Attacker moves 97.09 BTC from Coldcard vaults via THORChain and CoinJoin
Quick Look
- Galaxy Research reported that 97.09 BTC worth about $7.7 million was moved from Wave 3 vaults linked to the Coldcard exploit, with funds routed through THORChain on September 2 and into CoinJoin rounds over the weekend.
- Across the entire Coldcard exploit, 82% of stolen Bitcoin remains unmoved.
- The thefts stem from a 2021 firmware flaw in Coinkite devices that weakened seed generation, allowing offline key reconstruction.
AI-generated summary
Why It Matters
The Coldcard exploit traces to a firmware bug introduced by Coinkite in March 2021 that rerouted seed generation from the device's hardware random-number chip to a software stand-in, reducing entropy from 128 bits to as low as 40 bits. This allowed attackers to reconstruct private keys offline and drain funds without physical access to the hardware. Sweeps began on July 30.
In brief
Galaxy Research said Monday that 97.09 BTC, worth about $7.7 million, has left the Wave 3 vaults.
The coins went out through THORChain on September 2 and into CoinJoin rounds over the weekend.
Across the whole Coldcard exploit, 82% of the stolen Bitcoin has still not moved.
The attacker behind the third wave of thefts from Coldcard hardware wallets has moved 97.09 BTC, roughly 45% of that wave's haul and about $7.7 million at Monday's prices, according to Galaxy Research.
The first exit came on September 2, when around 20.5 BTC from the largest vault went through THORChain and came out as Ethereum. The coins spent on Sunday night went into CoinJoin rounds instead, a Bitcoin privacy technique that pools transactions from multiple users to break the trail between inputs and outputs. Only 20.56 BTC actually reached Ethereum. Another 57.24 BTC is sitting unspent as CoinJoin change in a single address, and Galaxy says its trail ends on roughly 19 BTC more.
The vaults are the attacker's own construction. Galaxy said the operator built 293 two-of-two multisig addresses and has been working through them in order of size. Eleven are now empty. The next ten hold 30.81 BTC between them, and the 233 smallest hold 33.77 BTC.
A flaw shipped in 2021
The thefts trace to a firmware bug Coinkite introduced in March 2021, which rerouted seed generation off the device's hardware random-number chip and onto a software stand-in, collapsing key strength from 128 bits of entropy to as low as 40. That let attackers reconstruct private keys offline and drain single-signature addresses without ever touching the hardware. The sweeps began on July 30.
Coinkite has overhauled the firmware, now at Mk4/Mk5 5.6.2 and Q 1.5.2Q, requiring owners to supply their own randomness through key presses, dice rolls or coin flips. An update still cannot repair a seed generated under the flawed version, and anyone whose wallet was created on affected firmware has to generate a fresh seed and move their coins to it. Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31, writing that the company would have to "earn back our users' trust." A full technical postmortem is still in preparation.
What to Watch
AI outlook — possibilities, not facts
More Bitcoin from the Coldcard exploit will be moved in the coming weeks as the attacker continues working through the vaults.
Likely · Within weeks
Coinkite will release a full technical postmortem on the firmware flaw in the near future.
Likely · Within weeks
Open Questions
- Will the remaining unmoved Bitcoin from the Coldcard exploit ever be spent?
- How many users were affected by the flawed firmware?
- Has Coinkite compensated users impacted by the seed generation flaw?
- Are there any ongoing legal or regulatory actions against Coinkite related to the firmware defect?







