BNB $745.68 -1.59%
XRP $1.40 -1.37%
ETH $2,493.15 -0.41%
BTC $79,510.13 -0.59%
BNB $745.68 -1.59%
XRP $1.40 -1.37%
ETH $2,493.15 -0.41%
BTC $79,510.13 -0.59%
BREAKING
Bitcoin News

Coldcard Hacker Moves 97 Bitcoin in $7.7M THORChain and CoinJoin Scheme

Coldcard Hacker Sweeps 97 Bitcoin Across CoinJoin and THORChain in $7.7M Move
Coldcard Hacker Sweeps 97 Bitcoin Across CoinJoin and THORChain in $7.7M Move

Community Trust ScoreVerified

83%
Real
Verified41 votes
Updated 2 hours ago

The attacker behind the Coldcard hardware wallet thefts is moving fast. On September 2, the hacker started shifting funds — 97.09 BTC in total, worth roughly $7.7 million — which amounts to nearly half of what was taken in the third wave of the exploit. Galaxy Research caught it.

The mechanics of the move are worth breaking down. It didn’t happen in one clean transfer. The hacker first pulled approximately 20.5 BTC from the largest vault and routed it through THORChain, converting it into Ethereum. After that, the remaining funds went into CoinJoin rounds — a Bitcoin privacy technique that pools transactions together and scrambles the trail, making it much harder to trace individual coins back to their origin. Of the 97.09 BTC that moved, only 20.56 BTC actually made it to Ethereum. Another 57.24 BTC sits unspent as CoinJoin change output. And the trail on nearly 19 BTC? Unclear. Galaxy hasn’t pinned it down yet.

So not all of it’s gone. Not even close.

Advertisement

How the Hacker Built 293 Multisig Vaults

What makes this exploit unusual isn’t just the scale — it’s the architecture. The attacker built 293 two-of-two multisig vaults, each one set up to drain a specific victim’s coins. It’s methodical. Systematic. Whoever is behind this clearly planned well ahead of the actual theft.

Right now, eleven of those vaults are fully drained. The next ten on the list hold a combined 30.81 BTC. The 233 smallest vaults collectively sit at 33.77 BTC. The hacker seems to be working through them in order of size — biggest first, smallest last. That pattern probably tells us something about how they’re managing risk and timing, though no one’s confirmed that read publicly.

The exploitations started on July 30.

The Firmware Bug That Started Everything

Go back to March 2021. That’s when Coinkite, the company behind Coldcard, shipped a firmware update that introduced a critical bug. The flaw rerouted seed generation away from the hardware’s dedicated random-number chip and handed that job to a software alternative instead. That’s a big downgrade. The hardware chip exists precisely because software randomness is weaker and more predictable. With that change in place, an attacker who knew about the bug could reconstruct private keys offline — no physical access to the wallet required.

Coinkite has since pushed out updated firmware. The new version forces users to add their own randomness through physical actions during setup, which basically patches the weak point in seed generation. But — and this is the hard part — the update can’t fix seeds that were already generated under the flawed version. Those seeds are compromised. Full stop. Anyone who set up a Coldcard wallet during the affected period needs to generate a brand new seed and move their funds to a fresh wallet. There’s no workaround.

Coinkite’s CEO, Rodolfo Novak, issued an apology and said the company is committed to restoring user trust. A full technical postmortem is still pending. No timeline given.

A Possible Fourth Wave and $143.9M at Stake

Galaxy Research found something else while tracking all of this — a previously unknown vault tied to 58 addresses that looks like it belongs to another Coldcard victim. If that’s confirmed, the total exploit value climbs to around 1,806 BTC, or approximately $143.9 million at current prices.

And it could go higher. Back in August, Galaxy flagged a potential fourth wave involving 638.5 BTC. If that materializes, the cumulative total would push past 2,400 BTC. That’s a staggering number. But here’s the thing — 82% of the coins across all identified vaults haven’t moved yet. They’re still sitting at their original addresses.

That’s either patience or caution. Maybe both.

The hacker’s use of CoinJoin and THORChain together is worth noting on its own. CoinJoin obscures on-chain trails within Bitcoin. THORChain lets you bridge across to Ethereum without a centralized exchange — no KYC, no account freeze risk. Combining the two is a pretty effective way to layer transactions and reduce traceability. It’s not foolproof, and blockchain analytics firms have gotten better at unwinding CoinJoin outputs, but it adds friction to any investigation.

For hardware wallet users broadly, the Coldcard situation is a rough reminder that firmware updates — the kind that seem routine — can carry serious consequences when they go wrong. The attack surface here wasn’t a phishing link or a weak password. It was a quiet change to how randomness gets generated during wallet setup, buried in code, unnoticed for years.

Coinkite’s technical postmortem is still outstanding. Affected users are still waiting on answers. And the hacker still has the majority of the stolen funds sitting untouched.

Galaxy Research keeps watching. The 233 smallest vaults — 33.77 BTC combined — haven’t been touched yet.

Frequently Asked Questions

What firmware bug caused the Coldcard wallet exploit?

A bug introduced in March 2021 rerouted seed generation from Coldcard’s hardware random-number chip to a weaker software alternative, letting attackers reconstruct private keys offline without physical access to the device.

How much Bitcoin has the Coldcard hacker moved so far?

The attacker moved 97.09 BTC — worth roughly $7.7 million — with 20.56 BTC converted to Ethereum via THORChain, 57.24 BTC sitting as CoinJoin change, and the trail on nearly 19 BTC still uncertain, per Galaxy Research.

Why It Matters

This significant movement of stolen Bitcoin highlights ongoing vulnerabilities in the crypto security landscape, particularly concerning hardware wallets like Coldcard. The use of CoinJoin and THORChain for laundering funds showcases the sophisticated methods employed by hackers to obfuscate their activities, raising concerns about the effectiveness of current tracking and recovery efforts. As such incidents continue to unfold, they underscore the critical need for enhanced security measures and user awareness within the crypto ecosystem.

Community Trust IndexHigh Confidence
83%
Real
Real83%17%Fake
41 community signals

James Thorp

James Thorp is a passionate crypto journalist from South Africa specializing in Litecoin, Dash, and emerging digital assets. With years of experience covering the crypto markets, James delivers in-depth analysis and breaking news on altcoins, blockchain adoption, and decentralized payment networks for The Currency Analytics.

Advertisement

Related Stories