Rank 1 through Rank 11. Gone.
Galaxy Research released that classification without drama, but it is the most important forensic paragraph in the Coldcard story since the exploit began on July 30, 2026. The operator behind the third wave has now moved 45% of the coins seized in that wave. Some of that capital crossed THORChain into Ethereum. Some of it entered Coinjoin rounds. For analysts who have spent years tracing stolen bitcoin, the numbers are less surprising than the discipline behind them.
This was not a panicked cash-out. It was a structured liquidation. The attacker is methodically draining vaults in descending order of value, treating stolen cryptocurrency like an indexed portfolio rather than an emergency windfall. That tells us something about the threat model most coverage has missed: this is not a thief in a hurry. This is a professional extraction process built on an exploiter-controlled ledger.
We should begin where the story actually begins: not with the movement, but with the physics of the vaults themselves.
Context: A Firmware Ghost From March 2021
The attack that emerged on July 30, 2026, did not come from a zero-day discovered overnight. It came from an old ghost. In March 2021, a Coldcard firmware update introduced a build error that would sit dormant for years. The mistake allowed wallets to fall back on a weak software random number generator instead of their hardware-based source of entropy.
That single failure reduced seed security from an expected 128 bits down to as low as 40 bits on older devices. The difference in computational difficulty between 2^128 and 2^40 is not incremental. It is astronomical. A 40-bit search space can be attacked offline with consumer-grade hardware in minutes or hours, depending on the device architecture. A 128-bit space remains practically immune to brute force. By compromising the entropy generation layer, the attacker could extract private keys remotely, without physical access, and without triggering the alarm bells that typically accompany hardware wallet theft.
The sobering detail is that the flaw was not in the Bitcoin protocol. It was not in the secure element's cryptographic primitives. It was in the supply chain of trusted updates, the exact layer that most self-custody users assume is beyond question. This is why the aftermath was so violent on-chain.
Bitcoin activity spiked hard after the exploit became public. Affected users moved coins, consolidated balances, and re-derived keys into new wallets. Active addresses climbed to an eight-month high. That reaction was rational at the individual level. At the aggregate level, it created a measurable liquidity event in the charts, even if the price of bitcoin showed little acknowledgment of what had happened.
The price action was, in some ways, a trap. Bitcoin rose to nearly $82,000 last month before pulling back near $79,500. If you read the price alone, you would conclude that the Coldcard event was a minor security footnote in an otherwise bullish market. On-chain data tells a different story, and that discrepancy is precisely why the laundering pipeline deserves closer scrutiny.
Core: The Vault Architecture and the Liquidity Trail
The attacker did not simply send stolen coins to exchanges. During Wave 3, the exploiter created 293 distinct 2-of-2 multisig vaults to hold victims' coins. This is an unusual structural choice, and it is worth pausing on because most retail observers assume a thief would consolidate funds into one liquid address as quickly as possible.
A 2-of-2 multisig requires two signatures to move funds. When both keys are controlled by the same person, multisig becomes an operational layer, not a security layer. In this case, the architectural choice was almost certainly deliberate. By splitting the haul into hundreds of vaults, the operator created several advantages: operational separation between batches, a slower forensic trail, and most importantly, a built-in accounting system for staggered liquidation.
The ranking system matters more than the vault count. Galaxy Research reports that the operator has been spending the largest share of the theft, not by chronology, but by vault size. Ranks 1 through 11 have already moved. The next 10 unmoved vaults hold 30.81 BTC. Ranks 61 through 293 collectively hold just 33.77 BTC.
That distribution is highly uneven. The ten largest remaining vaults contain nearly as much bitcoin as the bottom 232 vaults combined. This is a Pareto curve, and the attacker is harvesting the long tail last. Why would anyone do that? Because small vaults generate mixers inputs and test transactions. They are useful probes for monitoring how much surveillance is attached to the cluster. The large vaults are the prize; the small vaults are the laboratory.
