The operator behind the so-called Wave 3 cluster of Coldcard hardware-wallet thefts has begun systematically cashing out stolen bitcoin after weeks of inactivity, according to a Monday update from Galaxy Research.
Galaxy’s on-chain team says the actor created 293 separate 2-of-2 multisignature vaults, one for each victim grouping, rather than funneling coins into a shared collector as earlier waves did.
Those vaults held about 208 bitcoin after the late-July and early-August sweeps.
Starting September 2, the operator began spending the largest holdings first.
By September 7 it had emptied ranks 1 through 11, moving 97.09 bitcoin from 12 vaults.
The next ten unspent vaults still contain 30.81 bitcoin; vaults ranked 61 through 293 hold another 33.77 bitcoin combined.
Two hundred eighty-two vaults remain untouched with 116.98 bitcoin.
The first large exit, on September 2, sent 20.50 bitcoin across THORChain into two Ethereum addresses that were later emptied.
Subsequent spends on September 5 and 6 routed coins into CoinJoin mixing rounds after brief hops through Taproot addresses.
Galaxy calculates that the Wave 3 operator has now moved roughly 45 percent of the coins taken in that cluster, sending them either to Ethereum via THORChain or into CoinJoin denominations.
The Coldcard Wave 3 operator has been methodically moving the largest thefts in order by size rank. They have spent ranks 1–11 in order; the next ten unmoved vaults hold 30.81 BTC. Ranks 61–293 hold 33.77 BTC between them. pic.twitter.com/iV09c1JwaL
— Galaxy Research (@glxyresearch) September 7, 2026
The same spending also revealed a previously unlisted 58-address cluster that used an identical 2-of-2 script and was co-spent into a hop that funded a CoinJoin.
Galaxy currently labels the cluster “cause = open” but considers it likely another Coldcard victim set.
If confirmed, Wave 3 would expand to 294 vaults and Galaxy’s published high-confidence total for the entire exploit would rise to about 1,806 bitcoin.
Across the wider investigation, Galaxy estimates that about 82 percent of coins it attributes to the Coldcard vulnerability still sit in original attacker-controlled addresses, while about 18 percent have been moved in patterns consistent with laundering.
The 45 percent figure applies only to the Wave 3 vaults now being spent.
The thefts stem from a firmware defect introduced in March 2021 that weakened seed generation on certain Coldcard models, allowing offline reconstruction of private keys for single-signature addresses created after that date.
Coinkite published an advisory and fixed firmware; existing weak seeds cannot be repaired and must be replaced.
Galaxy has documented multiple distinct waves and footprints and has said it cannot confirm whether they belong to one actor or several.
Researchers continue to work with victims so they can file reports with authorities and have shared suspected attacker addresses with investigators and industry partners. Additional victims are still coming forward, but Galaxy has not identified confirmed new attacker activity after August 6 except for these later movements of already-stolen coins.