97.09 BTC Moved From Addresses Attributed to Coldcard’s Third Wave
On September 7, Galaxy Research reported that 97.09 BTC had been spent from multisig vaults attributed to the third wave of the Coldcard exploit. Coinkite recommends that users of affected versions migrate their funds to a new seed.

BTC movement from addresses attributed to the third wave of the Coldcard exploit was recorded by Galaxy Research on September 7. Of 293 multisig “vaults,” 97.09 BTC was spent, representing approximately 45% of this wave’s volume.
Galaxy said the funds were sent through THORChain and into CoinJoin transactions. This is movement on a public blockchain, which by itself does not confirm the perpetrator’s identity or the unauthorized nature of every transfer.
BTC movement involves tracked vaults
The attribution of the 293 vaults to the third wave is a forensic conclusion by Galaxy Research. Blockchain data alone does not prove that all of the listed addresses belong to one person or group.
Galaxy also identified a vault linked to 58 addresses as probably related to Coldcard victims. However, it left the cause of this group open.
The issue involved seed generation
Coinkite confirmed a firmware issue that weakened seed generation. It said this was not a remote takeover of the devices.
A firmware update alone will not fix a seed created with a vulnerable version. Coinkite therefore released corrected firmware for the affected models and recommends migrating funds to a new seed according to the official procedure.
What the current BTC movement means
The current BTC movement does not mean a new exploitation of the vulnerability or a new attack on the devices. It is movement of a portion of the BTC that Galaxy Research attributed to the third wave of the incident.
The use of THORChain and CoinJoin transactions complicates further tracking of the funds’ movement on the blockchain, but it does not confirm the identity of the person who carried out the transactions.
For Coldcard users, Coinkite’s warning is significant: if the seed was created with a vulnerable firmware version, the update itself will not restore its security. The balance must be migrated to a new seed.
What to watch next
- whether Galaxy Research or independent analysts publish verifiable addresses and details of further transfers,
- whether Coinkite releases a technical analysis of the incident or changes the scope of the affected versions,
- whether the connection of the additional vault with 58 addresses is confirmed and whether further victims or waves emerge.
Sources
- COINKITE Blog – Coldcard Security Advisory – Coinkite confirms the issue weakening seed generation, the availability of firmware fixes, and the need to migrate old compromised seeds.
- Decrypt – Coldcard Hacker Moves $7.7M, Nearly Half of Third-Wave Bitcoin Haul – Cites Galaxy Research’s current analysis: 97.09 BTC moved from third-wave vaults, with routes through THORChain and CoinJoin.
- The Block – Coldcard exploiter moves 45% of funds stolen from 'Wave 3' attacks, Galaxy says – Independently confirms the figure of 97.09 BTC and the approximately 45% share, while noting that these are findings by Galaxy Research.
Verified and updated: 09/08/2026 07:38