There is a gap in the public dataset that deserves attention. Galaxy explicitly names ranks 1 through 11 as moved, and ranks 12 through 21 as the next ten unmoved vaults. It also provides the aggregate figure for ranks 61 through 293. But the vaults ranked 22 through 60 are not clearly enumerated in the published summary. That missing middle tier could hold the next signaling event. If the attacker moves vaults 22 through 60 before touching the remaining large vaults, it would indicate a deliberate sequencing strategy that the market has not yet priced.
The movement itself began on September 2. The first transactions pushed funds through THORChain into Ethereum. THORChain was chosen for the same reason it has become the highway for stolen bitcoin in recent years: it does not require centralized approval, it is not blocked by OFAC sanctions lists, and it produces native BTC to ETH swaps and beyond without forcing users through custodial exchange checkpoints. The operator did not need to ask permission. The cross-chain liquidity engine handled the conversion automatically.
The latest activity, by contrast, has shifted into Coinjoin rounds. That is a different approach entirely. THORChain is a conversion tool; Coinjoin is a graph-breaking tool. By cycling the stolen coins through Coinjoin, the attacker aims to break the link between the initial vault addresses and the eventual destination addresses. The goal is to manufacture plausible deniability for any downstream spend, particularly if those coins are eventually sold over-the-counter or moved into exchange wallets.
Here is where the forensic numbers become genuinely beautiful: the published percentages are self-consistent. If 45% of Wave 3 has moved, and that quantity represents only 18% of the total stolen haul across all waves, then Wave 3 accounts for exactly 40% of the entire theft. This is not an accident of rounding. It is a mathematical identity. The attacker's Wave 3 vaults represent two-fifths of all stolen bitcoin, and the remaining 82% of the overall haul is still sitting in the original attacker-controlled addresses.
Most analysts will interpret that as containment. They will say the attacker has been unable to launder the majority of the stolen funds. But that is not the reading I take from these numbers. The 82% figure indicates restraint, not failure. This operator has already demonstrated the ability to move significant sums through cross-chain bridges and mixers. The decision to leave 82% untouched is intentional. It is a reserve. It is leverage against a future liquidation window.
The percentage split also reveals that the earlier waves, Wave 1 and Wave 2, have contributed relatively little to the 18% that has moved. The attacker is concentrating all of the current laundering activity inside Wave 3, the newest and most well-structured portion of the haul. That suggests a staged rollout. Wave 3 is the test floor. If these Coinjoin rounds and THORChain swaps continue without triggering effective freeze mechanisms, the attacker can apply the same methodology to the remaining waves at a much faster pace.
Another new data point emerged from this wave: a previously unidentified vault linked to a cluster of 58 addresses that are likely associated with Coldcard victims. This is significant because many victims of the firmware flaw may not know they were compromised. They may have held their keys for years, never connected the wallets to the network, and only now are being exposed through attribution. The 58-address cluster expands the victim circle well beyond the earlier public incident reports.
The existence of that unidentified vault should also change how the security community estimates the total damages. If one additional vault was uncovered late in Wave 3, there may be more. Attackers frequently retain a "shadow reserve" of victim keys they never activate immediately. That reserve is the most dangerous asset in this entire incident, because it can be deployed long after the market has forgotten the hack.
Hashes don't lie. Wallets do.
The Mechanics of the Laundering Loop
Let me be precise about the laundering sequence, because there is a lot of imprecise language in the coverage of this incident.
First, identify a set of stolen bitcoin sitting in a 2-of-2 vault that has not yet been drained. The vault can be viewed publicly on the Bitcoin blockchain. Its structure is not hidden. Multisig scripts do not contain owner identities, but they do contain public keys, and those keys feed directly into wallet clustering algorithms.
Second, move the bitcoin out of that vault. In this wave, the operator has used two distinct mechanisms. On September 2, the first mechanism was THORChain. The operator routed bitcoin into a THORChain pool, and the protocol swapped it into Ethereum-native assets on the other side. Why Ethereum? Because Ethereum's ecosystem provides access to decentralized exchanges, lending protocols, privacy platforms, and the ability to hop between chains with far less friction than Bitcoin's primary network.
