Coldcard’s ‘Wave 3’ Bitcoin Heist Strikes Again—What This Mysterious Laundering Move Means for Crypto Investors
It’s been more than a month since the Coldcard exploit rattled the crypto world, yet the digital fugitive behind it all hasn’t hit pause on moving those stolen Bitcoin coins. Curious, right? Just when you think the trail might have gone cold, Galaxy Research drops a bombshell analysis revealing the Coldcard “Wave 3” attacker is still weaving through complex transaction paths — making the laundering game slicker and far from over. From cleverly funneling funds through THORChain into Ethereum to now shaking things up with Bitcoin CoinJoin transactions, this isn’t your average thief scrambling to cash out fast. Nope, we’re looking at a meticulously crafted system with 293 multisig vaults acting like a fortress for the loot, each tied to victims’ hard-earned coins. The attackers aren’t just moving money; they’re playing chess with it, taking their time to obfuscate every move. Makes you wonder: in this high-stakes digital heist, who’s really holding the cards — and how long before this saga finally unfolds? LEARN MORE.
More than a month has passed since the Coldcard exploit happened, but the attacker has not stopped moving funds yet.
On the 7th of September, Galaxy Research came up with an analysis that showed that the Coldcard “Wave 3” attacker is actively moving the stolen Bitcoin [BTC] through different transaction paths.
The laundering route of the exploiter
According to the on-chain activity, the attacker first moved the stolen funds through THORChain into Ethereum [ETH]. And now the laundering is happening through Bitcoin CoinJoin transactions.

Here, in Wave 3, the attacker appears to have created 293 separate 2-of-2 multisig vaults, with each vault corresponding to a victim or group of victim funds.
According to the analysis, about 208.24 BTC was consolidated from roughly 1,912 victim addresses into 293 collection addresses. Post which, each collection address then funded one of these vaults. This effectively created a structured system for storing the stolen BTC.
Bitcoin’s compromised so far
Going ahead, the 293 vaults were then ranked according to how much BTC they originally contained, and the attacker has been spending them in that order.

The first major exit came on 2nd September, when the largest vault’s 20.50 BTC was routed through THORChain into Ethereum, adding more transaction layers and making the funds harder to follow. Two Ethereum addresses receiving the funds have since been emptied.
The attacker then shifted to CoinJoin, which mixes multiple users’ Bitcoin inputs and outputs, making individual funds harder to trace. Using the latter, about 15.48 BTC was moved on 5th September.
This was followed by a 61.12 BTC move on 6th September, with some funds entering CoinJoin rounds through intermediate addresses.
That said, across three major movements, the attacker was able to move 97.09 BTC in five days, leaving about 116.98 BTC untouched in the Wave 3 vaults.
This means roughly 45% of the 214.07 BTC in these vaults has already been moved.

Laundering appears to continue further
Researchers also identified a previously unknown vault containing funds from 58 addresses that showed the same 2-of-2 multisig pattern and was later linked to a CoinJoin.
If confirmed as another Coldcard victim vault, Wave 3 would rise from 293 to 294 vaults. This in turn would potentially increase the estimated total stolen to around 1,806 BTC.
After all of these movements, Galaxy Research reported,
Approximately 82% of coins stolen in the Coldcard exploit remain held in the original attacker- controlled addresses, while 18% has been moved apparently for laundering purposes.
Final Summary
- The Coldcard exploiter has now moved the stolen funds through Bitcoin CoinJoin transactions.
- Around 82% of coins stolen in the Coldcard exploit remain held in the original attacker-controlled addresses.




Post Comment