Coldcard hack 2026: Wave 3 thief tests THORChain with 20.5 stolen BTC

On 2 September 2026 the Coldcard “Wave 3” thief moved 20.50 BTC through THORChain to a new Ethereum address and kept getting refunded — the first on-chain movement from the ~1,816 BTC stolen in July and August.

Voxel shield in bitcoin orange with a white ₿ sign, cracked diagonally, with debris cubes flying on a dark background

For a month the bitcoin stolen from Coldcard users sat in the attackers’ original addresses. On 2 September some of it moved. Coins from the original attacker addresses of the theft’s “Wave 3” started flowing through THORChain toward Ethereum — the first known on-chain movement from any wave’s original addresses, flagged on 3 September by Galaxy’s Alex Thorn.

The amount is small next to the total: 20.50 BTC out of roughly 1,816 BTC taken between 30 July and 4 August. But it tells you two things. The thief is now testing exit routes. And the root cause — a seed that was never as random as its owner believed — is still sitting in wallets that haven’t been migrated.

Key facts

  • On 2 September 2026, about 10% of the Coldcard theft’s “Wave 3” funds — 20.50 BTC — moved through THORChain to a new Ethereum address, the first known movement from any wave’s original attacker addresses.
  • Galaxy’s Alex Thorn flagged the movement on 3 September and said the attacker appeared to be having trouble swapping and kept getting refunded.
  • The flaw traces to a March 2021 Coldcard firmware build (4.0.1, per TRM Labs) that fell back on a weak software random number generator, cutting seed strength from 128 bits to as little as about 40 bits.
  • Between 30 July and 4 August 2026, attackers drained about 1,816 BTC (~$116M) according to TRM Labs; TFTC counts at least 1,789 BTC (~$114.7M).
  • Reported affected models are the Coldcard Mk3, Mk4, Mk5 and Q.
  • TRM Labs says any seed generated on the vulnerable firmware should be treated as compromised; a firmware update does not fix an existing seed.

What happened to the stolen Coldcard bitcoin on September 3?

On 2 September the attacker behind “Wave 3” of the Coldcard theft began moving coins, sending 20.50 BTC — about 10% of that wave’s haul — through THORChain to a fresh Ethereum address. It was the first known on-chain movement from the original attacker addresses of any wave, and Galaxy’s Alex Thorn flagged it on 3 September.

It didn’t go smoothly. Galaxy said the attacker “appears to be having some issues swapping” and kept getting refunded, with repeated attempts bouncing back. As TFTC reported, the pattern looks less like a full cash-out and more like a route test: push a slice through, see what fails, retry. AMBCrypto likewise framed the movement as an apparent first step toward laundering.

The remaining roughly 90% of Wave 3, and the funds from the other waves, had not moved from the original addresses as of 3 September.

How did the Coldcard seeds get cracked?

The seeds were weak from birth. According to TRM Labs, a March 2021 Coldcard firmware build, version 4.0.1, used a weak software random number generator instead of proper hardware entropy. That cut effective key strength from 128 bits to as little as about 40 bits, low enough to brute-force seeds without ever touching the device.

That’s the uncomfortable part for anyone who treats a hardware wallet as a vault. No device had to be stolen and no PIN had to be guessed. The attacker simply searched a key space that was far smaller than it should have been, then swept every matching address — about 1,816 BTC (~$116M) between 30 July and 4 August, per TRM. TFTC puts the figure at no less than 1,789 BTC (~$114.7M). Reported affected models are the Mk3, Mk4, Mk5 and Q.

A hardware wallet is only as strong as the randomness of its seed.

What should you do if you generated a seed on affected firmware?

Treat the seed as compromised and move the funds. TRM Labs is explicit that updating the firmware doesn’t fix an existing seed: it only stops new weak seeds being created. Generate a brand-new seed on updated hardware, verify the new wallet fingerprint, send a small test transaction, then migrate the rest.

