One of the year’s largest Bitcoin theft operations has entered another laundering phase.
Galaxy Research says the attacker behind the third wave of Coldcard wallet compromises has moved approximately 45% of that wave’s stolen assets.
The operator previously converted stolen Bitcoin into Ether through THORChain on September 2. On Sunday, the attacker shifted tactics and began sending Bitcoin through CoinJoin transactions intended to make transaction tracing more difficult.
Approximately 97.09 BTC, worth roughly $7.8 million at Monday’s prices, had been spent from the tracked Wave 3 wallets. Galaxy says the attacker appears to be processing compromised wallets from largest to smallest.
Across the broader Coldcard incident, roughly 82% of identified stolen assets remained in original attacker-controlled addresses, while the remainder had begun moving through laundering routes.
Galaxy previously identified about 1,779 stolen BTC from 190 victims involving more than 8,600 addresses. A newly identified cluster of 58 additional addresses could raise the total to approximately 1,806 BTC, worth about $144 million at current prices.
Investigators trace the compromise to a firmware flaw introduced in 2021 that reduced entropy when some Coldcard wallets generated seeds, making affected seed phrases more vulnerable to brute-force recovery.
TOKEN RECON ASSESSMENT
The important development is movement.
Stolen Bitcoin sitting still can be mapped, watched and potentially intercepted if it reaches a compliant exchange.
Once the attacker begins systematically using CoinJoin, THORChain and other cross-network routes, asset recovery becomes much harder.
Token Recon is watching the remaining 82% closely. A large-scale activation of those wallets could create hundreds of millions of dollars in additional laundering activity.
Source: The Block / Galaxy Research — Coldcard attacker movements