• The Coldcard Hacker Isn’t Rushing – And That Should Worry Self-Custody Users More Than a Fast Cash-Out Would
  • The Slow Death of “Risk-Free”: Why Wall Street’s Bitcoin Bulls Have Stopped Talking About Price
  • The Real Deadline Isn’t September 15. It’s the Calendar Itself.
  • When “White Hat” Meets $320 Million: What the Liquid Network Drain Really Tells Us About Bitcoin’s Bridge Problem
  • El Salvador’s President Denies Report That Country’s Bitcoin Reserve Was Handed to a Private Operator
2026-09-07
Coins by Cryptorank
Bitcoinworld Bitcoinworld
Bitcoinworld Bitcoinworld
  • Crypto News
  • Exclusive Article
  • Reviews
  • Sponsored
  • Press Release
  • Events
  • Advertisement
  • More
    • About Us
    • Learn
    • Contact Us
    • Privacy Policy
Bitcoinworld
  • Crypto News
  • Exclusive Article
  • Reviews
  • Sponsored
  • Press Release
  • Events
  • Advertisement
  • More
    • About Us
    • Learn
    • Contact Us
    • Privacy Policy
Skip to content
Home Crypto News The Coldcard Hacker Isn’t Rushing – And That Should Worry Self-Custody Users More Than a Fast Cash-Out Would
Crypto News

The Coldcard Hacker Isn’t Rushing – And That Should Worry Self-Custody Users More Than a Fast Cash-Out Would

  • by Keshav Aggarwal
  • 2026-09-07
  • 0 Comments
  • 7 minutes read
  • 1 View
  • 19 seconds ago
Facebook Twitter Pinterest Whatsapp
The Coldcard Hacker Isn't Rushing

There’s an instinct, when a stolen-crypto story updates with new laundering numbers, to read it as a countdown: the thief is cashing out, the clock is ticking, soon it’ll all be gone. The latest update on the Coldcard hardware wallet exploit deserves the opposite read. Eighteen percent moved, 82% still sitting untouched in the attacker’s own addresses, months after the theft was first identified – that’s not the behavior of someone in a hurry. It’s the behavior of someone who either doesn’t need to rush, or is being deliberately careful not to trip the wires that would get the rest of the funds frozen or traced.

Either way, the patience on display here is arguably more informative than the dollar figures, and it says something uncomfortable about where this case is heading.

 

A Quick Recap of How We Got Here

For anyone who hasn’t followed this since the summer, the Coldcard exploit isn’t a single hack – it’s a slow-motion, multi-wave campaign that blockchain research firm Galaxy Research has been tracking and re-sizing upward for months. The vulnerability traces back to a firmware flaw in Coldcard hardware wallets dating to March 2021, which allowed an attacker (or attackers) to predict or reconstruct private keys for addresses the affected devices had generated. Galaxy’s head of research, Alex Thorn, has been blunt about the implications from the start: every single-sig Coldcard address created after that firmware flaw was introduced is eventually drainable, whether or not the owner has touched the wallet since.

The numbers grew in distinct jumps as Galaxy uncovered each new wave. The first wave put losses in the range of $75 million. A second wave, identified in early August, pushed the total to roughly 1,158 BTC across thousands of addresses. A third wave added hundreds more BTC and introduced a structural wrinkle: rather than sweeping funds into simple wallets, this attacker began organizing stolen coins into 293 – now 294, with the newly identified vault – separate 2-of-2 multisig vaults. That detail matters more than it might seem.

 

Why Multisig Vaults Change the Laundering Calculus

A simple wallet holding stolen funds is one thing to trace and, in theory, one thing for exchanges or compliance tools to flag once addresses get blacklisted. Splitting the loot across nearly 300 individually structured 2-of-2 multisig vaults is a fundamentally different operational choice. It fragments the total exposure, makes automated address-flagging systems work much harder, and – crucially – requires two keys to move any given vault’s funds, which suggests either an attacker working with an accomplice, a deliberate operational security measure to prevent a single point of failure (a stolen or seized key can’t move funds alone), or some combination of both.

This isn’t the fingerprint of an opportunistic script-kiddie who got lucky with a leaked vulnerability. Setting up nearly 300 discrete multisig structures, each requiring coordinated signing, is meaningful operational overhead. Someone invested real effort into making this theft resistant to exactly the kind of on-chain forensic mapping that firms like Galaxy Research specialize in.

 

The Laundering Pattern Itself Is the Story

Of the roughly 18% that has moved, Galaxy’s data points to two primary exit routes: THORChain, a cross-chain liquidity protocol that lets holders swap Bitcoin directly for Ethereum-based assets without touching a centralized exchange, and CoinJoin, a Bitcoin-native privacy technique that pools multiple users’ transactions together to obscure which inputs correspond to which outputs.

Both tools exist for entirely legitimate reasons – THORChain is a genuine piece of decentralized cross-chain infrastructure, and CoinJoin has long been championed by Bitcoin privacy advocates as a way for ordinary users to protect their financial privacy against surveillance, not just a laundering vehicle. But in the hands of someone moving stolen funds, they serve a specific and well-understood purpose: breaking the traceable chain that ties Bitcoin sitting in an attacker’s wallet to Bitcoin sitting somewhere that can eventually be converted to spendable value, ideally in a jurisdiction or through a service that won’t ask hard questions.

The choice to route through Ethereum via THORChain rather than staying entirely within Bitcoin is itself notable. Cross-chain swaps break the single-chain forensic trail that Bitcoin’s fully public ledger otherwise makes relatively easy to follow, forcing investigators to essentially restart their tracing effort on an entirely different blockchain with different tooling and different mixing services available. It’s a strategy that trades some speed and efficiency for a meaningfully harder trace – again, consistent with an actor optimizing for staying unlinked rather than for cashing out quickly.

