A hacker linked to the third wave of attacks on users of the Coldcard hardware wallet has begun moving nearly half of their stolen Bitcoin holdings, intensifying scrutiny over one of the most methodically executed cryptocurrency theft campaigns tracked in recent memory. According to research published by Galaxy, the third-wave attacker has transferred 45% of the Bitcoin attributed to their specific tranche of the theft — a significant on-chain movement that analysts are treating as an active laundering operation.
The broader picture, however, tells a story of calculated patience. Galaxy's on-chain analysis found that across all documented Coldcard attack waves combined, a striking 82% of the total stolen Bitcoin remains sitting in the original addresses where it was first deposited after the thefts. Only 18% of the aggregate stolen funds have been moved in what the firm describes as apparent laundering activity. That the overwhelming majority of funds have remained stationary suggests that most attackers — or a single coordinated threat actor operating across multiple waves — have been deliberately biding their time, possibly waiting for investigative heat to dissipate before attempting to liquidate.
A Multi-Wave Attack Pattern Under the Microscope
The Coldcard attacks are structured across at least three distinct waves, a pattern that itself carries investigative significance. Staged theft campaigns of this nature typically indicate a degree of operational sophistication: the attacker or attacker group tests laundering routes, monitors blockchain surveillance responses, and adjusts methodology between waves. The fact that the third-wave actor has now moved 45% of their specific holdings — while first- and second-wave funds appear to remain largely static relative to the 82% aggregate dormancy rate — suggests either different individuals operating at different risk tolerances, or a single actor rotating through different operational phases for each tranche.
Coldcard hardware wallets are widely regarded within the Bitcoin security community as among the most robust cold-storage solutions available, favored by security-conscious holders precisely because of their air-gapped architecture and open-source firmware. Attacks that result in private key compromise through this class of device are therefore especially alarming to the broader self-custody ecosystem. The precise mechanism of the Coldcard-linked thefts — whether through supply-chain compromise, social engineering, seed phrase exposure, or firmware exploitation — carries outsized implications for hardware wallet users worldwide, as any confirmed vulnerability in this category of device would represent a fundamental challenge to the cold-storage security model.
On-Chain Surveillance and the Limits of Laundering
Galaxy's ability to track these movements underscores both the transparency of the Bitcoin blockchain and the increasing sophistication of on-chain forensic firms operating in the space. Every transaction on the Bitcoin network is permanently recorded and publicly auditable, meaning that fund movements — even those executed with mixing or layering intent — leave traceable artifacts that experienced analysts can reconstruct. The 18% of total funds that have been moved in apparent laundering represent a substantial sum in absolute terms, even if the majority of holdings remain frozen in place.
Law enforcement agencies and blockchain analytics firms including Chainalysis and Elliptic have developed increasingly granular tools for tracing funds through mixers, cross-chain bridges, and decentralized exchange hops — the standard toolkit employed by sophisticated crypto thieves attempting to break the transaction trail. The third-wave attacker's decision to move 45% of their holdings will inevitably generate a rich dataset for these tools to work against, potentially narrowing the investigative window for authorities.
What This Means for Hardware Wallet Security and Institutional Trust
For the broader financial community, the Coldcard incident series arrives at a particularly sensitive moment. Institutional adoption of Bitcoin has accelerated sharply, with exchange-traded funds, corporate treasury programs, and sovereign wealth vehicles all increasing exposure to the asset class. The custodial architecture underpinning much of this adoption relies — directly or indirectly — on the security guarantees of hardware wallet technology and cold-storage protocols. Any sustained erosion of confidence in those guarantees has the potential to ripple through custodial service providers, insurance underwriters, and ultimately the institutional investors whose continued participation is widely seen as a structural pillar of Bitcoin's current market position.
Galaxy's ongoing tracking of the stolen funds represents precisely the kind of real-time forensic transparency that regulators and institutional participants increasingly expect. With 82% of the total stolen Bitcoin still traceable in original addresses and 18% already in apparent motion, the critical question for investigators is whether the dormant 82% represents funds that will eventually follow the same laundering pathway — and how quickly authorities can close that window before they do. The third-wave attacker's 45% movement may be a signal that patience, for at least one actor in this campaign, has finally run out.
Written by the editorial team — independent journalism powered by Codego Press.