VERSE PRESS

Crypto News, Global First.

Coldcard Attacker Moves 97 BTC as Galaxy Research Maps the Full Damage

The operator behind Wave 3 of the Coldcard firmware exploit shifted nearly half their holdings this week, even as roughly 82% of all stolen coins remain parked in attacker-controlled addresses.

|

The person or group responsible for Wave 3 of the Coldcard hardware wallet exploit (the third of at least three distinct attack waves) transferred approximately 97.09 BTC (about 45% of their Wave 3 holdings) between September 2 and September 6, 2026, according to on-chain tracking by Galaxy Research. The movement came through a combination of THORChain swaps converting Bitcoin to Ether and CoinJoin privacy rounds, both methods designed to obscure the trail of stolen funds. The broader exploit, which began July 30 and targeted a firmware flaw in Coinkite's Coldcard devices, has now been confirmed to affect at least 1,806 BTC worth roughly $143.9 million at current prices.

How the Attacker Is Moving the Money

Wave 3's operator started by draining the largest vault first, pulling 20.50 BTC on September 2 via THORChain, then working down through sequentially smaller vaults. By September 5 and 6, the operator had switched to CoinJoin rounds, a technique that pools Bitcoin transactions from multiple parties to reduce traceability. In earlier laundering activity documented by TRM Labs, 64.9 BTC was funneled through Wasabi Coinjoin and 200 ETH through Tornado Cash. As of September 7, 116.98 BTC remains spread across 282 vaults still under Wave 3 control.

Galaxy Research has mapped 293 separate 2-of-2 multisignature vaults used to hold victim funds across all waves. Approximately 82% of stolen coins have not moved from their original attacker addresses. A suspected fourth wave, if confirmed, could push total losses to roughly 2,417 BTC, or approximately $151.3 million. That figure reflects a different BTC price baseline than the confirmed total of $143.9 million cited above; the two estimates are drawn from different sources and different price snapshots and should not be read as directly comparable.

The Flaw Behind the Theft

The root cause traces to a firmware build error introduced in Coldcard version 4.0.1 in March 2021. That error caused the device to fall back to a weak software-based random number generator during seed creation instead of drawing on the hardware's own entropy source. The cryptographic strength of keys generated on affected devices collapsed from a designed 128 bits to as low as 40 bits on older Mk3 hardware and around 72 bits on Mk4 and Mk5 units.

At 40-bit entropy, an attacker with parallel computing resources faces a key space of roughly 1.1 trillion possibilities, which is searchable. Crucially, the attackers needed only three device-specific inputs to reconstruct private keys offline: chip identifier, boot timing, and clock state. No physical access to the devices was required. Affected firmware ran from version 4.0.1 through 4.1.9 on Mk2 and Mk3 devices, through pre-5.6.0 on Mk4 and Mk5 units, and through pre-1.5.0Q on the Coldcard Q model.

Wave 1 alone drained 1,082.65 BTC from 1,195 addresses in approximately 41 minutes on July 30. The last confirmed attacker activity was recorded on August 6. Galaxy Research says no new attack waves have appeared since then, suggesting most vulnerable holders have either migrated funds or already been emptied.

James Thorne, Galaxy Digital's head of research, told Bloomberg he has spoken directly with more than 100 affected users and described the event as "a tragedy for the Bitcoin community," adding that many victims lost their entire savings. Galaxy Research has separately confirmed at least 190 victims and more than 8,600 affected addresses as of mid-August. Thorne said he is coordinating victim reports, monitoring fund movements, and sharing materials with law enforcement.

Notably, Coinkite reportedly conducted an AI-assisted security review weeks before the exploit became public, and that review did not detect the defect, according to NYDIG. Subsequent testing with frontier AI models reproduced the same audit failure, raising broader questions about the reliability of AI-assisted review for cryptographic edge cases.

Regional Stakes: Where Self-Custody Is the Only Option

For users in Nigeria, India, Pakistan, and Kenya, the implications go beyond a software bug. In these markets, hardware wallets are not a preference but a practical necessity. Over 33 million Nigerians hold cryptocurrency, many doing so to work around banking restrictions or capital controls. India ranks first globally in the Chainalysis Crypto Adoption Index; Pakistan ranks fifth. In this context, a single compromised hardware wallet often represents a meaningful share of a household's long-term savings and remittance holdings.

The post-exploit pivot toward regulated Bitcoin ETFs, which analysts at FRNT Financial say could accelerate demand in Western markets, is largely unavailable across sub-Saharan Africa and much of South Asia. Domestic spot ETF markets in these regions are nascent or non-existent, and access to offshore products is constrained, leaving affected users with fewer fallback options than their counterparts in the US or Europe. The Human Rights Foundation underscored the importance of non-custodial infrastructure in the Global South through its September 2026 grants round, which included funding for three African projects focused on self-custody wallet security and censorship-resistant messaging.

NYDIG Research framed the structural problem plainly: "Cold storage is only as secure as the process used to generate, protect, and govern the underlying keys."

What Comes Next

Galaxy Research continues to monitor fund movements and is sharing findings with law enforcement. Coinkite has confirmed that installing a firmware update does not fix an existing compromised seed; users must generate entirely new seeds on patched hardware. Users who generated seeds with at least 50 fair and independent dice rolls through the device's Add Dice Rolls feature are considered safe, assuming those rolls were not recorded or exposed. For users without access to institutional custody alternatives, a multi-device multisignature setup remains the most viable path to stronger security going forward.