Coldcard Wave 3 Operator Begins Cashing Out Stolen Bitcoin via THORChain and CoinJoin

The operator behind the so-called Wave 3 cluster of Coldcard hardware-wallet thefts has begun systematically cashing out stolen bitcoin after weeks of inactivity, according to a Monday update from Galaxy Research.

Galaxy’s on-chain team says the actor created 293 separate 2-of-2 multisignature vaults, one for each victim grouping, rather than funneling coins into a shared collector as earlier waves did.

Those vaults held about 208 bitcoin after the late-July and early-August sweeps.

Starting September 2, the operator began spending the largest holdings first.

By September 7 it had emptied ranks 1 through 11, moving 97.09 bitcoin from 12 vaults.

The next ten unspent vaults still contain 30.81 bitcoin; vaults ranked 61 through 293 hold another 33.77 bitcoin combined.

Two hundred eighty-two vaults remain untouched with 116.98 bitcoin.

The first large exit, on September 2, sent 20.50 bitcoin across THORChain into two Ethereum addresses that were later emptied.

Subsequent spends on September 5 and 6 routed coins into CoinJoin mixing rounds after brief hops through Taproot addresses.

Galaxy calculates that the Wave 3 operator has now moved roughly 45 percent of the coins taken in that cluster, sending them either to Ethereum via THORChain or into CoinJoin denominations.

The same spending also revealed a previously unlisted 58-address cluster that used an identical 2-of-2 script and was co-spent into a hop that funded a CoinJoin.

Galaxy currently labels the cluster “cause = open” but considers it likely another Coldcard victim set.

If confirmed, Wave 3 would expand to 294 vaults and Galaxy’s published high-confidence total for the entire exploit would rise to about 1,806 bitcoin.

Across the wider investigation, Galaxy estimates that about 82 percent of coins it attributes to the Coldcard vulnerability still sit in original attacker-controlled addresses, while about 18 percent have been moved in patterns consistent with laundering.

The 45 percent figure applies only to the Wave 3 vaults now being spent.

The thefts stem from a firmware defect introduced in March 2021 that weakened seed generation on certain Coldcard models, allowing offline reconstruction of private keys for single-signature addresses created after that date.

Coinkite published an advisory and fixed firmware; existing weak seeds cannot be repaired and must be replaced.

Galaxy has documented multiple distinct waves and footprints and has said it cannot confirm whether they belong to one actor or several.

Researchers continue to work with victims so they can file reports with authorities and have shared suspected attacker addresses with investigators and industry partners. Additional victims are still coming forward, but Galaxy has not identified confirmed new attacker activity after August 6 except for these later movements of already-stolen coins.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend