Coldcard Third-Wave Attacker Moves 45% of Stolen Bitcoin

The exploiter behind the third wave of the Coldcard wallet hack has moved approximately 45% of their stolen Bitcoin (BTC) by routing funds through THORChain and CoinJoin transactions, according to Galaxy Research. Since September 2, 2026, the attacker has been transferring coins from two-of-two multisignature vaults established to hold victims’ assets, systematically laundering them through privacy-enhancing and cross-chain services. Galaxy also discovered an unknown vault likely containing another victim’s funds. This breach ranks among the three largest crypto exploits in 2026.
Details on Stolen Bitcoin Movements
Galaxy Research reported that the attacker started moving stolen Bitcoin into Ethereum network via the cross-chain protocol THORChain on September 2, 2026. Recently, the thief has been funneling funds into CoinJoin transactions, which mix multiple users’ payments into one to enhance privacy and complicate tracing.
The attacker created 293 two-of-two multisignature vaults to store victims’ coins. Funds from the largest of these vaults have been moved sequentially from largest to smallest, with the assets from the top 11 vaults already relocated.
Galaxy also identified a previously unknown vault likely holding funds from another Coldcard victim, though the origin and details remain unconfirmed.
Magnitude and Statistics of the Hack
Galaxy Research estimates that across all waves of the Coldcard exploit, roughly 82% of the stolen Bitcoin still resides in original attacker-controlled addresses, while about 18% has been moved possibly for laundering.
According to DefiLlama rankings, the Coldcard breach is the third-largest crypto hack of 2026, surpassed only by the $293 million Kelp DAO incident and the $280 million Drift protocol breach.
Why it matters
This news highlights how attackers use sophisticated mechanisms and privacy-enhancing services like THORChain and CoinJoin to launder significant amounts of stolen cryptocurrencies. Ranked as the third-largest hack in 2026, it underscores ongoing security risks to multisignature wallets and the critical need for stronger protection measures. Moreover, uncovering previously unknown victim vaults sheds light on the extent and duration of the breach, aiding investigations and raising user awareness about potential vulnerabilities.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