cleartext

Independent, sourced crypto news. No paid placements.

bitcoin

Coldcard thief moves nearly half of 'Wave 3' bitcoin as total losses near 1,806 BTC

Galaxy Research says the attacker behind the Coldcard hardware-wallet thefts has moved 45% of the bitcoin taken in the "Wave 3" round, with total losses now put at roughly 1,806 BTC (~$143.9 million).

The attacker draining Coldcard bitcoin hardware wallets has shifted 45% of the funds stolen in the third wave of the campaign, Galaxy Research said in posts on X reported by The Block on Sept. 7. Galaxy tracks the money moving in size order — largest first — with ranks 1 through 11 already relocated. The next 10 untouched vaults hold 30.81 BTC, and the smaller vaults ranked 61 to 293 hold a combined 33.77 BTC.

The thefts trace to a firmware bug Coinkite shipped in 2021, according to Galaxy. The flaw weakened the randomness Coldcard devices used to generate wallet seeds, letting an attacker brute-force the seed phrases and drain single-signature addresses without ever touching the physical device. The first thefts landed on July 30.

By mid-August, Galaxy said it had identified roughly 1,779 BTC taken from 190 victims across more than 8,600 addresses. In Monday's update, Galaxy said the exploiter "co-spent" a previously unknown vault of 58 addresses it believes belong to Coldcard victims — pushing the running total to 1,806 BTC, which Galaxy valued at about $143.9 million at current prices. Across the whole campaign, Galaxy said 82% of the exploited coins still sit in the original attacker-controlled addresses; the remainder has been moved, it said, for laundering. The firm floated a possible "Wave 4" but has not confirmed one.

Key facts

  • 45% of Wave 3 funds moved; ranks 1–11 relocated, largest first — Galaxy Research (via The Block, Sept. 7).
  • Untouched: 30.81 BTC across the next 10 vaults; 33.77 BTC across ranks 61–293 — Galaxy.
  • Mid-August tally: ~1,779 BTC from 190 victims, 8,600+ addresses — Galaxy.
  • Newly co-spent 58-address vault lifts total to 1,806 BTC (~$143.9M) — Galaxy.
  • 82% of exploited coins remain in original attacker addresses — Galaxy.
  • Root cause: 2021 Coinkite firmware bug reducing seed randomness; thefts began July 30 — Galaxy.

The real-world read

Nearly every hard number here rests on a single interested-adjacent source: Galaxy Research's own on-chain attribution, relayed secondhand. Galaxy is a reputable analyst, not a party to the theft, but no independent confirmation of the victim count, the BTC totals, or the "co-spent" 58-address vault appears alongside it — and the dollar figure moves with the price. The 45% and 82% figures describe different things (Wave 3 versus the whole campaign) and shouldn't be conflated. Two items remain explicitly unconfirmed by Galaxy itself: whether the extra 58 addresses are truly victims, and whether a Wave 4 exists. Note also what's conspicuous: the flaw was a vendor firmware bug from 2021 that only now shows up as mass theft — the mechanics of how it went unnoticed for four years aren't spelled out here, and Coinkite's own account isn't part of this record.

Not financial advice.

Sources

  • The Block — reporting Galaxy Research's Sept. 7 X posts on Wave 3 movement, vault balances, the mid-August tally, and the 1,806 BTC / $143.9M total. Reputable secondary source; the underlying figures are Galaxy's on-chain estimates, not independently verified here.