What actually happened
How Coldcard broke in the first place
From one attacker to a swarm
The three trails everyone's still watching

Over a month of silence. Then, late on September 2, the Wave 3 attacker behind the Coldcard hack finally touched the stolen coins. Galaxy Research's Alex Thorn reported it the next morning, September 3.
A Wave 3 cluster pushed roughly 20.5 BTC out of the original attacker-controlled wallet, ran it through THORChain, and pulled ETH out the other side. This is the first time funds from any of the three original Coldcard attacker waves have moved since the theft.
That single fact matters more than the dollar amount. For five weeks, Waves 1, 2, and 3 sat frozen. Researchers watched. Victims waited. Now one of them has blinked.
Thorn traced the path on-chain: victim addresses to a Wave 3 collection wallet, into a P2WSH vault, through several separate 2-of-2 hops, then into THORChain's inbound vaults, and out as ETH on Ethereum. Several swap attempts failed and were refunded before later retries went through, which tells you the attacker is still testing the exit, not executing a smooth playbook.

Wave 3's route out of Bitcoin. The refunded attempts suggest the attacker is still probing THORChain's liquidity and slippage limits.
Around 90% of Wave 3 funds are still sitting untouched in the original vaults. This is a first move, not a full cash-out. But it opens a live cross-chain tracing point that didn't exist before today, and it tells compliance teams and exchanges exactly where to watch.
The root cause goes back to a single build flag from March 2021. Coldcard maker Coinkite shipped firmware 4.0.1 with a libngu library migration that was supposed to check whether hardware RNG was enabled. Instead, it checked whether the macro existed. Wrong check, same result either way: devices silently fell back to MicroPython's Yasmarang software PRNG instead of the STM32 chip's hardware random number generator.
The practical effect: seeds that should have carried 128 bits of entropy came out with 72 bits on Mk4, Mk5, and Q models, and as little as 40 bits on Mk2 and Mk3. 128 bits is unbreakable with any hardware that exists today. 40 bits is a weekend job for anyone with the right tooling.

The entropy gap in one chart. Every bit lost roughly halves the work needed to guess the key.
Coinkite disclosed the flaw on July 30-31 and shipped a patch within a day. But a firmware update can't fix a seed that was already generated weakly. Any single-sig wallet created on vulnerable firmware between March 2021 and the patch date is still exposed until the funds move to a fresh, correctly-generated seed.
What started as three coordinated waves is now a lot messier. By early August, Thorn had confirmed at least 15 separate attackers exploiting the same flaw independently. Victim reports kept surfacing new footprints, and by mid-August that count had grown past 33. Galaxy's most recent full tally, published August 24, put high-confidence losses across all waves and imitators near 1,789 BTC (about $115 million at the time of theft, over $138 million at today's prices) spread across more than 8,800 addresses. That number is separate from today's Wave 3 cash-out and hasn't been revised to reflect it yet.

Five years from broken build flag to live cross-chain laundering.
Three specific threads from earlier reporting saw no confirmed new movement in today's update:
bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, one of the Wave 1/2 addresses, holds roughly 562 BTC (about $36 million at last check) and has not shown a new confirmed spend. The 64.9 BTC that went into a Wasabi CoinJoin back on August 4 hasn't surfaced a new destination since. And the 30.185 BTC that moved to a fresh wallet on August 7 hasn't shown further movement of that specific tranche.
None of that means those funds are safe or forgotten. It means today's news is specifically about Wave 3, and the other trails are still cold for now.
What this means if you own a Coldcard
If your seed was generated on a Coldcard before the July 31 patch, on any single-sig setup, treat it as compromised. Not "probably fine." Compromised. Generate a fresh seed on patched firmware and move your funds now, ideally in a way that doesn't reuse the old vulnerable addresses as change outputs.
Multisig setups are meaningfully safer here since an attacker needs more than one weak key, but they're not automatically clean either if multiple signers used affected devices.
As of early August, Galaxy Research had already flagged roughly 600 suspected attacker addresses to investigators and compliance firms, and that list has only grown since. If THORChain and downstream exchanges are watching those addresses closely, today's ETH conversion is exactly the kind of movement that gets flagged and potentially frozen. That's the one piece of good news in this update.
India Crypto Research operates independently. The information presented herein is intended solely for educational and informational purposes and should not be construed as financial advice. Before making any financial decisions, it's essential to undertake your own thorough research and analysis. If you're uncertain about any financial matters, we strongly recommend seeking guidance from an impartial financial advisor.