Industry News

Coldcard Wallet Hack: Stolen $7.7M in Bitcoin Being Laundered via CoinJoin and THORChain

The Currency Analytics · 7 Sept 2026
Key Takeaway Businesses using hardware wallets or crypto for payments should verify firmware update history and consider migrating funds if a device has ever run vulnerable firmware.

An attacker who stole funds from Coldcard hardware wallet users is now moving the proceeds through laundering techniques designed to obscure the money trail. According to Galaxy Research, the hacker recently shifted 97.09 BTC (about $7.7 million), sending part of it through THORChain to convert into Ethereum and routing the rest through CoinJoin, a Bitcoin privacy method that mixes transactions together to make tracing difficult. Not all funds have moved cleanly: some remains unspent as CoinJoin change, and the destination of nearly 19 BTC is still unclear.

The theft itself was highly organised. The attacker created 293 individual two-of-two multisig vaults, each built to drain a specific victim's coins, and appears to be working through them from largest to smallest. The root cause traces back to a March 2021 Coldcard firmware update from maker Coinkite that introduced a critical flaw: it replaced the wallet's dedicated hardware random-number generator with a weaker software alternative for seed generation. This made it possible for someone aware of the bug to reconstruct private keys offline, without ever needing physical access to the device.

This case is a reminder that hardware wallets are only as secure as the firmware running on them, and that flaws can go undetected for years before being exploited at scale.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Currency Analytics. We link back to every original so you can read it yourself.