Coldcard hack moves $7.7 million, draining half of stolen Bitcoin

A Coldcard breach has shifted $7.7 million in Bitcoin, wiping out 45% of the third‑wave theft and emptying the 11 biggest vaults, according to Galaxy Research.

Coldcard hack moves $7.7 million, draining half of stolen Bitcoin

According to CoinDesk: Bitcoin, Ethereum, Crypto News and Price Data, a Coldcard attacker has now moved $7.7 million in BTC, accounting for 45 % of the Bitcoin taken in the third wave of Coldcard thefts, and has emptied the 11 largest vaults linked to that wave.

The breach marks a stark reminder that hardware‑wallet security is only as strong as the weakest step in the custody chain. It also shows how a single actor can shift large sums across the blockchain without changing the underlying technology.

What happened

The third wave of Coldcard thefts began when a group of attackers targeted users of the Coldcard hardware wallet, a device that stores private keys offline to keep them away from internet‑connected threats. In this latest phase, the attacker managed to move $7.7 million worth of Bitcoin from a cluster of accounts that together held the 11 biggest “vaults”—large, consolidated storage addresses that the thieves had previously filled.

Galaxy Research, a blockchain analytics firm, confirmed that the 11 vaults are now empty. Those vaults represented the bulk of the Bitcoin stolen in this wave, meaning the attacker has already accounted for almost half of the total amount taken in the third‑wave campaign. The movement of the funds was recorded on the public Bitcoin ledger, where each transfer is visible but the identities behind the addresses remain pseudonymous.

Why it works that way

Coldcard wallets protect private keys by keeping them on a physically isolated chip. The keys never leave the device unless the user authorises a transaction, typically by connecting the wallet to a computer, entering a PIN, and confirming the details on the device’s screen. The security model assumes that an attacker must compromise either the user’s physical access, the PIN, or the software that signs the transaction.

In practice, most breaches of hardware wallets stem from social engineering or supply‑chain weaknesses. If a victim is tricked into exposing their PIN or signing a malicious transaction on a compromised computer, the attacker can generate a valid signature without ever seeing the private key. Once the signature is produced, the Bitcoin network treats the transaction like any other, moving the coins from the victim’s address to the attacker’s address.

The “vault” concept is a layering technique: users aggregate many smaller addresses into a single large one for easier management, often protected by multi‑signature (multi‑sig) setups that require several keys to approve a move. However, if the attacker gains control of the required keys—or tricks the user into authorising a multi‑sig transaction—the vault can be emptied in a single sweep. The blockchain’s transparent nature records each output, so analysts can trace the flow from the original vaults to the new destination, even if the final address belongs to a mixing service or a new wallet.

What changes because of it

The immediate impact is a concentration of stolen Bitcoin in the hands of a single operator. That consolidation can make the next step—cash‑out or laundering—more visible to exchanges and monitoring services, potentially accelerating the detection of the illicit funds. At the same time, the loss of the 11 largest vaults reduces the pool of Bitcoin that remains in limbo, meaning fewer “unknown” coins to hide behind.

For the broader Coldcard community, the episode underscores two trade‑offs. On one hand, hardware wallets remain the most secure way for non‑traders to hold Bitcoin, because the private key never touches the internet. On the other hand, the human element—PIN security, device handling, and software hygiene—continues to be the weakest link. Users who rely on a single device and a single PIN for multiple vaults now face a higher risk: a breach of that PIN can expose a substantial amount of value.

What we would watch next is the flow of the $7.7 million after it left the emptied vaults. If the funds appear on major exchanges, regulators and compliance teams may flag the addresses, forcing the attacker to use more sophisticated laundering methods such as peer‑to‑peer swaps or privacy‑focused chains. Conversely, if the coins move into privacy‑oriented mixers or are split into many smaller outputs, they could disappear from public view for months, making recovery unlikely.

In practice this usually means that ordinary Coldcard owners should revisit their operational security: use strong, unique PINs, keep the device firmware up to date, and consider multi‑sig arrangements that involve separate physical devices for each required key. Those who already store large sums in a single vault may want to diversify across multiple addresses or wallets, reducing the incentive for an attacker to target one point of failure.

The takeaway is not that Coldcard is broken, but that the security chain ends at the user. The blockchain will continue to record any movement, but the human steps that enable those movements remain the most fertile ground for theft.

Sources

related