- Galaxy reports the Coldcard hacker moved 97.09 Bitcoin worth about $7.8 million.
- The attacker used CoinJoin, which mixes multiple transactions to obscure the trail.
- Galaxy data shows 82% of stolen funds remain in attacker wallets; 18% shows laundering activity.
Galaxy Research says the hacker behind the third wave of the Coldcard exploit has moved 97.09 BTC, worth about $7.8 million at Monday’s prices. It represents roughly 45% of the Bitcoin stolen in that particular attack.
What makes this move notable is that the attacker seems to be following a clear plan, instead of moving coins randomly.
Galaxy Research says the attacker is going through the stolen funds from the biggest vaults to the smallest. Vaults 1 through 11 have already been drained, and the next 10 untouched ones contain approximately 30.81 BTC between them.
Attacker is Changing Tactics
On September 2, the attacker began moving stolen Bitcoin through THORChain, swapping it for Ether. That was the first notable movement from the Coldcard hacks after the coins had mostly sat idle.
However, over the weekend, the attacker began funneling more Bitcoin through CoinJoin, a technique used to obscure the trail.
CoinJoin mixes transactions from many users at once, making it much harder to connect who sent what to whom. It doesn’t make Bitcoin impossible to track, but it does make blockchain analysis a lot more complicated.
Not surprisingly, this suggests the attacker is actively trying to make it harder to follow the stolen funds.
Bigger Coldcard Theft is Much Larger
Earlier, Galaxy Research said around 1,778.84 BTC was taken from more than 8,600 addresses, based on their investigation of 190 confirmed victims.
More recent tracking puts the total at roughly 1,789 BTC, and there’s another possible cluster in danger that could push the amount to approximately 1,806 BTC.
Interestingly, despite the scale of the theft, most of the stolen Bitcoin has remained stationary. Galaxy’s latest numbers show that about 82% is still sitting in the attacker’s wallets, while the remaining 18% has been moved in ways consistent with laundering.
The Coldcard incident is especially unsettling for the Bitcoin community, as it didn’t involve a typical exchange breach.
Those behind the attack exploited a firmware vulnerability affecting how wallet seeds were generated. Galaxy says the affected Coldcard devices didn’t produce random enough seeds, which let the attackers figure out the keys and drain the Bitcoin remotely without physically accessing the devices.
The company has recommended that anyone with funds in a vulnerable Coldcard wallet should move them immediately.
Related: Coldcard Hacker Moves Stolen BTC, Swaps to ETH via THORChain
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.