Friday, September 18, 2026
BTC: $78,186 +2.01% ETH: $2,511 +2.72% SOL: $106.03 +5.38% XRP: $1.33 +2.06% ADA: $0.2146 +7.43%

Coldcard Attacker Drains 11 Largest Vaults in Third Wave, Moving $7.8 Million in BTC

The attacker behind the third wave of Coldcard hardware-wallet thefts has drained the 11 largest compromised vaults, moving $7.8 million in BTC, per Galaxy Research.

The attacker draining Coldcard hardware wallets has moved 45% of the bitcoin stolen in the campaign’s third wave. Some 97.09 BTC, roughly $7.8 million at recent prices, is now in motion, according to Galaxy Research.

Galaxy has tracked the exploits from the start. The pattern is mechanical: compromised vaults emptied largest first. Ranks one through 11 are gone. The next 10 untouched vaults still hold 30.81 BTC. Smaller ones, ranks 61 to 293, carry a combined 33.77 BTC.

This is the latest turn in a hardware-wallet security crisis rooted in a 2021 Coinkite firmware bug. The flaw degraded the randomness behind wallet-seed generation on Coldcard devices. Attackers can brute-force private seed phrases and drain single-signature addresses without ever touching the hardware.

Anyone whose Coldcard seed was produced under that code remains exposed.

Galaxy had counted roughly 1,779 BTC taken from 190 victims across more than 8,600 addresses by mid-August. On Monday, the firm said the exploiter “co-spent” a previously unknown vault of 58 addresses likely tied to Coldcard victims. That pushes total losses to 1,806 BTC, about $143.9 million at current prices.

Most of the haul has not moved far. Galaxy said 82% of total exploited funds still sit in the original attacker-controlled addresses. The rest has gone through laundering steps. On Sept. 2, the exploiter swapped stolen bitcoin for ether via THORChain. On Sunday, the funds passed through CoinJoin transactions.

The waves track the attacker’s appetite for moving coins in batches. Galaxy has flagged the possibility of a fourth wave. It has not confirmed one.

Traders, as ever, disagree on what the on-chain churn signals.

The broader theft campaign started July 30. The Block traces the root cause to that 2021 Coinkite firmware bug affecting seed generation. Whether Coinkite has issued a patch or formal guidance was not stated in the reporting.

What remains unknown: the attacker’s identity, whether a fourth wave is coming, and how many compromised Coldcard devices still hold funds at risk.