etc. Let's craft the article. Title: "Coldcard Exploiter Moves 45% of Stolen Funds, Galaxy Research Says" or something like that. But we need to be specific: "Exploiter Behind Coldcard Wave 3 Moves 45% of Stolen Coins" - but we have to include the entity? The facts say "The exploiter linked to the third wave of attacks on Coldcard wallets has moved 45% of the coins stolen, according to Galaxy Research." So title: "Coldcard Wave 3 Exploiter Moves 45% of Stolen Funds, Galaxy Research Says" - that's good. Slug: coldcard-wave3-exploiter-moves-45-percent-stolen-funds Subtitle: "The attacker is laundering through THORChain and Coinjoin, with 82% of all stolen funds still sitting in attacker-controlled addresses." Meta description: "Galaxy Research says the Coldcard Wave 3 exploiter has moved 45% of stolen coins, using THORChain and Coinjoin. 82% of all stolen funds remain unmoved." Keywords: Coldcard, exploit, Galaxy Research, THORChain, Coinjoin, Bitcoin, laundering Focus keyword: Coldcard exploit Now content. Let's write. Lead: "The attacker behind the third wave of Coldcard wallet exploits has moved 45% of the coins they stole, according to Galaxy Research. The funds are being laundered through THORChain to Ethereum and into Coinjoin rounds, a sign the operator is actively trying to cash out. The movement comes as the broader attack, which began July 30, 2026, continues to be untangled." That's 3 sentences. Section 1: "How the funds are moving" - details. "Galaxy Research tracked the transfers and found the exploiter created 293 2-of-2 multisig vaults for victims' coins during Wave 3. The first movements on September 2 sent funds through THORChain to Ethereum, while the latest activity has moved into Coinjoin rounds. The operator has been systematically spending the largest share of thefts according to size ranking; ranks 1 through 11 have already been moved." Section 2: "What's still at stake" - the remaining funds. "The next 10 unmoved vaults contain 30.81 BTC, while ranks 61 through 293 hold a combined 33.77 units. Galaxy also identified a previously unknown vault linked to 58 addresses likely associated with Coldcard victims. Across all waves, approximately 82% of stolen funds are still held in attacker-controlled addresses; the remaining 18% has been moved, linked to laundering efforts." Section 3: "The flaw that made it possible" - background. "The attack exploited a firmware flaw that had existed for years. It came from a March 2021 update and a build error, making wallets use a weak software random generator instead of a hardware-based source. That weakened seed security from 128 bits to as low as 40 bits on older devices, allowing attackers to brute-force keys without physical access." Section 4: "Market reaction" - Bitcoin activity. "Bitcoin activity jumped sharply after the exploit as affected users moved and consolidated holdings, pushing active addresses to an eight-month high. The incident had negligible impact on BTC price; BTC rallied near $82,000 last month, then pulled back to near $79,500 at the time of writing." Ending: "With ranks 1 through 11 already moved, the next 10 unmoved vaults holding 30.81 BTC are the likely next targets. Galaxy Research says it will continue tracking the addresses." But we don't have that quote. We can say "The next 10 unmoved vaults hold 30.81 BTC, meaning the attacker is likely to move them next." That's a reasonable inference. Or we can say "The attacker's pattern suggests they will continue moving the largest vaults first." That's fine. We need to avoid saying "Galaxy Research says" as a quote, but we can attribute the findings. We can say "Galaxy Research found" or "according to Galaxy Research" in the lead. Let's write the content in HTML. We need to ensure word count 450-700. Let's count. We'll write the lead, then sections. Let's draft: The attacker behind the third wave of Coldcard wallet exploits has moved 45% of the coins they stole, according to Galaxy Research. The funds are being laundered through THORChain to Ethereum and into Coinjoin rounds, a sign the operator is actively trying to cash out. The movement comes as the broader attack, which began July 30, 2026, continues to be untangled.
How the funds are moving
Galaxy Research tracked the transfers and found the exploiter created 293 2-of-2 multisig vaults for victims' coins during Wave 3. The first movements on September 2 sent funds through THORChain to Ethereum, while the latest activity has moved into Coinjoin rounds. The operator has been systematically spending the largest share of thefts according to size ranking; ranks 1 through 11 have already been moved.
What's still at stake
The next 10 unmoved vaults contain 30.81 BTC, while ranks 61 through 293 hold a combined 33.77 units. Galaxy also identified a previously unknown vault linked to 58 addresses likely associated with Coldcard victims. Across all waves, approximately 82% of stolen funds are still held in attacker-controlled addresses; the remaining 18% has been moved, linked to laundering efforts.
The flaw that made it possible
The attack exploited a firmware flaw that had existed for years. It came from a March 2021 update and a build error, making wallets use a weak software random generator instead of a hardware-based source. That weakened seed security from 128 bits to as low as 40 bits on older devices, allowing attackers to brute-force keys without physical access.
Market reaction
Bitcoin activity jumped sharply after the exploit as affected users moved and consolidated holdings, pushing active addresses to an eight-month high. The incident had negligible impact on BTC price; BTC rallied near $82,000 last month, then pulled back to near $79,500 at the time of writing.
With ranks 1 through 11 already moved, the next 10 unmoved vaults holding 30.81 BTC are the likely next targets. The attacker's pattern suggests they will continue moving the largest vaults first.
The attacker behind the third wave of Coldcard wallet exploits has moved 45% of the coins they stole, according to Galaxy Research. The funds are being laundered through THORChain to Ethereum and into Coinjoin rounds, a sign the operator is actively trying to cash out. The movement comes as the broader attack, which began July 30, 2026, continues to be untangled.
How the funds are moving
Galaxy Research tracked the transfers and found the exploiter created 293 2-of-2 multisig vaults for victims' coins during Wave 3. The first movements on September 2 sent funds through THORChain to Ethereum, while the latest activity has moved into Coinjoin rounds. The operator has been systematically spending the largest share of thefts according to size ranking; ranks 1 through 11 have already been moved.
What's still at stake
The next 10 unmoved vaults contain 30.81 BTC, while ranks 61 through 293 hold a combined 33.77 units. Galaxy also identified a previously unknown vault linked to 58 addresses likely associated with Coldcard victims. Across all waves, approximately 82% of stolen funds are still held in attacker-controlled addresses; the remaining 18% has been moved, linked to laundering efforts.
The flaw that made it possible
The attack exploited a firmware flaw that had existed for years. It came from a March 2021 update and a build error, making wallets use a weak software random generator instead of a hardware-based source. That weakened seed security from 128 bits to as low as 40 bits on older devices, allowing attackers to brute-force keys without physical access.
Market reaction
Bitcoin activity jumped sharply after the exploit as affected users moved and consolidated holdings, pushing active addresses to an eight-month high. The incident had negligible impact on BTC price; BTC rallied near $82,000 last month, then pulled back to near $79,500 at the time of writing.
With ranks 1 through 11 already moved, the next 10 unmoved vaults holding 30.81 BTC are the likely next targets. The attacker's pattern suggests they will continue moving the largest vaults first.



