How Coldcard Developments Reshapes the Competitive Landscape
BiFu Editorial · 2026-09-09 · 3 min read
Table of contents
Galaxy Research confirms the Coldcard third-wave attacker moved 45% of stolen bitcoin, draining the 11 largest vaults. Roughly 82% of all stolen funds remain in original addresses, while 18% moved through laundering channels, affecting victims and exchanges tracking the funds.
Four independent sources have confirmed a significant development in the Coldcard theft saga: the attacker behind the third wave of exploits has moved 45% of the stolen bitcoin, draining the 11 largest vaults. This change affects the 190 victims identified by Galaxy Research, as well as exchanges and analytics firms that must now track actively moving funds rather than static stolen balances.
The operating impact matters because the movement pattern signals active laundering, not a dormant wallet, which shifts how custodians and investigators prioritize address monitoring.
What changed in the third attack wave
CoinDesk reported that the Coldcard hacker moved $7.7 million in BTC, representing 45% of the bitcoin stolen in the third attack wave. Galaxy Research said the attacker has now drained the 11 largest vaults tied to that wave, meaning the biggest concentrations of stolen funds are no longer sitting idle. Decrypt added that the attacker built 293 separate vaults for the stolen bitcoin and is emptying them in order of size, largest first.
That methodical approach gives investigators a predictable sequence, but it also means the largest recoverable amounts are moving fastest.
The Block confirmed the same 45% figure and cited Galaxy data from mid-August showing roughly 1,779 BTC stolen from 190 victims across more than 8,600 addresses. The scale of the address count matters because it fragments the stolen supply across many wallets, complicating any single seizure or freeze request. For exchanges, this means screening against a growing list of tagged addresses rather than one identifiable wallet.
Who is affected by the fund movements
The affected participants include the 190 victims identified by Galaxy Research, the exchanges that may receive tainted funds, and the analytics firms maintaining address watchlists. Cointelegraph reported that Galaxy said 82% of bitcoin stolen across all Coldcard attacks remains in the original addresses, with 18% moved in apparent laundering. The laundering appears to involve THORChain or CoinJoin transactions, according to the Cointelegraph report, which creates a practical problem for compliance teams because those methods obscure the destination wallet.
For bitcoin holders using Coldcard devices, the confirmed change is not a new vulnerability in the hardware itself but rather the continued movement of funds from earlier exploits. The operational consequence is that any exchange receiving bitcoin from the flagged addresses faces a higher compliance burden. Custodians and institutional desks that handle large bitcoin flows need to check whether their screening tools cover the 8,600-plus addresses identified by Galaxy, since the attacker is actively consolidating and moving funds.
What remains unconfirmed in the Coldcard developments
What remains unconfirmed is whether the 45% movement figure covers only the third wave or includes earlier attack waves. Galaxy's mid-August data covered roughly 1,779 BTC from 190 victims, but the relationship between that total and the 293 vaults described by Decrypt is not fully spelled out in the source documents.
The 82% static figure from Cointelegraph applies to all Coldcard attacks, yet the 45% movement figure applies specifically to the third wave, so readers should not combine those percentages without checking the underlying Galaxy report.
The next source-document check is Galaxy Research's full report, which should clarify whether the 293 vaults are exclusive to the third wave or span multiple waves. It should also confirm whether the 11 drained vaults held a disproportionate share of the 1,779 BTC total. Until that document is reviewed, the confirmed facts are the 45% movement, the 11 drained vaults, the 293-vault structure, and the 82% static balance across all attacks.
For BiFu readers tracking bitcoin security events, the practical takeaway is to treat the 8,600-plus tagged addresses as an active laundering network rather than a static theft record. The next verification step is to check whether Galaxy has published updated address lists since mid-August, because the attacker's continued movement means any watchlist older than that date is already incomplete.
Reference
- https://www.coindesk.com/business/2026/09/07/coldcard-hacker-moves-45-of-bitcoin-stolen-in-third-attack-wave
- https://cointelegraph.com/news/coldcard-third-wave-attacker-moves-bitcoin-stolen
- https://decrypt.co/377537/coldcard-hacker-moves-7-7m-nearly-half-of-third-wave-bitcoin-haul
- https://www.theblock.co/news/defi/2026-09-07-coldcard-exploiter-moves-wave-3-413661
Read more from BiFu
Galaxy Research confirms the Coldcard third-wave attacker moved 45% of stolen bitcoin, draining the 11 largest vaults. Roughly 82% of all stolen funds remain in original addresses, while 18% moved through laundering channels, affecting victims and exchanges tracking the funds.
Related articles
Kevin O’Leary Developments: Affected Participants and What Comes Next
Three independent publisher reports confirm Kevin O’Leary developments that affect compliance teams, exchange operators, and Bitcoin holders: Congress will revisit the Clarity bill, O’Leary is buying crypto again while watching for a major stock exchange to adopt a blockchain network, and Bitcoin.
2026-09-20 · 6 min read
World Money Developments: Step Sequence and What Comes Next
World Money developments across 3 independent sources confirm that World has launched a self-custodial 'super app' named World Money, now rolling out across more than 150 countries.
2026-09-19 · 4 min read






