The individual responsible for the third wave of the Coldcard wallet hack has transferred around 45% of the stolen Bitcoin, according to Galaxy Research. The funds have been routed through THORChain as well as CoinJoin transactions in an effort to obfuscate their origins.
Large-scale movements traced
On September 2, Galaxy Research reported that the hacker began moving Bitcoin through THORChain to swap into Ethereum, marking a significant step in laundering the stolen assets. The most recent activity involved sending funds into CoinJoin rounds, which aggregate payments from multiple users within a single transaction to mask individual sources.
The research team found that the exploiter established 293 two-of-two multisignature vaults to store the illicitly acquired Bitcoin. The hacker has been systematically draining the funds, starting from the largest vaults and proceeding in descending order by size. So far, withdrawals from the 11 biggest vaults have been completed.
These transfers enabled Galaxy Research to spot a previously unidentified vault that appeared to contain assets from another Coldcard wallet victim. However, the circumstances leading to this loss have not yet been verified.
Ongoing laundering efforts
Galaxy Research calculated that 82% of all Bitcoin stolen across the Coldcard wallet exploit waves is still parked in addresses believed to be under attacker control. The remaining 18% has been moved, likely as part of ongoing attempts to launder the proceeds and further complicate tracking efforts.
Galaxy identified systematic fund movements from sizable multisignature vaults, and noted the use of protocols like CoinJoin and THORChain to layer transactions and increase privacy while dispersing the stolen Bitcoin.
The Coldcard exploit now stands as the third-largest crypto attack so far in 2026, as indicated by data from DefiLlama. Only the $293 million Kelp DAO breach and the $280 million Drift protocol incident eclipsed the Coldcard case in scale this year.
Security landscape and investor tools
Incidents like the Coldcard breach highlight the need for vigilant monitoring of digital asset flows and market events. Sudden protocol exploits and high-profile listings can trigger market shifts within seconds, impacting users and liquidity. In this fast-moving environment, investors can be at a disadvantage if forced to switch between multiple apps for charts, news, or portfolio updates.
Seeking to address these challenges, many traders are turning to privacy-oriented platforms such as CryptoAppsy, which streamline all essential features. With instant access to real-time charts, price notifications, token-specific news, and macroeconomic data—all without requiring account creation—traders can respond faster to developments that may affect their holdings or risk exposure.





USDT
AAPL
