Coldcard thief moves nearly half of 'Wave 3' bitcoin as total losses near 1,806 BTC
Galaxy Research says the attacker behind the Coldcard hardware-wallet thefts has moved 45% of the bitcoin taken in the "Wave 3" round, with total losses now put at roughly 1,806 BTC (~$143.9 million).
The attacker draining Coldcard bitcoin hardware wallets has shifted 45% of the funds stolen in the third wave of the campaign, Galaxy Research said in posts on X reported by The Block on Sept. 7. Galaxy tracks the money moving in size order — largest first — with ranks 1 through 11 already relocated. The next 10 untouched vaults hold 30.81 BTC, and the smaller vaults ranked 61 to 293 hold a combined 33.77 BTC.
The thefts trace to a firmware bug Coinkite shipped in 2021, according to Galaxy. The flaw weakened the randomness Coldcard devices used to generate wallet seeds, letting an attacker brute-force the seed phrases and drain single-signature addresses without ever touching the physical device. The first thefts landed on July 30.
By mid-August, Galaxy said it had identified roughly 1,779 BTC taken from 190 victims across more than 8,600 addresses. In Monday's update, Galaxy said the exploiter "co-spent" a previously unknown vault of 58 addresses it believes belong to Coldcard victims — pushing the running total to 1,806 BTC, which Galaxy valued at about $143.9 million at current prices. Across the whole campaign, Galaxy said 82% of the exploited coins still sit in the original attacker-controlled addresses; the remainder has been moved, it said, for laundering. The firm floated a possible "Wave 4" but has not confirmed one.
Key facts
- 45% of Wave 3 funds moved; ranks 1–11 relocated, largest first — Galaxy Research (via The Block, Sept. 7).
- Untouched: 30.81 BTC across the next 10 vaults; 33.77 BTC across ranks 61–293 — Galaxy.
- Mid-August tally: ~1,779 BTC from 190 victims, 8,600+ addresses — Galaxy.
- Newly co-spent 58-address vault lifts total to 1,806 BTC (~$143.9M) — Galaxy.
- 82% of exploited coins remain in original attacker addresses — Galaxy.
- Root cause: 2021 Coinkite firmware bug reducing seed randomness; thefts began July 30 — Galaxy.
The real-world read
Nearly every hard number here rests on a single interested-adjacent source: Galaxy Research's own on-chain attribution, relayed secondhand. Galaxy is a reputable analyst, not a party to the theft, but no independent confirmation of the victim count, the BTC totals, or the "co-spent" 58-address vault appears alongside it — and the dollar figure moves with the price. The 45% and 82% figures describe different things (Wave 3 versus the whole campaign) and shouldn't be conflated. Two items remain explicitly unconfirmed by Galaxy itself: whether the extra 58 addresses are truly victims, and whether a Wave 4 exists. Note also what's conspicuous: the flaw was a vendor firmware bug from 2021 that only now shows up as mass theft — the mechanics of how it went unnoticed for four years aren't spelled out here, and Coinkite's own account isn't part of this record.
Not financial advice.
Sources
- The Block — reporting Galaxy Research's Sept. 7 X posts on Wave 3 movement, vault balances, the mid-August tally, and the 1,806 BTC / $143.9M total. Reputable secondary source; the underlying figures are Galaxy's on-chain estimates, not independently verified here.