BrandLogo
Table of Contents

What actually happened

How Coldcard broke in the first place

From one attacker to a swarm

The three trails everyone's still watching

beginner

Coldcard Hack Update: Wave 3 Money Finally Moves, and It's Going Through THORChain

By India Crypto Research|3 mins read
Last Updated on: Sep 03, 2026|Published On: Sep 3, 2026
Key Takeaways
  • Stolen Bitcoin just crossed into Ethereum for the first time. Waves 1, 2 and 3 sat completely frozen for five weeks since late July, and now one Wave 3 wallet has broken that silence.
  • Only about 20.5 BTC moved so far, with roughly 90% of Wave 3's stolen funds still untouched. Looks like a test run, not a full cash-out.
  • Several THORChain swap attempts got refunded before finally going through. Points to the attacker fumbling with liquidity and slippage, not running a clean operation.
  • Moving into Ethereum through THORChain creates a fresh cross-chain paper trail that didn't exist yesterday. Compliance teams and exchanges now know exactly where to watch.
India Crypto Research
LearnPart of a series
Coldcard Hack
Coldcard wallet losses near $114 million as a fourth sweep hits the mempool
  • 1. What's new in wave four
  • 2. How the losses stack up
  • 3. What's driving the exploit
  • 4. What should affected users do?
Current Article
Coldcard Hack Update: Wave 3 Money Finally Moves, and It's Going Through THORChain
  • 1. What actually happened
  • 2. How Coldcard broke in the first place
  • 3. From one attacker to a swarm
  • 4. The three trails everyone's still watching
Coldcard Bitcoin Theft Tops $100M and the Stolen Funds Still Haven't Moved
  • 1. Coldcard Bitcoin Theft Tops $100M and the Stolen Funds Still Haven't Moved
  • 2. What Happened?
  • 3. The Damage
  • 4. Where the Money Is Now?
  • 5. The Wallet Turned Graffiti Wall
  • 6. What This Means for Self-Custody
  • 7. Watch the Wallets
Coldcard Hack Update: $75M in Stolen Bitcoin Hasn't Moved. Here's Why That Matters.
  • 1. Coldcard Hack Update: $75M in Stolen Bitcoin Hasn't Moved. Here's Why That Matters.
How a Five-Year-Old Coldcard Bug Drained Over $115 Million in Bitcoin
  • 1. What Went Wrong Inside the Wallet
  • 2. Galaxy Research's Numbers, Verified and Growing
  • 3. How the Thefts Were Actually Carried Out
  • 4. What This Means for Bitcoin Self-Custody Holders
Coldcard Hack Update: No New Movement as of September 1
  • 1. What the Three Tracked Positions Show Today
  • 2. Why the Wasabi Transfer Still Matters Most
  • 3. What This Means for the Broader Case
  • 4. What to Watch Next

Over a month of silence. Then, late on September 2, the Wave 3 attacker behind the Coldcard hack finally touched the stolen coins. Galaxy Research's Alex Thorn reported it the next morning, September 3.

A Wave 3 cluster pushed roughly 20.5 BTC out of the original attacker-controlled wallet, ran it through THORChain, and pulled ETH out the other side. This is the first time funds from any of the three original Coldcard attacker waves have moved since the theft.

That single fact matters more than the dollar amount. For five weeks, Waves 1, 2, and 3 sat frozen. Researchers watched. Victims waited. Now one of them has blinked.

What actually happened

Thorn traced the path on-chain: victim addresses to a Wave 3 collection wallet, into a P2WSH vault, through several separate 2-of-2 hops, then into THORChain's inbound vaults, and out as ETH on Ethereum. Several swap attempts failed and were refunded before later retries went through, which tells you the attacker is still testing the exit, not executing a smooth playbook.

Blog_Image

Wave 3's route out of Bitcoin. The refunded attempts suggest the attacker is still probing THORChain's liquidity and slippage limits.

Around 90% of Wave 3 funds are still sitting untouched in the original vaults. This is a first move, not a full cash-out. But it opens a live cross-chain tracing point that didn't exist before today, and it tells compliance teams and exchanges exactly where to watch.

How Coldcard broke in the first place

The root cause goes back to a single build flag from March 2021. Coldcard maker Coinkite shipped firmware 4.0.1 with a libngu library migration that was supposed to check whether hardware RNG was enabled. Instead, it checked whether the macro existed. Wrong check, same result either way: devices silently fell back to MicroPython's Yasmarang software PRNG instead of the STM32 chip's hardware random number generator.

The practical effect: seeds that should have carried 128 bits of entropy came out with 72 bits on Mk4, Mk5, and Q models, and as little as 40 bits on Mk2 and Mk3. 128 bits is unbreakable with any hardware that exists today. 40 bits is a weekend job for anyone with the right tooling.

Blog_Image

The entropy gap in one chart. Every bit lost roughly halves the work needed to guess the key.

Coinkite disclosed the flaw on July 30-31 and shipped a patch within a day. But a firmware update can't fix a seed that was already generated weakly. Any single-sig wallet created on vulnerable firmware between March 2021 and the patch date is still exposed until the funds move to a fresh, correctly-generated seed.

From one attacker to a swarm

What started as three coordinated waves is now a lot messier. By early August, Thorn had confirmed at least 15 separate attackers exploiting the same flaw independently. Victim reports kept surfacing new footprints, and by mid-August that count had grown past 33. Galaxy's most recent full tally, published August 24, put high-confidence losses across all waves and imitators near 1,789 BTC (about $115 million at the time of theft, over $138 million at today's prices) spread across more than 8,800 addresses. That number is separate from today's Wave 3 cash-out and hasn't been revised to reflect it yet.

Blog_Image

Five years from broken build flag to live cross-chain laundering.

The three trails everyone's still watching

Three specific threads from earlier reporting saw no confirmed new movement in today's update:

bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, one of the Wave 1/2 addresses, holds roughly 562 BTC (about $36 million at last check) and has not shown a new confirmed spend. The 64.9 BTC that went into a Wasabi CoinJoin back on August 4 hasn't surfaced a new destination since. And the 30.185 BTC that moved to a fresh wallet on August 7 hasn't shown further movement of that specific tranche.

None of that means those funds are safe or forgotten. It means today's news is specifically about Wave 3, and the other trails are still cold for now.

What this means if you own a Coldcard

If your seed was generated on a Coldcard before the July 31 patch, on any single-sig setup, treat it as compromised. Not "probably fine." Compromised. Generate a fresh seed on patched firmware and move your funds now, ideally in a way that doesn't reuse the old vulnerable addresses as change outputs.

Multisig setups are meaningfully safer here since an attacker needs more than one weak key, but they're not automatically clean either if multiple signers used affected devices.

As of early August, Galaxy Research had already flagged roughly 600 suspected attacker addresses to investigators and compliance firms, and that list has only grown since. If THORChain and downstream exchanges are watching those addresses closely, today's ETH conversion is exactly the kind of movement that gets flagged and potentially frozen. That's the one piece of good news in this update.

Disclaimer

India Crypto Research operates independently. The information presented herein is intended solely for educational and informational purposes and should not be construed as financial advice. Before making any financial decisions, it's essential to undertake your own thorough research and analysis. If you're uncertain about any financial matters, we strongly recommend seeking guidance from an impartial financial advisor.