Tracking the Coldcard Stolen Funds Laundering Path: Third-Wave Attacker Moves 45% via THORChain and CoinJoin in 2026
Galaxy Research: third-wave Coldcard attacker moved ~45% of stolen BTC via THORChain or CoinJoin; 82% remains. Explore laundering path and risks.
Article Citation Summary
Galaxy Research: third-wave Coldcard attacker moved ~45% of stolen BTC via THORChain or CoinJoin; 82% remains. Explore laundering path and risks.
Tracking the Coldcard Stolen Funds Laundering Path: Third-Wave Attacker Moves 45% via THORChain and CoinJoin in 2026
Key Takeaways / TL;DR
- Share moved: As of September 7, 2026, the third-wave Coldcard attacker has moved about 45% of the stolen Bitcoin, via THORChain or CoinJoin. Source: Galaxy Research (as reported by Cointelegraph).
- Remaining funds: About 82% of Bitcoin stolen across all Coldcard attacks remains at original addresses; only 18% has been moved, suspected for laundering.
- Multisig vaults: The attacker created 293 2-of-2 multisig vaults and has begun moving funds from the 11 largest vaults in descending size order.
- Exploit ranking: This Coldcard exploit is the third-largest crypto exploit in 2026 so far, behind a $293 million exploit.
| Metric | Value | Notes |
|---|---|---|
| Third-wave attacker share moved | 45% | As of September 7, 2026, via THORChain or CoinJoin |
| Remaining funds across all attacks | 82% | Still at original addresses |
| Share moved for suspected laundering | 18% | Suspected to be moved for laundering |
| Multisig vaults | 293 | 2-of-2 multisig |
| Largest vaults from which transfers have begun | 11 | In descending size order |
| 2026 exploit ranking | Third-largest | Behind a $293 million exploit |
What Happened in the Third-Wave Coldcard Attack?

According to Galaxy Research data (as reported by Cointelegraph), as of September 7, 2026, the third-wave Coldcard attacker has moved approximately 45% of the stolen Bitcoin, with funds transferred via THORChain or CoinJoin, and the exploit is the third-largest crypto exploit in 2026 so far. About 82% of funds from all Coldcard attacks remain at original addresses. This article provides a detailed analysis of the Coldcard stolen funds laundering path tracking.
How Much Stolen Funds Has the Attacker Moved?
The third-wave attacker has moved about 45% of the stolen Bitcoin. Across all Coldcard attacks, roughly 82% of the stolen Bitcoin remains at original addresses, and 18% has been moved, suspected for laundering. This means most funds have not moved yet, but the risk of further transfers remains, as the attacker has begun moving funds in descending size order.
What Tools Were Used for Transfers?
The attacker used THORChain (a cross-chain decentralized liquidity protocol) or CoinJoin (a Bitcoin mixing technique) to move funds. Both tools significantly increase the difficulty of on-chain tracking. The tools themselves are neutral, but in this context they were used for suspected laundering.
How Did the Attacker Store Victim Funds?
The attacker created 293 2-of-2 multisig vaults to hold victim funds and began moving funds from the 11 largest vaults in descending size order, which helped identify a previously unknown victim vault. This dispersed storage method increases the complexity of tracking and freezing.
Market and Security Impact of the Attack

This Coldcard exploit is the third-largest exploit in 2026 so far, behind a $293 million exploit. With 82% of funds still at original addresses, there is subsequent transfer risk. Investor attention to cold wallet security has increased.
What Is the Size of This Exploit in 2026?
This exploit is the third-largest crypto exploit in 2026 so far, behind a $293 million exploit. This ranking underscores the severity of the incident.
Is Bitcoin Cold Storage Security Being Questioned?
Coldcard is a hardware wallet. The incident reminds investors that cold storage is not absolutely secure. They should keep device firmware updated, verify transaction sources, and follow official security advisories. A single incident is not enough to negate the overall security of hardware wallets. For more analysis on recent BTC market pressure, see Bitcoin market multiple pressure analysis.
Will Cross-Chain Privacy Tools Face Stricter Scrutiny?
THORChain and CoinJoin being used for laundering may prompt regulators to increase scrutiny of cross-chain protocols and mixing services. Related tokens and projects may face more compliance pressure; investors should monitor regulatory developments.
What Should Altcoin Holders Watch For?
Altcoin investors should watch regulatory developments for leading cross-chain protocols like THORChain, and whether mixing services will be restricted. This could affect related token liquidity and market sentiment.
