Coldcard third-wave attacker moves 45% of stolen Bitcoin
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
The attacker responsible for the third wave of the Coldcard wallet hack has moved about 45% of their stolen Bitcoin. They routed the funds through THORChain and CoinJoin transactions to obscure the trail, according to Galaxy Research. The exploiter used multiple two-of-two multisignature vaults to hold victims' coins and has moved funds from the largest vaults first.
Why it matters
The source highlights that the movement of stolen Bitcoin through mixing services like THORChain and CoinJoin complicates tracking and potential recovery efforts. The ongoing laundering efforts indicate active attempts by the exploiter to obfuscate the stolen funds. The hack ranks as one of the largest exploits of 2026 to date.
Key context
Galaxy Research reported that the exploiter started moving funds to Ethereum via THORChain on September 2 and then into CoinJoin rounds. The attacker created 293 multisignature vaults to store victims' Bitcoin. Approximately 82% of the stolen Bitcoin remains in attacker-controlled addresses, with 18% moved for laundering. The Coldcard exploit is the third-largest hack in 2026 behind Kelp DAO and Drift protocol incidents.
Key numbers and entities
The exploiter moved coins from 11 largest vaults. There are 293 two-of-two multisignature vaults involved. The Coldcard hack is the third-largest of 2026, following a $293 million hack at Kelp DAO and a $280 million Drift protocol hack. Galaxy Research and DefiLlama provided data mentioned.
What remains unclear
The exact cause of the Coldcard wallet exploit is not confirmed. The nature and identity of the previously unknown vault and its victim remain uncertain. Further details about the exploiter’s methods or identity are not disclosed.