The third mechanism is not a mechanism at all, but a destination pattern: Coinjoin. Coinjoin has existed for years as a method of breaking the provenance trail. Multiple participants sign a single transaction that combines their inputs and outputs in a way that makes it cryptographically difficult to determine which output belongs to which input. For a sophisticated attacker, the anonymity set is the product of everyone else's discipline. If a Coinjoin round contains only stolen coins, the privacy benefit is minimal. If it contains thousands of honest coins, the stolen coins can blend into the crowd.
Galaxy's report does not claim that the funds have become unrecoverable. That distinction matters. Coinjoin is not magic. It clears some heuristics, but it leaves others untouched. Transaction timestamps, spending patterns, amounts that do not conform to standard denomination sizes, and the eventual speed of consolidation can still be used to make probabilistic claims about where the funds eventually arrive.
It is tempting to measure the success of Coinjoin by the privacy it promises. A forensic analyst should measure it by the privacy it actually delivers. The attacker is spending the largest vaults first because those vaults produce a single identifiable thread: a big payment entering a mixer, followed by a series of outputs. The earliest output from that thread is frequently the one the operator will spend months later. If there is a time fingerprint, it will be visible in the next consolidation event.
This is where my experience tracing thefts over the years matters, because I have seen this exact sequencing before. Since my early audits of ICO distribution mechanics, through the 2020 DeFi Summer projects that collapsed on liquidity illusions, to the NFT mint-chasers of 2021 and the Terra post-mortem in 2022, the operators who move stolen funds in ranked order are the ones who maintain a long-term liquidation timeline. They never dump all at once. They test the pipes. They measure reaction times. They adjust the entropy of their spend behavior until they see the market stop paying attention.
The current data suggests the attacker knows exactly what the forensic community is watching. Ranks 1 through 11 were moved first, the vaults with the highest expected value. The 30.81 BTC sitting in the next 10 unmoved vaults is the next logical prize. If I wanted to detect the next move, I would monitor two things: the Coinjoin participation rates around the Bitcoin block intervals when fees are low, and the THORChain inbound liquidity for bitcoin-denominated swap events that cluster near vault addresses in the 12-to-21 range.
On-chain truth will always be a better signal than Twitter narratives.
I would also continue to ignore the asset's price as a measure of threat. The fact that bitcoin rallied to $82,000 while this laundering pipeline was active does not mean the exploit lacked significance. The market's indifference is a structural feature, not a statement of safety. The total size of the Coldcard theft is large for a hardware wallet incident, but it is still small relative to the daily volume of bitcoin trading across centralized and decentralized venues. Attackers do not need the price to move when they launder through synthetic assets or when they use the Bitcoin network as a temporary storage layer.
Follow the liquidity, not the narrative.
Contrarian Angle: 82% Frozen Is Not a Victory
The natural optimistic read of Galaxy Research's data is that the attacker has only managed to move 18% of the total haul. If 82% remains in identifiable attacker-controlled addresses, one might reasonably conclude that the threat has been contained and that law enforcement has the upper hand.
That conclusion is both correct and dangerously incomplete.
The containment is real only if the attacker cannot eventually move those funds. But with private keys already in hand, the barrier to moving the remaining 82% is not technical. It is operational. The attacker is choosing not to move those coins yet. Why? Because moving all of them at once would destroy their value and eliminate the labor-intensive privacy engineering that allows the earlier samples to pass through unused pathways.
There is a deeper pattern here. The 82% figure represents a type of cold storage for criminals. It is a reserve of future liquidity that can be deployed when the market is more favorable for liquidation. Every day those addresses remain dormant, the attacker accumulates optionality. If bitcoin's price rises further, the eventual sale will bring more proceeds. If the price falls, the attacker can wait. The vault walls have no maintenance fees. Bitcoin holding costs nothing beyond opportunity risk.
There is also the matter of the previously unknown vault tied to 58 victim-related addresses. If Galaxy found one additional vault so late, then the threat-analysis community must revisit its assumptions about how many Coldcard users were affected. Some of those users may have already written off their balances as lost. Others may not yet know that their seed phrase was exposed. The gap between the victim list and the actual victim pool is itself a discovery with important consequences.
