The attacker tied to the third wave of the Coldcard wallet exploit has moved about 45% of the Bitcoin taken in that phase of the breach, according to a Monday update from Galaxy Research. The firm said the funds were routed either through THORChain or into CoinJoin transactions, both paths that can make tracing more difficult.
Galaxy said the latest activity began on Sept. 2, when the exploiter started moving Bitcoin into Ethereum through THORChain. It also reported more recent transfers into CoinJoin rounds, a transaction method that combines multiple users’ payments into one transfer.
Funds leave largest victim vaults first
Galaxy Research said the third-wave attacker had set up 293 two-of-two multisignature vaults to hold victims’ coins. According to the update, the exploiter has been draining those vaults in descending order by size rather than moving funds evenly across all addresses.
The 11 largest vaults have now been emptied, Galaxy said. That pattern suggests the latest transfers are concentrated in the biggest pools of stolen Bitcoin associated with the third wave.
THORChain and CoinJoin used in recent movements
In its update, Galaxy said part of the stolen Bitcoin was sent through THORChain and converted into Ethereum. The firm placed the start of that activity on Sept. 2.
It also said the latest transactions pushed Bitcoin into CoinJoin rounds. CoinJoin is commonly used to combine multiple payments into a single transaction, which can obscure the path of funds onchain. Galaxy described the broader 18% of moved Coldcard funds as having apparently been shifted for laundering purposes.
Most stolen Bitcoin remains in attacker-controlled addresses
Despite the recent transfers, Galaxy said most of the Bitcoin taken across all waves of the Coldcard exploit has not yet left its original holding addresses. Its estimate is that roughly 82% of the stolen Bitcoin still sits in the initial attacker-controlled wallets.
The remaining 18% has moved, according to the research note. Galaxy characterized those transfers as apparent laundering activity, while stopping short of claiming the funds have exited the attacker’s control entirely.
Exploit ranks among 2026’s largest so far
Data cited from DefiLlama places the Coldcard incident as the third-largest exploit recorded so far in 2026. Only the $293 million Kelp DAO hack and the $280 million Drift protocol hack rank above it in the same tally.
The next confirmed point to watch is whether the attacker continues draining the remaining multisig vaults in the same order and whether additional Bitcoin is routed through THORChain, CoinJoin, or other destinations. For now, Galaxy’s update indicates that a majority of the stolen funds are still sitting in the original addresses linked to the exploit.
Source: cointelegraph.com