Most of the Bitcoin stolen from Coldcard hardware wallets is still sitting in attacker-controlled addresses, untouched, and that frozen 82% is what makes the exploit’s next chapter dangerous.
On September 7, Galaxy Research posted on X that the attacker behind the third wave of Coldcard thefts had moved 97.09 BTC, roughly 45% of that wave’s haul, in the wave’s first systematic laundering. That made headlines. The quieter number in the same update matters more: across all waves, about 82% of the stolen Bitcoin remains at its original attacker-controlled addresses, with only 18% moved in transactions that appear designed to obscure the funds’ trail, according to Galaxy.
What moved, and what didn’t
The Wave 3 exploiter created 293 two-of-two multisignature vaults, one per victim, and has been working through them largest first. Eleven are now empty. On September 2, about 20.5 BTC from the largest vault went through THORChain, with proceeds landing on Ethereum; on September 5 and 6, 15.48 BTC from the second-largest vault plus another 61.12 BTC from 10 vaults went into CoinJoin rounds, which combine multiple users’ payments into one transaction to make funds harder to trace. All figures are an on-chain snapshot as of September 7 and will shift.
Wave 3’s 97.09 BTC, about $7.7 million at the time, is a small slice of the whole. Galaxy’s running estimate of the exploit was roughly 1,779 BTC from 190 victims by mid-August, and later counts put confirmed losses near 1,789 BTC. Including a newly flagged 58-address vault, probably linked to another Coldcard victim but unconfirmed, would raise the total to about 1,806 BTC, or roughly $143.9 million. Galaxy has also carried an unconfirmed fourth wave of 638.5 BTC, which would push the total past 2,400 BTC. None of those totals is settled.
Why the frozen 82% is the problem
The laundering that did happen suggests a cash-out phase is underway, and Galaxy’s post describes the Wave 3 operator continuing to move funds. But the bulk of the haul is still parked where it landed. Until it moves, law enforcement and victims retain their best recovery window; once it does, Galaxy has shared identified attacker addresses with law enforcement agencies and industry partners, and traced the Wave 3 funds as far as roughly 19 BTC whose trail ends at CoinJoin outputs.
Whether the remaining Bitcoin is mixed, swept, or held is unknown. What is known is the root cause: a Coinkite firmware update shipped in March 2021 (version 4.0.1 onward) weakened seed generation, cutting effective entropy to 40 to 72 bits from 128, low enough to brute-force. Coinkite has released fixed firmware (Mk4/Mk5 5.6.2 and Q 1.5.2Q), but an update cannot repair an already-generated seed, so affected owners still need to create new seeds and move their funds. Chief executive Rodolfo Novak apologized in an open letter on July 31, writing the company would have to “earn back our users’ trust.”
Galaxy’s team has engaged directly with more than 190 victims. The attacker’s next sweep, when it comes, will decide whether the story ends in recovery or in a mix.


