Galaxy Research identified that the exploiter behind the third wave of the Coldcard hardware‑wallet breach has transferred roughly 45% of the stolen Bitcoin. The movement began on Sept. 2, when the attacker sent Bitcoin to Ethereum using the THORChain cross‑chain bridge.
Subsequent transactions placed the Bitcoin into CoinJoin mixes, a technique that aggregates multiple users' payments into a single transaction to obscure the flow of funds. Galaxy said the attacker created 293 two‑of‑two multisignature vaults to store victims' coins and has been emptying the largest vaults in descending order of size. Funds from the 11 biggest vaults have now been moved.
The analysis also uncovered a previously unknown vault that likely contains assets from another Coldcard victim, though the source of that loss remains unconfirmed. Across all three waves of the Coldcard exploit, about 82% of the stolen Bitcoin remains in the original attacker‑controlled addresses, while the remaining 18% has been moved, apparently for laundering purposes.
DefiLlama ranks the Coldcard incident as the third‑largest crypto exploit of 2026, trailing a $293 million hack of the Kelp DAO and a $280 million breach of the Drift protocol. The ongoing tracing effort highlights the challenges of following illicit crypto flows, even when sophisticated mixing services and cross‑chain bridges are employed.