The other contrarian point concerns the active address spike. Conventional market commentary assumed that the surge in active addresses after the exploit represented network usage growth. I read it differently. The migration of affected users into new wallets inflates active address counts, but it does not represent new economic demand. It is capitulation in the form of transaction volume. An address spike driven by fear is not the same as an address spike driven by adoption. Analysts who blend the two signals will inevitably generate false readings about the health of the network.
Perhaps the most overlooked detail is the entropy failure itself. The Coldcard incident was not a Bitcoin failure and not even a hardware wallet failure in the conventional sense. It was a supply chain failure in the firmware build process. A build error that was introduced in March 2021 compromised the randomness source, which then reduced the effective security of seeds. There are no on-chain indications of intent. The victims did nothing wrong. They held their own keys. They followed the best practices of self-custody. And they were still exposed because the device itself generated weak entropy.
That distinction matters because the crypto industry is already using the Coldcard event to justify two counterproductive extremes. The first extreme argument is that self-custody is too risky for ordinary users and that regulated custodians should hold digital assets instead. The second extreme argument is that open source hardware wallets are no safer than hot wallets because they are susceptible to supply chain attacks. Both arguments confuse a firmware vulnerability with a systemic indictment of self-custody.
The real lesson is narrower: entropy generation at the hardware level must be verifiable by the user. That is not always possible with closed source firmware. Coldcard's core value proposition was built on the trust model that its source code was transparent, reproducible, and audited. A single build error in March 2021 broke that trust and introduced an exploitable entropy collapse. The entire industry should respond not by abandoning hardware wallets, but by demanding independent verification of every firmware release and reproducible builds as a mandatory security baseline.
I have personally audited enough wallet implementations to know that random number generators are the first place attackers look. It is not the cryptography that fails in most real-world exploits. It is the glue around the cryptography: the build process, the environment variable, the software fallback, the unused code path. In this case, the fallback random generator was old, weak, and silent. It did not announce its failure. It simply made every seed phrase it generated fundamentally survivable by brute force. That is the horror story hiding inside this incident.
Fragmented yields, fragmented trust. The same principle applies to security promises as it does to DeFi protocols. Trust distributed across many components is trust that must be verified across each component.
The Last Unmoved Coins
Any pre-mortem of future on-chain risk should be built around the ranking structure Galaxy has documented. The attacker's behavior suggests a simple liquidation schedule: first the largest vaults, then the mid-tier vaults, then the long tail of small balances. We have evidence that the first eleven vaults are already empty. The next ten vaults contain 30.81 BTC combined. That is not a trivial amount, but it is also far from the largest tranche still in play, which remains hidden inside the vaults that ranks 22 through 60 could represent.
The next signal will not be a tweet. It will be a liquidity movement. If the 30.81 BTC from vaults 12 through 21 begins moving through THORChain into Ethereum addresses that subsequently interact with Coinjoin rounds, the event is confirmed. The Wave 3 pipeline will have been established as the template for all future waves. If, on the other hand, the next movements begin from the lower-ranked vaults, analysts should pay even closer attention, because the attacker will have changed strategies in response to external pressure.
The second signal to watch is commercial: which privacy pools and cross-chain liquidity providers maintain their current inflow patterns. The laundering business does not stop when an article is published. It continues until the funds are either frozen, seized, or clean enough to be spent without triggering surveillance. The remaining 82% of the Coldcard haul is a reservoir of risk that will not disappear. It will wait, sometimes for years, for the moment when the market's collective attention has moved on.
The price of bitcoin near $79,500 is irrelevant to that risk. Prices can move by thousands of dollars while stolen coins remain dormant in their vaults. Security events do not need to have an immediate price effect to be meaningful. They are meaningful because they reveal the fragility that market prices never fully discount.
The Coldcard story is not over because the news cycle has moved on. It is paused. The attacker has left the bulk of the stolen bitcoin in vaults that function as a hidden treasury, waiting for the right liquidity conditions to launder the next tranche.
On-chain analysts will be watching the unspent vault outputs for the first sign of movement. The question, as always, is whether the broader market will notice before the next wave begins.
Follow the liquidity. The answer is already written in the unspent transaction outputs.