The Coldcard Hacker Just Drained 11 Vaults in a Single Wave, and 45% of Stolen Bitcoin Is Now in Motion
The attacker behind the ongoing Coldcard theft campaign has liquidated $7.7 million in Bitcoin, targeting the 11 largest vaults tied to the third wave of exploits, according to Galaxy Research.
That number alone should make every hardware wallet holder stop scrolling.
This is not a one-and-done breach. Three waves. Escalating volume. Increasingly coordinated vault targeting. Whatever method this attacker is using, it is working, and it is getting more precise with every round.
What Galaxy Research Is Actually Saying
Galaxy Research confirmed that the attacker has now fully drained the 11 largest vaults connected to the third attack wave. The 45% figure refers to how much of the total stolen Bitcoin from this wave has already been moved, meaning the attacker is actively laundering or repositioning funds in real time.
That pace matters. Fast movement after a theft typically signals the attacker knows exactly where they are going. Amateur exploits sit. Professional ones move.
CoinDesk first surfaced the story, but the deeper implication is what Galaxy's involvement signals: this incident is now being tracked at institutional research levels, not just Reddit threads.
The Coldcard Brand Problem Nobody Is Saying Out Loud
Coldcard has long carried a near-mythical reputation in the Bitcoin self-custody world. Cypherpunks swore by it. Maximalists called it the only serious option. Three attack waves later, that reputation is under genuine pressure.
The critical unknown is still the attack vector. Until researchers confirm whether these thefts exploit a hardware flaw, a firmware vulnerability, a supply chain compromise, or user-level operational security failures, every Coldcard holder is sitting with the same question: am I exposed?
That ambiguity is the most dangerous part of this story right now.
What Crypto Holders Should Actually Do Right Now
If you hold Bitcoin on a Coldcard device, three things matter immediately.
First, check whether your firmware is current and verify you sourced your device from an official, trusted channel. Supply chain attacks are real and increasingly common.
Second, watch Galaxy Research and Coldcard's official communications closely over the next 48 to 72 hours. If a fourth wave triggers, the timeline between waves is your only warning window.
Third, consider whether your current vault structure mirrors the profile being targeted. The attacker is going after the largest vaults first. High-value, single-sig cold storage setups should be reviewed immediately.
The hacker is not hiding. The funds are moving in real time. The only question is whether wave four is already in motion.