Coldcard Wave 3 Drainer Routes $7.7M via THORChain, Parks Change in CoinJoin—82% of Stolen BTC Still Idle
97.09 BTC ($7.7M) from Coldcard’s Wave 3 moved: THORChain to ETH, then CoinJoin with 57.24 BTC left as change. Firmware flaw cut entropy to 40 bits; 82% of funds remain unmoved.

Because Bitcoin
September 7, 2026
The Coldcard attacker just revealed more of their playbook. After weeks of quiet, 97.09 BTC—about 45% of the Wave 3 stash and roughly $7.7 million at current prices—has been pushed off the attacker’s vaults, mixing cross-chain exits with Bitcoin privacy tooling while leaving forensic breadcrumbs that matter.
Here’s the movement pattern worth focusing on: - On September 2, the first tranche left the largest vault and traversed THORChain, surfacing as Ethereum. Only 20.56 BTC’s worth actually landed on ETH. - Over the weekend, subsequent spends went into CoinJoin rounds. About 57.24 BTC now sits unspent as CoinJoin change at a single address, with the trail going cold on roughly 19 BTC more.
The architecture behind these withdrawals is deliberate. The exploiter erected 293 two-of-two multisig “vaults,” then began emptying them top-down by size. Eleven are fully drained. The next ten collectively hold 30.81 BTC, while the smallest 233 vaults retain 33.77 BTC. Across every wave tied to this exploit, an estimated 82% of the seized Bitcoin hasn’t moved.
The strategic tell: choosing THORChain first and CoinJoin later balances speed, liquidity, and traceability. A cross-chain hop yields quick conversion and distribution optionality, but subjects the attacker to slippage, potential MEV exposure, and growing analytics coverage on decentralized swaps. CoinJoin buys plausible deniability on-chain, yet concentrating 57.24 BTC of change at a single address introduces linkage risk. That consolidation may be opportunistic staging—or operational sloppiness that enables clustering heuristics to bite later.
The vault-by-size drain fits an attacker’s risk calculus. Clearing the fattest UTXOs early reduces headline exposure if the operation gets clipped, while leaving a long tail of smaller vaults to be worked through opportunistically. Using 2-of-2 multisig here isn’t about security; it’s about controlled distribution and fee/transaction management under pressure.
This entire saga traces back to a deterministic failure: a 2021 firmware bug diverted seed generation from the hardware RNG to a software substitute, taking effective entropy from 128 bits down to as low as 40. That downgrade let adversaries reconstruct private keys offline and sweep single-signature wallets without touching the hardware. The siphoning began July 30.
Coinkite has since overhauled firmware—Mk4/Mk5 5.6.2 and Q 1.5.2Q—now requiring users to inject their own randomness (keypresses, dice rolls, coin flips). Important nuance: no update can fix a seed born under the flawed firmware. Anyone who created a wallet on affected versions needs to generate a fresh seed and move funds. The CEO publicly apologized on July 31, acknowledging the trust gap, with a deeper technical postmortem still pending.
Scope is still widening. A new vault funded by 58 addresses has been identified; indications suggest it’s another victim, which would bring the published exploit total to roughly 1,806 BTC (~$143.9 million). There’s also an unconfirmed fourth wave of 638.5 BTC that, if validated, would push cumulative losses past 2,400 BTC. Back in August, researchers noted no attacker sweeps since August 6—before the latest September moves restarted the flow.
Market backdrop remains stable enough to encourage patient laundering rather than panic selling. Bitcoin trades near $79,420, down about 0.64% on the day, with a 24-hour high of $80,494, low of $79,081, and volume around $827.8 million. Odds trackers put an 86% chance of BTC staying between $78,000 and $80,000 today and a 58% chance it finishes the week below $80,000, conditions that rarely force rushed exits.
What matters next: - Watch that 57.24 BTC CoinJoin change. If it fragments intelligently, traceability declines; if it reconsolidates or interacts with KYC’d rails, risk spikes. - Monitor the bottom 233 vaults. Small, repeated spends often reveal pattern leakage. - Expect heightened analytics on THORChain and CoinJoin intersections; cross-domain heuristics get stronger with each mistake.
The technical root cause was simple entropy discipline. The operational story is evolving UTXO management under surveillance. The reputational outcome will hinge on whether firmware, audits, and user education materially reduce single points of failure—without pushing users into workflows they won’t follow.