
Coldcard Attacker Launders Significant Portion of Stolen Bitcoin
Vexoda Newsroom
An attacker involved in the third wave of the Coldcard wallet exploit has moved approximately 45% of their stolen Bitcoin holdings, employing THORChain and CoinJoin techniques to obscure the funds' tr
The individual responsible for the third wave of exploits targeting Coldcard Bitcoin wallets has recently moved a substantial portion of the stolen cryptocurrency. Analysis indicates that nearly half of the Bitcoin acquired through this specific attack vector has now been re-routed. This movement is a significant development, as it suggests the attacker is actively attempting to integrate the illicitly obtained funds back into the broader financial ecosystem, making them harder to trace and recover.
According to a research update from Galaxy, the attacker began transferring funds on September 2nd, initially utilizing THORChain to move Bitcoin onto the Ethereum network. Following this, the funds were subjected to CoinJoin transactions. CoinJoin is a privacy-enhancing technique that aggregates multiple Bitcoin transactions into a single, larger transaction, thereby obfuscating the origin and destination of individual payments and making it significantly more difficult for blockchain analysis tools to follow the money.
The investigation revealed that the attacker had established 293 separate multisignature wallets, specifically designed as two-of-two vaults, to house the stolen coins from various victims. These vaults were systematically emptied, starting with the largest holdings and progressing downwards. The movement of funds from the eleven largest vaults has now been confirmed, providing valuable insights into the scale and methodology of the attack. This process also inadvertently helped researchers identify an additional, previously unknown vault.
This newly identified vault, separate from the initially tracked ones, is believed to contain assets from another Coldcard victim, although the exact cause of that specific loss remains under investigation. Across all identified waves of the Coldcard exploit, a considerable amount of Bitcoin, approximately 82%, still resides in the addresses controlled by the attackers. However, the 18% that has been moved represents a clear effort towards laundering the stolen assets.
The cumulative losses from the Coldcard exploits place it as the third-largest exploit within the cryptocurrency space for the year 2026, trailing behind significant hacks such as the Kelp DAO incident, which resulted in $293 million in losses, and the Drift protocol hack, amounting to $280 million. These figures underscore the ongoing challenges in securing digital assets and protecting users from sophisticated cyber threats within the rapidly evolving digital asset landscape.
For traders and cryptocurrency users, this event serves as a stark reminder of the importance of robust security practices, particularly concerning self-custody of digital assets. The ongoing efforts by attackers to launder stolen funds highlight the persistent need for enhanced blockchain surveillance and recovery mechanisms. Investors should remain vigilant about hardware wallet security, transaction monitoring, and the potential risks associated with newly identified vulnerabilities within the ecosystem.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.