 

Why 82% Is Still Sitting There

The more interesting question might be why the large majority of the stolen funds haven’t moved at all. A few explanations are plausible, and they’re not mutually exclusive. The attacker may be laundering in deliberately small, spaced-out tranches specifically to avoid the kind of sudden, large on-chain movement that draws immediate scrutiny from firms like Galaxy, Chainalysis, or exchange compliance teams – a slow drip is much harder to build a public narrative around than a dramatic dump. It’s also possible that the operational friction of coordinating multisig signing across nearly 300 separate vaults, potentially requiring cooperation between multiple parties holding different keys, genuinely slows the process down. And there’s a simpler possibility worth not dismissing: with this much public attention and this much money at stake, patience itself might be the strategy – waiting for scrutiny to fade before moving the bulk of the funds.

Whatever the reason, Galaxy’s continued public tracking – and its stated practice of sharing suspected attacker addresses with law enforcement, compliance firms, and cross-industry investigators – means the attacker is operating under active surveillance, not obscurity. That the laundering has continued anyway, however cautiously, tells you the attacker is betting that fragmentation and cross-chain movement will eventually outpace the trackers, not that the trackers don’t exist.

 

The Part That Should Actually Change User Behavior

It’s worth stepping back from the laundering mechanics to the more consequential fact underneath all of it: this exploit is still generating new victim discoveries months after it was first identified. Galaxy’s identification of a newly linked vault this week, bringing the third-wave total to 294 vaults and the cumulative theft across all three waves to roughly 1,806 BTC, means the full scope of this campaign still isn’t fully mapped. That’s a genuinely unusual situation for a vulnerability this old and this publicly disclosed to still be producing fresh casualties.

The practical takeaway for Coldcard users hasn’t changed since researchers first raised the alarm, and it bears repeating precisely because the ongoing news cycle can create a false sense that the danger has passed: any address generated by an affected device before the firmware fix remains a target, regardless of whether funds have moved recently or whether the owner has any reason to suspect compromise. Waiting to see whether your specific wallet gets targeted is not a strategy – the attacker’s own pace demonstrates that they’re working through victim wallets methodically, not randomly, and there’s no way to know where any given address sits in that sequence.

 

Future Implications

A few things are worth watching from here. First, whether the 82% still sitting untouched actually gets moved at a similar patient pace, or whether the attacker eventually accelerates once enough time has passed that public attention wanes – that will say a lot about whether the delay has been a deliberate strategy or simply operational friction. Second, whether the cross-chain trail through THORChain into Ethereum-based assets produces an actual identification, since moving into a different ecosystem doesn’t make funds untraceable, just harder to trace, and law enforcement agencies have had real success in past cases piecing together cross-chain movement given enough time and cooperation from involved protocols and exchanges.

Third, and probably most significant for the broader hardware wallet industry: this case is likely to accelerate scrutiny of how wallet manufacturers handle, disclose, and remediate firmware-level key generation flaws. A vulnerability that sat quietly for years before being exploited at scale, and that continues to affect users who have no way of independently verifying whether their own addresses are compromised, is the kind of failure mode that regulators and industry standards bodies tend to respond to with new disclosure requirements once the dust settles.

 

Conclusion

The headline number – 18% moved, 82% still parked – reads at first like a story about how much money is still recoverable, and to some degree it is. But the more important signal is the behavior underneath the numbers: a patient, structurally sophisticated attacker using multisig fragmentation and cross-chain swaps to methodically outlast the investigators tracking them, while new victims are still being identified months into the investigation. That combination – technical care on the laundering side and continued expansion on the victim side – is what should worry the self-custody community more than any single dollar figure. This isn’t a story that’s winding down. It’s one that’s still actively being written, on both sides of the ledger.

Disclaimer: The information provided is not trading advice, Bitcoinworld.co.in holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Related Reading

  • Hacker Spends $46.5M to Accumulate 21,659 ETH in 24 Hours, On-Chain Data Shows
  • Coldcard Patches Critical Seed-Generation Flaw After $112M Bitcoin Theft
  • Coldcard Hardware Wallet Flaw Went Undetected for Years, Resulting in $100M Bitcoin Theft
  • Coldcard Hack Losses Surpass 1,778 BTC as Galaxy Research Tracks Attack Flows
  • 233,000 BTC Moved From Long-Term Wallets After Coldcard Hack: Market Shifts $15 Billion in Bitcoin

Tags:

ColdcardHacker

Share This Post:

Facebook Twitter Pinterest Whatsapp
Avatar photo

Keshav Aggarwal

Co- Founder
Keshav Aggarwal is the Co-Founder & CEO of BitcoinWorld, a Google News - indexed publication covering crypto, AI, and forex markets since 2020. A blockchain investor and trader with over six years in the digital-asset space, he built one of India's most active crypto investor communities and has guided thousands of retail participants through their first investments in the asset class. At BitcoinWorld, he sets editorial direction across the newsroom and reports on the business of crypto, AI, and Web3 - tracking the funding rounds, product launches, and regulatory shifts shaping the future of finance and frontier technology.
Next Post

The Slow Death of “Risk-Free”: Why Wall Street’s Bitcoin Bulls Have Stopped Talking About Price

Categories

Crypto News

Bitcoin Treasury Ambition: The Blockchain Group Seeks Staggering €10 Billion

Events

33

Learn

Press Release

Reviews

Google NewsGoogle News TwitterTwitter LinkedinLinkedin coinmarketcapcoinmarketcap BinanceBinance YouTubeYouTubes

Copyright © 2026 BitcoinWorld | Powered by BitcoinWorld – By BitWorld Media INC