Coldcard Exploit: 45% of Wave 3 Bitcoin Loot Moved

The Coldcard exploit has entered a new phase, with attackers moving 45% of the Bitcoin stolen in Wave 3, according to Galaxy Research. About 97.09 BTC, worth roughly $7.7 million at the earlier reported price, was transferred over 48 hours. The funds were routed through THORChain into Ethereum and through CoinJoin transactions, potentially to obscure their origin. Wave 3 involved 293 two-of-two multisignature vaults. The 11 largest vaults have been emptied. The next 10 hold 30.81 BTC, while vaults ranked 61 to 293 contain a combined 33.77 BTC. Galaxy Research also identified an additional vault linked to 58 addresses believed to belong to Coldcard victims. Across all three attack waves, about 1,806 BTC, worth approximately $143.9 million at the reported price, has been stolen. Around 82% remains in attacker-controlled addresses, while 18% has moved. The Coldcard exploit began on 30 July 2026 and was linked to a firmware build error introduced by a March 2021 update. Affected MK3 wallets used a weak software random-number generator instead of their hardware-based source, reducing seed security from 128 bits to as little as 40 bits on older devices. Attackers could therefore brute-force private keys without physical access. Coinkite released patched firmware, but users must create new seed phrases and transfer funds because an update alone cannot secure compromised wallets. The incident increased Bitcoin address activity as users consolidated assets, but it has had little apparent effect on BTC’s price. BTC recently approached $82,000 and was trading near $79,500 in the later report. Continued movement of stolen Bitcoin could create short-term selling and monitoring risks, although the transfers remain small relative to the wider Bitcoin market.
Neutral
The direct price impact on BTC is likely to remain neutral. The latest transfers could create short-term selling concerns if the attacker liquidates the coins, and transfers through THORChain and CoinJoin may increase market-monitoring risks. However, the moved amount is small compared with Bitcoin’s overall trading volume and market capitalisation. The earlier incident also increased on-chain activity without producing a clear BTC price reaction. In the short term, traders may watch known attacker addresses, exchange deposits and cross-chain flows for signs of liquidation. This could cause brief volatility or risk-off sentiment, particularly if larger vaults are emptied. In the longer term, the exploit may strengthen demand for secure wallet practices and hardware-based randomness, but it does not materially change Bitcoin’s supply, network fundamentals or adoption outlook. The main risk is event-driven volatility rather than a sustained bearish trend.