- Third-wave Coldcard hacker has already transferred roughly 45% of the stolen Bitcoin through THORChain and CoinJoin transactions.
- According to Galaxy, 82% of stolen Bitcoin from Coldcard hacks has remained in the possession of attackers.
The perpetrator of the third wave attack against the Coldcard wallet has escalated the pace of transferring funds, reports Galaxy Research. The exploiters have transferred approximately 45% of the Bitcoin stolen from the third wave so far. These transfers indicate a pattern of using methods that make blockchain tracking difficult.
Coldcard ‘Wave 3’ exploiter continues to move funds
— Galaxy Research (@glxyresearch) September 7, 2026
In wave 3, the exploiter created 293 2-of-2 multisig vaults for each victim’s coins.
The first movements on 9/2 sent coins over THORChain to Ethereum.
Tonight’s movements are going into coinjoins rounds. pic.twitter.com/H7HIpcI7ah
The perpetrator moved Bitcoin to Ethereum through THORChain on September 2. Recent transactions involved moving Bitcoin via CoinJoin rounds. CoinJoin is a process whereby payments from different users are included in a transaction. This makes it more difficult to track transactions of individual fund transfers on the Bitcoin blockchain. It now provides researchers with insight into how the attacker operates the stolen funds.
Two-of-Two Multisignature Vaults Indicate Attack Plan
According to Galaxy, the third-wave attacker opened 293 multisignature two-of-two vaults. These were vaults with Bitcoin stolen from Coldcard victims. So far, the funds have been transferred from the biggest vaults in decreasing order of their sizes. According to Galaxy, funds from the 11 biggest vaults have already been transferred.
This information allowed researchers to track down some of the transactions linked to the exploit. They managed to find an unknown multisignature vault, which had most probably been used for transferring stolen Bitcoins from another victim. However, Galaxy was unable to determine the circumstances of this new theft. It means that the extent of the attack has expanded, but no new confirmed loss is known yet.
Bulk of the Stolen Bitcoin is Yet Unmoved
Even with all of the recent activities, the bulk of the Bitcoin stolen in all Coldcard attack waves remains in the initial attack-controlled addresses. According to Galaxy, 82% of Bitcoin stolen in all Coldcard attacks still lies in those addresses. The remaining 18% has since been transferred in transactions indicative of laundering.
The third wave is, therefore, a big portion of the active fund movement activity. It provides investigators with yet another pattern of transactions for monitoring. The Coldcard exploit is one of the biggest cryptocurrency exploits documented within the year 2026. According to DefiLlama, it is the third-biggest exploit of the year with reported losses. The Kelp DAO hack is ranked first with reported losses of approximately $293 million. In second place is the Drift Protocol exploit, which incurred about $280 million in losses.
This particular exploit reveals how stolen cryptocurrency can be moved through various blockchain ecosystems like THORChain and CoinJoin. The transactions present yet another piece of evidence for investigators and market players to track down.
Highlighted Crypto News:
South Korea’s Hanwha Advances Tokenized Securities With Avalanche Platform as Regulations Evolve
