Coldcard Hacker Moves 45% of Stolen Bitcoin Through THORChain and CoinJoin
The attacker behind the third wave of the Coldcard hardware wallet exploit has moved approximately 45% of their stolen Bitcoin, routing the funds through THORChain or into CoinJoin mixing transactions to obscure their origin, according to research from Galaxy. Starting Sept. 2, the exploiter began converting Bitcoin to Ethereum via THORChain, a cross-chain liquidity protocol, before later shifting to CoinJoin rounds that combine multiple users' payments into single transactions to complicate blockchain analysis.
Galaxy Research reported on Monday that the third-wave exploiter had created 293 two-of-two multisignature vaults to hold victims' coins, systematically draining funds from the largest vaults in descending order of size. The 11 largest vaults have now been emptied. These transactions also helped Galaxy identify a previously unknown vault likely holding funds from another Coldcard victim, though the circumstances behind that loss remain unconfirmed.
Across all waves of the Coldcard exploit, roughly 82% of the stolen Bitcoin remains in the original attacker-controlled addresses, while 18% has been moved for apparent laundering, Galaxy noted. According to DefiLlama, the Coldcard exploit ranks as the third-largest crypto exploit of 2026, behind a $293 million Kelp DAO hack and the $280 million Drift protocol hack. The incident underscores ongoing security concerns in the hardware wallet sector, coming just days after Trezor disclosed a separate data breach affecting an additional 67,000 US customers.
Read Full Article at CoinTelegraph →