the movement on September 7, tying it directly to the same wallet cluster responsible for the third wave of thefts.
Cross-Chain Swaps and CoinJoin Mixing
The funds first surfaced on THORChain on September 2, where the attacker swapped Bitcoin into Ether. THORChain is a decentralized, permissionless liquidity protocol that lets users exchange native assets across different blockchains without going through a centralized exchange, which also means there is no operator able to freeze or reverse the transaction once it clears. By September 5 and 6, additional portions of the stolen Bitcoin had been run through CoinJoin transactions, the privacy technique behind much of the recent Bitcoin laundering THORChain activity, which bundles multiple users’ transactions together to obscure who sent what to whom. This CoinJoin privacy technique doesn’t make funds untraceable, but it does raise the cost and complexity of following the money.
Extent and Strategy of the Laundering Activity
Over that five-day window, the attacker moved roughly 97.09 BTC, worth about $7.8 million at the time, representing close to 45% of everything stolen in Wave 3 alone. Galaxy’s breakdown shows the attacker working through the largest vaults first: the top 11 ranked wallets have already been emptied, while the next ten untouched vaults hold 30.81 BTC and the remaining smaller vaults, ranked 61 through 293, hold 33.77 BTC combined. That size-ordered approach points to deliberate planning rather than a rushed liquidation.
Zooming out across the entire theft, the picture looks less alarming in the short term. About 82% of all stolen Bitcoin remains sitting untouched in attacker-controlled wallets, while only 18% has shown movement consistent with laundering. That gap matters for investigators: funds sitting still are easier to monitor and potentially intercept than funds already scattered across exchanges, but it also means the bulk of the exposure hasn’t been resolved yet, and firms like Chainalysis and Elliptic continue refining tools aimed at de-mixing CoinJoin outputs in cases like this one.
FAQ
How did attackers manage to steal Bitcoin from Coldcard wallets?
A firmware update released by Coinkite in March 2021 introduced a bug causing weak wallet seed entropy, enabling attackers to brute-force private keys offline.
How much Bitcoin was stolen in the Coldcard wallet exploit?
Approximately 1,789 BTC were stolen starting July 30, 2026, as tracked by Galaxy Research, with a newly identified cluster potentially pushing the total closer to 1,806 BTC.
What methods did attackers use to launder the stolen Bitcoin?
Attackers laundered about 97.09 BTC through THORChain cross-chain swaps and CoinJoin privacy mixing over five days, converting part of the stolen Bitcoin into Ether along the way.
What portion of the stolen Bitcoin remains unmoved by the attackers?
Around 82% of the stolen Bitcoin still remains in wallets controlled by the attackers, with only 18% showing movement consistent with laundering so far.
{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"How did attackers manage to steal Bitcoin from Coldcard wallets?","acceptedAnswer":{"@type":"Answer","text":"A firmware update released by Coinkite in March 2021 introduced a bug causing weak wallet seed entropy, enabling attackers to brute-force private keys offline."}},{"@type":"Question","name":"How much Bitcoin was stolen in the Coldcard wallet exploit?","acceptedAnswer":{"@type":"Answer","text":"Approximately 1,789 BTC were stolen starting July 30, 2026, as tracked by Galaxy Research, with a newly identified cluster potentially pushing the total closer to 1,806 BTC."}},{"@type":"Question","name":"What methods did attackers use to launder the stolen Bitcoin?","acceptedAnswer":{"@type":"Answer","text":"Attackers laundered about 97.09 BTC through THORChain cross-chain swaps and CoinJoin privacy mixing over five days, converting part of the stolen Bitcoin into Ether along the way."}},{"@type":"Question","name":"What portion of the stolen Bitcoin remains unmoved by the attackers?","acceptedAnswer":{"@type":"Answer","text":"Around 82% of the stolen Bitcoin still remains in wallets controlled by the attackers, with only 18% showing movement consistent with laundering so far."}}]}
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like

Australia sees $155B data center opportunity from AI boom
DBS and Citi complete first weekend tokenized cross-border payment via Swift
National Sheriffs’ Association drops opposition to Digital Asset Market Clarity Act
