The attacker associated with the third wave of Coldcard wallet thefts has begun moving more bitcoin, routing earlier transfers through THORChain to Ethereum and sending newer movements into CoinJoin rounds. Galaxy Research described the activity in a Sept. 7 on-chain update and said the exploiter had created 293 two-of-two multisignature vaults for victims’ coins.
The update documents wallet behavior, not the attacker’s identity or intent. Moving funds through cross-chain infrastructure and collaborative Bitcoin transactions can complicate tracing, but it does not by itself prove that the proceeds have been successfully laundered.
Wave 3 funds start leaving their vaults
Galaxy said the first movements in this wave occurred on Sept. 2, when coins were sent through THORChain and arrived on Ethereum. The research firm then observed subsequent transfers entering CoinJoin rounds. Its public post did not provide a final amount moved or say that every vault had been emptied.
A CoinJoin combines inputs and outputs from multiple participants in one Bitcoin transaction. That construction makes straightforward transaction-graph analysis more difficult because an observer cannot simply assume that each input maps to a specific output. Investigators can still use timing, amounts and later spending behavior, but confidence in attribution can fall.
The latest movement follows the larger Coldcard incident
Galaxy previously connected the third wave to hundreds of attacker-created vaults. Earlier reporting on the Coldcard exploit and affected bitcoin described a broader theft involving compromised wallet generation. The newest transfers change the case from largely stationary holdings to an active tracing problem.
THORChain and CoinJoin play different roles in that path. THORChain enables swaps across native assets, while CoinJoin operates within Bitcoin by combining transactions. Neither tool is inherently malicious; the relevance here comes from their observed use by addresses Galaxy associates with the exploiter.
Wallet remediation remains separate from fund tracing
Following stolen funds does not repair a compromised seed. Users affected by weak wallet generation must create a fresh seed with corrected software or trusted hardware and transfer remaining assets. Simply installing new firmware cannot make an already exposed recovery phrase secret again.
Galaxy’s update gives investigators a new sequence to monitor, but recovery is not guaranteed. Any definitive claim about attribution, the amount mixed or the destination of swapped assets will require additional on-chain evidence and, potentially, information from services that receive the funds.


