97.09 BTC Moved From Addresses Attributed to Coldcard’s Third Wave

On September 7, Galaxy Research reported that 97.09 BTC had been spent from multisig vaults attributed to the third wave of the Coldcard exploit. Coinkite recommends that users of affected versions migrate their funds to a new seed.

BTC movement from addresses attributed to the third wave of the Coldcard exploit was recorded by Galaxy Research on September 7. Of 293 multisig “vaults,” 97.09 BTC was spent, representing approximately 45% of this wave’s volume.

Galaxy said the funds were sent through THORChain and into CoinJoin transactions. This is movement on a public blockchain, which by itself does not confirm the perpetrator’s identity or the unauthorized nature of every transfer.

BTC movement involves tracked vaults

The attribution of the 293 vaults to the third wave is a forensic conclusion by Galaxy Research. Blockchain data alone does not prove that all of the listed addresses belong to one person or group.

Galaxy also identified a vault linked to 58 addresses as probably related to Coldcard victims. However, it left the cause of this group open.

The issue involved seed generation

Coinkite confirmed a firmware issue that weakened seed generation. It said this was not a remote takeover of the devices.

A firmware update alone will not fix a seed created with a vulnerable version. Coinkite therefore released corrected firmware for the affected models and recommends migrating funds to a new seed according to the official procedure.

What the current BTC movement means

The current BTC movement does not mean a new exploitation of the vulnerability or a new attack on the devices. It is movement of a portion of the BTC that Galaxy Research attributed to the third wave of the incident.

The use of THORChain and CoinJoin transactions complicates further tracking of the funds’ movement on the blockchain, but it does not confirm the identity of the person who carried out the transactions.

For Coldcard users, Coinkite’s warning is significant: if the seed was created with a vulnerable firmware version, the update itself will not restore its security. The balance must be migrated to a new seed.

What to watch next

  • whether Galaxy Research or independent analysts publish verifiable addresses and details of further transfers,
  • whether Coinkite releases a technical analysis of the incident or changes the scope of the affected versions,
  • whether the connection of the additional vault with 58 addresses is confirmed and whether further victims or waves emerge.

Sources

Verified and updated: 09/08/2026 07:38

Sharing