Coldcard Hacker Moves $7.7M Bitcoin, 45% of Wave 3 Theft

Key Points
- On September 2-3, 2026, the Coldcard attacker moved 97.09 BTC worth approximately $7.7 million from Wave 3 vaults.
- The hacker created 293 separate two-of-two multisig vaults and has emptied 11 of them, working through them by size largest first.
- Across all Coldcard exploit waves, 82% of the stolen Bitcoin remains unmoved as of September 7, 2026.
Firmware Flaw Behind Massive Breach
The thefts stem from a firmware bug Coinkite introduced in March 2021 that rerouted seed generation away from the device's hardware random-number chip to a software substitute, collapsing cryptographic key strength from 128 bits of entropy to as low as 40 bits. This vulnerability enabled attackers to reconstruct private keys offline and drain single-signature addresses without ever physically accessing the hardware. Sweeps began on July 30.
Read Next

Treasury Yields Face 4.8% Test as Fiscal Deficits Threaten Markets
12 hours ago

OpenAI GPT-6 Astra Launches at $10 per Million Tokens
20 hours ago
Coinkite has since overhauled its firmware in versions Mk4/Mk5 5.6.2 and Q 1.5.2Q, requiring owners to supply their own randomness through key presses, dice rolls, or coin flips. However, no firmware update can repair seeds generated under the flawed version. Anyone whose wallet was created on affected firmware must generate a fresh seed and transfer coins to it. Coinkite CEO Rodolfo Novak issued an apology in an open letter on July 31, stating the company would have to "earn back our users' trust." A full technical postmortem remains in preparation.
Galaxy Research's published total for the exploit stands at approximately 1,806 BTC, or $143.9 million. The firm also flagged an unconfirmed fourth wave containing 638.5 BTC in August, which would lift the total past 2,400 BTC. No attacker sweeps have been logged since August 6.
Related coverage: Treasury Yields Face 4.8% Test as Fiscal Deficits Threaten Markets
Across all Coldcard exploit waves, 82% of the stolen Bitcoin has not yet moved. At the current movement rate of 97.09 BTC over approximately one month, the attacker would move the remaining 45% of Wave 3 holdings—approximately 120 BTC—within three to four months, assuming consistent monthly withdrawals. This suggests the attacker may be prioritizing conversion to alternative assets through privacy-mixing services to complicate forensic tracing by blockchain analysts and law enforcement.
Related Guide: Read our complete guide →
Market Outlook
The attacker's methodical emptying of vaults by size, combined with consistent use of privacy protocols, suggests the perpetrator intends to fully liquidate stolen holdings rather than hold Bitcoin long-term. If Galaxy's unconfirmed fourth wave proves legitimate, total losses exceed $185 million. Expect continued pressure on CoinJoin and THORChain services to implement stricter controls on flagged transaction patterns.
Sources: Decrypt and other international news outlets.
Disclaimer: This article was produced with AI assistance based on publicly available news sources. While we strive for accuracy, NewsOracle makes no warranty as to the completeness or accuracy of the information. Errors and omissions may occur. Readers should independently verify all information before acting on it. NewsOracle does not intend to defame any individual or organisation and accepts no liability for any loss or damage arising from reliance on this content. Content is for informational purposes only and does not constitute legal, financial, medical, or professional advice. All rights reserved. Unauthorised reproduction prohibited.
NewsOracle Editorial
The NewsOracle Markets Desk covers stock markets, cryptocurrency, economic policy and breaking financial news from Wall Street and global exchanges.
Latest coverage: Bitcoin


