190 Victims. 1,779 BTC. And the Exploiter Just Cashed Out Nearly Half.

The attacker behind the so-called 'Wave 3' Coldcard exploit has moved 45% of stolen funds, according to fresh data from Galaxy Research, signaling that one of Bitcoin's most damaging hardware wallet attacks is now entering a laundering phase that could get much harder to trace.

Galaxy's mid-August findings put the total damage at roughly 1,779 BTC drained from 190 confirmed victims across more than 8,600 addresses. At current prices, that's tens of millions of dollars sitting in the hands of someone who has already decided to start moving it.

Why This Attack Hit Different

Coldcard is not some obscure no-name wallet. It is one of the most respected Bitcoin hardware wallets in existence, favored specifically by users who take self-custody seriously. These were not casual holders who reused passwords or clicked phishing links. Many of them followed best practices, which makes the 'Wave 3' attack particularly alarming for the broader Bitcoin security narrative.

The attack methodology has not been fully disclosed publicly, and Galaxy's investigation is ongoing. What is confirmed is the scale: 8,600-plus addresses compromised across nearly 200 victims is not a targeted hit. This was systematic.

The 45% Movement Is the Real Alert

When stolen funds sit still, they are traceable and potentially freezable through exchange cooperation. When they move, the clock starts. Experienced crypto thieves use a combination of mixers, chain-hops, and peer-to-peer markets to break the on-chain trail before cashing out.

The fact that nearly half the stolen BTC is already in motion means the window for on-chain recovery is closing fast. Galaxy flagging this publicly suggests the firm is either coordinating with exchanges to flag incoming deposits or issuing a warning to the market that these coins are about to enter circulation.

Either way, 45% moved means 55% has not. The second wave of movement could come at any time.

What Holders Should Watch Right Now

If you use a Coldcard or any hardware wallet that was active during the period Galaxy identifies as 'Wave 3,' audit your addresses now against any published victim lists as they become available. Do not wait for confirmation.

More broadly, this attack is a reminder that hardware wallets eliminate one threat vector, not all of them. Supply chain integrity, seed phrase generation, and firmware verification matter just as much as the device itself.

Watch for Galaxy's full report. If the remaining 55% starts moving, on-chain analysts will be tracking every hop. The exploiter knows that too, which means the next move will likely be their most sophisticated one yet.