
Galaxy Research reports the exploiter is utilizing THORChain and CoinJoin to launder funds from the third wave of attacks.
AI-generated summary
The Coldcard exploit is the third-largest of 2026, following the Kelp DAO and Drift protocol hacks. The attacker has created 293 multisignature vaults to manage stolen funds.
The exploiter behind the third wave of the Coldcard wallet hack has moved about 45% of their Bitcoin (BTC) haul, routing the funds through THORChain or into CoinJoin transactions, according to Galaxy Research.
In a Monday update, Galaxy said the exploiter began moving funds to Ethereum through THORChain on Sept. 2. The latest movements sent Bitcoin into CoinJoin rounds, which combine multiple usersā payments into a single transaction to make funds harder to trace.
Galaxy said the third-wave exploiter had created 293 two-of-two multisignature vaults to hold victimsā coins and was moving funds from the largest vaults in descending order of size. Funds from the 11 largest vaults have now been moved.
The transactions helped Galaxy identify a previously unknown vault that it said likely held another Coldcard victimās funds, although the cause of that loss remained unconfirmed.
Across all waves of the Coldcard exploit, approximately 82% of the stolen Bitcoin remains in the original attacker-controlled addresses, while 18% has moved, apparently for laundering purposes, Galaxy said.
The Coldcard exploit ranks as the third-largest exploit so far in 2026, behind a $293 million Kelp DAO hack and the $280 million Drift protocol hack, according to DefiLlama.

A FinCEN analysis identified $12.7 billion in cryptocurrency transactions tied to overseas scam centers, based on over 33,000 reports from September 2023 to December 2025. The scams included pig butchering, romance schemes, and fake crypto investment offers. Officials noted the operations are largely run by transnational criminal groups in Southeast Asia, with Myanmar and Cambodia pursuing legislation to criminalize such centers.

The United States and United Kingdom have formed a joint law enforcement alliance targeting scam centers involved in crypto and cyber-enabled investment fraud. The agreement, signed by the US Attorneyās Office for the District of Columbia, the Crown Prosecution Service of England and Wales, and the UK National Crime Agency, enables parallel investigations, information sharing, and coordinated prosecutions. It expands the Scam Center Strike Force launched in November 2025 and builds on prior international operations, including a Dubai-led raid that resulted in 276 arrests. The initiative responds to rising US losses from crypto investment fraud, which reached $8.65 billion in 2025.

The FBI seized Hamas-linked fundraising infrastructure and used it to intercept cryptocurrency donations intended for the group, building on earlier court-authorized seizures that recovered over $560,000 in digital assets. The operation involved working with Tether and Binance to redirect funds and leveraged seized domains and servers to trace and disrupt donations, turning a retrospective tracing effort into an active disruption operation.

Ukraine's National Police and Security Service dismantled a criminal network operating fake crypto investment platforms. The group, led by a 25-year-old IT specialist in Kyiv, defrauded victims in over 20 countries, stealing up to $1 million per month.

The FBI seized approximately $560,000 in cryptocurrency and took control of online infrastructure allegedly used by Hamas to collect donations, according to a Justice Department announcement. The funds were traced to wallets and accounts linked to Hamas' military wing, the Al Qassam Brigades, under warrants issued in March, June, and October 2025. Authorities stated the operation disrupts terrorist financing through digital networks and serves as a warning that cryptocurrency cannot shield illicit fundraising from law enforcement.

Britain's National Crime Agency has frozen over $13.6 million in a Barclays account held by the Premier League, received as the first payment from Sorare under a four-year sponsorship deal. The freeze, obtained under the Proceeds of Crime Act, aims to prevent dissipation while investigating potential links to third-party criminality. Sorare denies wrongdoing and states the funds are not in its account, while facing separate prosecution by the UK Gambling Commission over alleged unlicensed gambling activities.