Risks and Key Indicators for Investors
The attacker has already moved funds from the 11 largest vaults, and the remaining 82% of funds are still at original addresses, with continued transfer risk. Cold storage risks cannot be ignored.
Could the Remaining Funds Be Further Moved?
Based on the attacker's pattern of moving funds in descending size order, the remaining funds are likely to continue being moved, but this judgment is based on pattern recognition, not a certain conclusion. Investors should monitor on-chain data, especially those multisig vaults that still contain funds.
Is There Any Chance for Victims to Recover Funds?
On-chain tracking may help identify fund flows, but recovery depends on law enforcement and cooperation. There is no public recovery progress at present, and victim funds remain at risk of loss.
How Should Subsequent On-Chain Fund Movements Be Tracked?
You can follow Galaxy Research public reports, or use on-chain analysis tools to monitor balance changes in specific multisig vaults. Focus on whether transfers continue from large vaults to smaller vaults. For BTC historical trends, see Bitcoin history repeating: 200-day moving average breakout and retest opportunity reappears.
Which Regulatory Developments Should Be Watched?
Watch regulatory statements from major jurisdictions such as the US and EU on mixers and cross-chain protocols, as well as whether exchanges strengthen compliance reviews of related assets. Policy changes may directly affect the use of privacy tools and token prices.
What Happens If the Remaining 82% of Funds Continue to Move?
If the remaining funds continue to be moved, they may be further dispersed through channels like THORChain and CoinJoin, increasing on-chain tracking difficulty and possibly triggering expectations of stricter regulation on privacy tools. However, whether the attacker continues to move funds and the pace of transfers cannot be predicted. For more BTC price level analysis, read Bitcoin stalls after hitting $80,000.
Frequently Asked Questions About the Coldcard Stolen Funds Laundering Path
- What is the specific share of funds moved by the attacker? The third-wave attacker has moved about 45% of the stolen Bitcoin, and about 82% of funds across all Coldcard attacks remains at original addresses. Data from Galaxy Research, as reported by Cointelegraph.
- Are the remaining funds still at risk? Yes, the attacker has already moved funds from the 11 largest vaults, and the remaining funds may continue to be moved. This judgment is based on observed transfer patterns, not a certain prediction.
- How are THORChain and CoinJoin used for laundering? The attacker uses THORChain cross-chain swaps or CoinJoin mixing to obscure the fund trail. The tools themselves are neutral, but in this context they are abused.
- What exactly is the Coldcard exploit? There is currently no further information on the specific details of this exploit. It is known that the attacker has moved stolen Bitcoin. Users are advised to follow official announcements and update firmware.
- How can I protect my cold wallet assets? Regularly check device firmware, verify transaction receiving addresses, avoid using software and QR codes from unknown sources, and follow hardware wallet vendors' security updates.
- What is the difference between THORChain and CoinJoin? THORChain is a cross-chain decentralized exchange used for asset swaps; CoinJoin is a Bitcoin mixing technique used to combine transactions and obscure origins. The two are often confused, but they serve different functions.
- Do these laundering activities affect Bitcoin price? The impact is limited so far, but if they trigger stricter regulation or large sell-offs, they could cause short-term volatility. Close monitoring of on-chain transfers and regulatory developments is needed.
This article is produced by the MSXGO editorial team, AI-assisted, and reviewed through an editorial process. Fee rates and figures are subject to each platform's latest official announcements.
FAQ
How much stolen Bitcoin has the Coldcard attacker moved? ▼
The third-wave attacker has moved about 45% of the stolen Bitcoin, and about 82% of funds across all Coldcard attacks remains at original addresses. Data from Galaxy Research, as of September 7, 2026.
Which tools did the attacker use to move stolen funds? ▼
Funds were moved via THORChain or CoinJoin. THORChain is used for cross-chain swaps, and CoinJoin is a Bitcoin mixing technique; both tools can obscure the fund trail.
Why is this exploit called the third-largest exploit of 2026? ▼
Because this Coldcard exploit is the third-largest crypto exploit in 2026 so far, behind a $293 million exploit.
Will the remaining unmoved funds still be moved? ▼
There is a possibility of continued transfers. The attacker has begun moving funds from the 11 largest vaults in descending size order, and the remaining 82% of funds may be moved later.
How can investors track the movement of these laundered funds? ▼
You can follow Galaxy Research's subsequent tracking reports and on-chain multisig vault balance changes, while also keeping an eye on regulatory developments related to THORChain and CoinJoin.