  • Don’t wait to be next. If your seed dates from the vulnerable firmware and hasn’t been drained, that’s not proof it’s safe — only that it hasn’t been reached yet.
  • Don’t reuse the old seed anywhere. Importing it into a different wallet doesn’t add entropy.
  • Consider multisig across vendors. A 2-of-3 setup with devices from different makers would not have been drained by a single vendor’s RNG bug, because one weak key isn’t enough to spend.
  • Revisit your storage plan. Our guides to the best Bitcoin wallets in 2026 and hardware, paper and metal cold storage cover the options.

Why do thieves test cross-chain swap routes?

Because converting BTC into another asset on another chain is the first step to breaking an obvious trail, and every route has failure points. A small test shows whether a route executes, how it prices, and whether anyone blocks it. The repeated THORChain refunds suggest this first route didn’t work cleanly.

Refunds matter here in a way most users never see. When a cross-chain swap can’t be executed within its limits, the funds go back to the sender instead of disappearing, which is exactly what a legitimate user wants — and exactly what frustrated this attacker.

What this means for swap users

Cross-chain routes are public infrastructure, and after a theft this size their operators, and analytics firms, watch for the stolen coins. The licensed providers that SwapZilla routes through screen incoming deposits, and funds linked to a known theft can be flagged and held for review; our AML policy explains how that works.

For ordinary users the takeaway is practical. Swap from coins you control with a clean history, always set a refund address so a failed swap comes back to you, and if you’re migrating off a weak Coldcard seed, move directly to your new wallet first — swap later, not in the same rush.

Meanwhile, the broader market had a strong day. Bitcoin rallied on 3 September from about $77,300 at the open to roughly $81,200–81,500 by the evening, up about 5.5%, after Fed Governor Christopher Waller said he’d back holding rates if CPI shows progress; odds of a September hike fell from about 70% to about 48%. Context, not a forecast.

Final thoughts

The Coldcard theft isn’t a story about a bad device design so much as a bad input. Self-custody depends on a seed nobody else can guess, and for some users that assumption quietly failed in 2021.

Your keys, your coins — but only if your keys were truly random.

If your seed came from the vulnerable firmware, the fix isn’t an update. It’s a new seed, and ideally a setup where no single vendor’s mistake can empty it.

FAQ

What is the Coldcard hack of 2026?
The Coldcard hack is the theft of about 1,816 BTC (~$116M, per TRM Labs) from Coldcard users between 30 July and 4 August 2026. A March 2021 firmware build, version 4.0.1, used a weak software random number generator, cutting seed strength from 128 bits to as little as about 40 bits. Attackers brute-forced affected seeds without physical access. TFTC counts at least 1,789 BTC (~$114.7M) stolen.
Where did the stolen Coldcard bitcoin go?
On 2 September 2026 about 10% of the Coldcard theft’s Wave 3 funds, 20.50 BTC, moved through THORChain to a new Ethereum address. Galaxy’s Alex Thorn flagged it on 3 September as the first known movement from any wave’s original attacker addresses and said the attacker kept getting refunded while trying to swap, which looks like a test of the route. The rest of the stolen BTC had not moved as of 3 September.
Which Coldcard models are affected by the weak seed bug?
Reported affected models are the Coldcard Mk3, Mk4, Mk5 and Q. The flaw traces to a March 2021 firmware build, version 4.0.1 according to TRM Labs, which used a weak software random number generator for seed creation. What matters is whether your seed was generated on the vulnerable firmware; TRM Labs says any such seed should be treated as compromised, whichever model it now sits on.
Does updating Coldcard firmware make my wallet safe?
No. According to TRM Labs, updating Coldcard firmware only stops new weak seeds from being generated; it does not fix a seed created on the vulnerable firmware from March 2021. If your seed came from that firmware, generate a new seed on updated hardware, verify the new wallet fingerprint, send a small test transaction and then move all funds. Around 1,816 BTC had already been drained this way by August 2026.
Would multisig have protected against the Coldcard RNG bug?
A 2-of-3 multisig with signing devices from different manufacturers would not have been drained by the Coldcard RNG bug alone, because one weak key is not enough to spend. The 2026 Coldcard theft of about 1,816 BTC exploited single-signature seeds generated with weak randomness. Spreading keys across vendors means a single firmware flaw at one maker cannot empty the wallet on its own.