Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Currencies39062
Market Cap$ 2.77T-0.41%
24h Spot Volume$ 33.60B+10%
DominanceBTC57.14%-0.67%ETH10.88%+0.05%
ETH Gas0.24 Gwei
MarketBitcoinBlockchainGalaxyCold Wallet
Sep 7, 2026
2min read
byLakshya Baskar
forTheNewsCrypto

Third-wave Coldcard attacker has moved roughly 45% of the stolen Bitcoin so far, using THORChain on September 2 to bridge coins to Ethereum and running CoinJoin rounds to obfuscate flows after creating 293 2-of-2 multisig vaults and emptying the 11 largest vaults. Across all Coldcard waves Galaxy reports 82% of stolen BTC remains in attacker-controlled addresses and only 18% has been laundered, making the exploit one of 2026’s largest losses (ranked third behind Kelp DAO ~$293M and Drift ~$280M) and underscoring cross-chain, DeFi and wallet security risks for crypto investigators and market participants.
See what traders are focused on
- Third-wave Coldcard hacker has already transferred roughly 45% of the stolen Bitcoin through THORChain and CoinJoin transactions.
- According to Galaxy, 82% of stolen Bitcoin from Coldcard hacks has remained in the possession of attackers.
The perpetrator of the third wave attack against the Coldcard wallet has escalated the pace of transferring funds, reports Galaxy Research. The exploiters have transferred approximately 45% of the Bitcoin stolen from the third wave so far. These transfers indicate a pattern of using methods that make blockchain tracking difficult.
https://x.com/glxyresearch/status/2096785347929608296
The perpetrator moved Bitcoin to Ethereum through THORChain on September 2. Recent transactions involved moving Bitcoin different users are included in a transaction. This makes it more difficult to track transactions of individual fund transfers on the Bitcoin blockchain. It now provides researchers with insight into how the attacker operates the stolen funds
Two-of-Two Multisignature Vaults Indicate Attack Plan
According to Galaxy, the third-wave attacker opened 293 multisignature two-of-two vaults. These were vaults with Bitcoin stolen from Coldcard victims. So far, the funds have been transferred from the biggest vaults in decreasing order of their sizes. According to Galaxy, funds from the 11 biggest vaults have already been transferred.
This information allowed researchers to track down some of the transactions linked to the exploit. They managed to find an unknown multisignature vault, which had most probably been used for transferring stolen Bitcoins from another victim. However, Galaxy was unable to determine the circumstances of this new theft. It means that the extent of the attack has expanded, but no new confirmed loss is known yet.
Bulk of the Stolen Bitcoin is Yet Unmoved
Even with all of the recent activities, the bulk of the Bitcoin stolen in all Coldcard attack waves remains in the initial attack-controlled addresses. According to Galaxy, 82% of Bitcoin stolen in all Coldcard attacks still lies in those addresses. The remaining 18% has since been transferred in transactions indicative of laundering.
The third wave is, therefore, a big portion of the active fund movement activity. It provides investigators with yet another pattern of transactions for monitoring. The Coldcard exploit is one of the biggest cryptocurrency exploits documented within the year 2026. According to DefiLlama, it is the third-biggest exploit of the year with reported losses. The Kelp DAO hack is ranked first with reported losses of approximately $293 million. In second place is the Drift Protocol exploit, which incurred about $280 million in losses.
This particular exploit reveals how stolen cryptocurrency can be moved through various blockchain ecosystems like THORChain and CoinJoin. The transactions present yet another piece of evidence for investigators and market players to track down.
Highlighted Crypto News:
South Korea’s Hanwha Advances Tokenized Securities With Avalanche Platform as Regulations Evolve
Source: cryptorank.io
