Mark RadarMARK RADAR
About
EN
Sign in

Coldcard Hacker Moves 45% of Third-Wave Bitcoin Haul

6 reports · First detected 2026-09-03 · Last active 2026-09-07

Coldcard is a hardware wallet designed for offline Bitcoin key storage, but a series of thefts targeting its users has drawn attention because of the broad victim pool and the large number of affected addresses. Moving stolen funds across chains or converting them into other assets can complicate blockchain tracing and recovery efforts, underscoring that self-custody still carries operational and security risks despite reducing reliance on centralized intermediaries.

Galaxy said the hacker behind the “Wave 3” attacks recently moved about $7.7 million in Bitcoin, representing roughly 45% of the haul from that phase, and swapped some of the stolen BTC for Ether through THORChain. By mid-August, the broader campaign had been linked to approximately 1,779 stolen Bitcoin taken from 190 victims and more than 8,600 addresses, according to the blockchain-focused firm’s findings.

All Coverage

6 original reports

The Backstory

The history behind this event
Coldcard Bitcoin Theft Losses Could Top $150 Million, Galaxy Saysfirst seen 2026-08-15 · 3 reports · similarity 0.86

Coldcard, a hardware wallet designed to keep Bitcoin private keys offline, has faced scrutiny over thefts linked in reports to a random-number-generation flaw dating to 2021. The weakness may have allowed attackers to derive keys and drain vulnerable wallets. The episode is significant because it challenges the security premise of hardware custody and highlights the persistent risk facing older devices whose funds were never migrated.

Galaxy Research said the theft campaign targeting Coldcard Bitcoin holders has recently slowed, possibly because the most vulnerable users have moved their assets or affected wallets have already been emptied. Reported losses now exceed $115 million, according to the latest account. Galaxy estimates the cumulative total could ultimately surpass $150 million, leaving a substantial gap between confirmed losses and the potential final toll.

Coldcard Seed Flaw Pushes Estimated Bitcoin Losses to $115 Millionfirst seen 2026-07-31 · 56 reports · similarity 0.82

Coldcard, made by Canada-based Coinkite, is an air-gapped hardware wallet designed to let Bitcoin holders control their own keys. A software integration error introduced in March 2021 caused some devices to use a weak pseudorandom-number path when generating seed phrases, sharply reducing their effective entropy. Attackers could therefore reconstruct vulnerable private keys by brute force without touching the devices, undermining a central assumption of self-custody: that an offline seed created by trusted hardware is practically unguessable.

Coinkite disclosed the incident on July 30, 2026, and told users whose Mk3 seeds were created with firmware 4.0.1 through 4.1.9 to generate new seeds and move their funds; installing updated firmware alone does not secure an existing seed. Investigators initially examined a 594.48-Bitcoin transfer, but Galaxy Research said by Aug. 25 that 1,789.28 Bitcoin, worth about $114.7 million, had been stolen across 8,865 addresses. About 87.3% of the traced funds, or roughly 1,561 Bitcoin, remained unmoved in attacker-controlled addresses.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)