A threat actor responsible for a coordinated series of Coldcard hardware-wallet thefts has broken weeks of operational silence and begun systematically liquidating stolen bitcoin, deploying a sophisticated two-pronged laundering strategy that combines cross-chain obfuscation via THORChain with privacy-mixing techniques through CoinJoin. The development, disclosed in a Monday on-chain intelligence update from Galaxy Research, marks a significant escalation in what analysts have designated the Wave 3 cluster — the latest and most operationally complex phase of the Coldcard theft campaign.

According to Galaxy's on-chain team, the actor constructed 293 separate 2-of-2 multisignature vaults as part of their initial infrastructure setup, a degree of architectural sophistication that points to deliberate pre-planning rather than opportunistic theft. Each vault represents an individual controlled address designed to compartmentalize stolen funds, making blockchain tracing substantially more labor-intensive for investigators and complicating any attempt to freeze assets at a single choke point. The sheer volume of vaults — nearly three hundred discrete constructs — suggests the operator anticipated forensic scrutiny from the outset and built their exit infrastructure accordingly.

The choice of THORChain as a liquidity corridor is particularly telling. THORChain is a decentralized cross-chain liquidity protocol that allows users to swap native assets across blockchains — bitcoin to ether, for instance — without relying on a centralized exchange that would ordinarily impose Know Your Customer (KYC) and Anti-Money Laundering (AML) checks. By routing stolen bitcoin through THORChain, the Wave 3 operator is effectively severing the on-chain trail at the point of cross-chain conversion, converting bitcoin-denominated theft proceeds into assets on other networks where the original forensic lineage becomes harder to follow. This is not a novel tactic in crypto crime, but the deliberate pairing with CoinJoin amplifies its effectiveness considerably.

CoinJoin is a bitcoin transaction-mixing technique that merges multiple users' inputs into a single transaction, making it statistically difficult to determine which output corresponds to which original input. When deployed in sequence with a cross-chain swap, the combination creates layered obfuscation: CoinJoin degrades on-chain traceability within the bitcoin network, while THORChain then relocates the residual value to an entirely different blockchain environment. Blockchain forensics firms have long flagged this pairing as among the most operationally effective laundering methodologies available to technically proficient bad actors operating within decentralized finance (DeFi) infrastructure.

The weeks of inactivity preceding this cash-out phase are themselves analytically significant. Sophisticated crypto theft operators frequently impose a deliberate dormancy period following an initial breach — a tactic that serves multiple purposes. It allows investigative attention to wane, reduces the likelihood that exchange compliance teams have flagged associated addresses in real time, and gives the operator time to construct the layered vault and routing architecture that Galaxy's researchers have now documented. The reactivation after a quiet period is a well-documented behavioral pattern in high-value crypto theft cases, and its recurrence in Wave 3 underscores that this is not an amateur operation.

The Coldcard hardware wallet, manufactured by Coinkite, is widely regarded as one of the most security-hardened bitcoin storage devices available to retail and institutional users. The fact that a structured theft campaign has successfully compromised multiple devices across three identified waves raises uncomfortable questions about attack vectors that likely extend beyond the hardware itself — targeting supply chains, seed phrase handling, or user operational security rather than the device firmware directly. Galaxy Research has not, in the publicly available portion of its update, attributed the thefts to a specific vulnerability in Coldcard's hardware design, and the precise method of initial compromise across all three waves remains a matter of active investigation.

What This Means for Crypto Security and DeFi Oversight

The Wave 3 cash-out activity crystallizes a tension that regulators and DeFi protocol developers have been circling for several years: decentralized, permissionless infrastructure is genuinely and by design difficult to mobilize as a law-enforcement tool. THORChain operates without a central operator capable of freezing funds or complying with asset-recovery orders in the way a centralized exchange could. CoinJoin, similarly, is a peer-coordinated protocol with no single point of interdiction. This structural reality does not make prosecution or asset recovery impossible — blockchain forensics has advanced considerably — but it materially raises the cost and time horizon of investigative responses.

For institutional and serious retail holders of self-custody bitcoin, the Galaxy Research findings serve as a pointed reminder that hardware wallet security does not exist in isolation. Operational security practices around seed phrase storage, supply chain provenance, and transaction hygiene remain live vulnerabilities regardless of device quality. As the Wave 3 operator moves systematically through 293 vaults toward liquidity, the forensic window for intervention narrows with each completed swap. The on-chain community will be watching Galaxy's subsequent updates closely.

Written by the editorial team — independent journalism powered by Codego Press.