CoinDesk•
Coldcard hacker moves $7.7 million in BTC, 45% of bitcoin stolen in third attack wave

On-chain data confirms that the attacker behind the recent exploits targeting Coldcard hardware wallet users has begun consolidating illicit holdings, transferring approximately $7.7 million in Bitcoin across multiple fresh addresses. According to analysis published by Galaxy Research, this latest series of transactions accounts for roughly 45% of the total Bitcoin exfiltrated during the campaign's third attack wave. The movement marks a critical escalation in the adversary’s operational timeline, as the hacker successfully drained the 11 largest high-value vaults associated with this specific iteration of the exploit, systematically emptying wallets that had previously remained untouched since the initial breach.
Blockchain intelligence tracking the movement noted that the transfers executed with high network fee priority, sweeping unspent transaction outputs (UTXOs) from complex storage setups into single-signature control nodes. Security analysts suspect the breach stems not from a core cryptographic flaw in the Bitcoin protocol itself, but rather from a compromised implementation vector—potentially involving malicious firmware, intercepted supply chain logistics, or sophisticated social engineering that exposed seed phrases or multi-signature quorum keys. The fact that high-value multi-signature arrangements were compromised highlights an evolving threat matrix where attackers bypass air-gapped physical protections by targeting key generation workflows and backup procedures.
The systematic emptying of these tier-one vaults carries profound implications for the broader crypto custody sector. Coldcard, long regarded as a gold standard for high-security Bitcoin self-custody due to its air-gapped architecture and open-source code, now finds its user base confronting uncomfortable trade-offs between physical isolation and operational security. Institutional investors and high-net-worth individuals utilizing self-custody solutions are increasingly auditing their key management protocols, with several over-the-counter (OTC) trading desks reporting a surge in inquiries regarding institutional-grade multi-party computation (MPC) alternatives over traditional hardware setups.
Market sentiment surrounding Bitcoin self-custody tooling has taken a noticeable hit, compounding broader anxieties within the digital asset ecosystem regarding the safety of sovereign asset storage. Analysts warn that if the attacker begins liquidating the $7.7 million bounty through privacy-preserving protocols like CoinJoin, decentralized cross-chain bridges, or privacy-focused mixing services, it could trigger localized sell-side pressure or renewed regulatory scrutiny against non-custodial privacy infrastructure. Blockchain forensic firms continue to actively track the tainted funds, but as the adversary systematically obfuscates transaction traces, the incident serves as a stark reminder that even the most hardened physical hardware remains vulnerable to upstream operational flaws.
