Industry News

Coldcard Hardware Wallet Hack: Stolen Bitcoin Still Being Laundered a Month Later

AMBCrypto · 7 Sept 2026
Key Takeaway If your business holds cryptocurrency, ensure hardware wallets are sourced from trusted vendors, kept updated, and monitored, as stolen funds can be laundered rapidly across multiple blockchains once compromised.

More than a month after the Coldcard hardware wallet exploit, researchers say the attacker behind the so-called 'Wave 3' theft is still actively moving stolen Bitcoin. Analysis from Galaxy Research shows the attacker organised stolen funds from roughly 1,912 victim addresses into 293 separate two-of-two multisig vaults, effectively creating a structured system to store and later disperse the stolen coins.

The attacker has been draining these vaults in order of size, first routing funds through THORChain into Ethereum, then switching to Bitcoin CoinJoin transactions, which mix multiple users' funds together to obscure their origin. Across just five days in early September, about 97 BTC was moved out of the vaults, leaving roughly 117 BTC still untouched. Researchers also flagged a previously unknown vault that, if confirmed as another Coldcard-linked victim group, could push the total estimated theft to around 1,806 BTC.

This case highlights how attackers increasingly use cross-chain transfers and mixing services to launder large volumes of stolen cryptocurrency, making recovery and attribution far harder for investigators. For businesses holding or transacting in cryptocurrency, incidents like this underline the importance of securing hardware wallets and monitoring for firmware or supply-chain vulnerabilities.

Key Takeaway: If your business holds cryptocurrency, ensure hardware wallets are sourced from trusted vendors, kept updated, and monitored, as stolen funds can be laundered rapidly across multiple blockchains once compromised.

Summarised by CISO AI from AMBCrypto. We link back to every original so you can read it yourself.