For a month the bitcoin stolen from Coldcard users sat in the attackers’ original addresses. On 2 September some of it moved. Coins from the original attacker addresses of the theft’s “Wave 3” started flowing through THORChain toward Ethereum — the first known on-chain movement from any wave’s original addresses, flagged on 3 September by Galaxy’s Alex Thorn.
The amount is small next to the total: 20.50 BTC out of roughly 1,816 BTC taken between 30 July and 4 August. But it tells you two things. The thief is now testing exit routes. And the root cause — a seed that was never as random as its owner believed — is still sitting in wallets that haven’t been migrated.
Key facts
- On 2 September 2026, about 10% of the Coldcard theft’s “Wave 3” funds — 20.50 BTC — moved through THORChain to a new Ethereum address, the first known movement from any wave’s original attacker addresses.
- Galaxy’s Alex Thorn flagged the movement on 3 September and said the attacker appeared to be having trouble swapping and kept getting refunded.
- The flaw traces to a March 2021 Coldcard firmware build (4.0.1, per TRM Labs) that fell back on a weak software random number generator, cutting seed strength from 128 bits to as little as about 40 bits.
- Between 30 July and 4 August 2026, attackers drained about 1,816 BTC (~$116M) according to TRM Labs; TFTC counts at least 1,789 BTC (~$114.7M).
- Reported affected models are the Coldcard Mk3, Mk4, Mk5 and Q.
- TRM Labs says any seed generated on the vulnerable firmware should be treated as compromised; a firmware update does not fix an existing seed.
What happened to the stolen Coldcard bitcoin on September 3?
On 2 September the attacker behind “Wave 3” of the Coldcard theft began moving coins, sending 20.50 BTC — about 10% of that wave’s haul — through THORChain to a fresh Ethereum address. It was the first known on-chain movement from the original attacker addresses of any wave, and Galaxy’s Alex Thorn flagged it on 3 September.
It didn’t go smoothly. Galaxy said the attacker “appears to be having some issues swapping” and kept getting refunded, with repeated attempts bouncing back. As TFTC reported, the pattern looks less like a full cash-out and more like a route test: push a slice through, see what fails, retry. AMBCrypto likewise framed the movement as an apparent first step toward laundering.
The remaining roughly 90% of Wave 3, and the funds from the other waves, had not moved from the original addresses as of 3 September.
How did the Coldcard seeds get cracked?
The seeds were weak from birth. According to TRM Labs, a March 2021 Coldcard firmware build, version 4.0.1, used a weak software random number generator instead of proper hardware entropy. That cut effective key strength from 128 bits to as little as about 40 bits, low enough to brute-force seeds without ever touching the device.
That’s the uncomfortable part for anyone who treats a hardware wallet as a vault. No device had to be stolen and no PIN had to be guessed. The attacker simply searched a key space that was far smaller than it should have been, then swept every matching address — about 1,816 BTC (~$116M) between 30 July and 4 August, per TRM. TFTC puts the figure at no less than 1,789 BTC (~$114.7M). Reported affected models are the Mk3, Mk4, Mk5 and Q.
A hardware wallet is only as strong as the randomness of its seed.
What should you do if you generated a seed on affected firmware?
Treat the seed as compromised and move the funds. TRM Labs is explicit that updating the firmware doesn’t fix an existing seed: it only stops new weak seeds being created. Generate a brand-new seed on updated hardware, verify the new wallet fingerprint, send a small test transaction, then migrate the rest.
- Don’t wait to be next. If your seed dates from the vulnerable firmware and hasn’t been drained, that’s not proof it’s safe — only that it hasn’t been reached yet.
- Don’t reuse the old seed anywhere. Importing it into a different wallet doesn’t add entropy.
- Consider multisig across vendors. A 2-of-3 setup with devices from different makers would not have been drained by a single vendor’s RNG bug, because one weak key isn’t enough to spend.
- Revisit your storage plan. Our guides to the best Bitcoin wallets in 2026 and hardware, paper and metal cold storage cover the options.
Why do thieves test cross-chain swap routes?
Because converting BTC into another asset on another chain is the first step to breaking an obvious trail, and every route has failure points. A small test shows whether a route executes, how it prices, and whether anyone blocks it. The repeated THORChain refunds suggest this first route didn’t work cleanly.
Refunds matter here in a way most users never see. When a cross-chain swap can’t be executed within its limits, the funds go back to the sender instead of disappearing, which is exactly what a legitimate user wants — and exactly what frustrated this attacker.
What this means for swap users
Cross-chain routes are public infrastructure, and after a theft this size their operators, and analytics firms, watch for the stolen coins. The licensed providers that SwapZilla routes through screen incoming deposits, and funds linked to a known theft can be flagged and held for review; our AML policy explains how that works.
For ordinary users the takeaway is practical. Swap from coins you control with a clean history, always set a refund address so a failed swap comes back to you, and if you’re migrating off a weak Coldcard seed, move directly to your new wallet first — swap later, not in the same rush.
Meanwhile, the broader market had a strong day. Bitcoin rallied on 3 September from about $77,300 at the open to roughly $81,200–81,500 by the evening, up about 5.5%, after Fed Governor Christopher Waller said he’d back holding rates if CPI shows progress; odds of a September hike fell from about 70% to about 48%. Context, not a forecast.
Final thoughts
The Coldcard theft isn’t a story about a bad device design so much as a bad input. Self-custody depends on a seed nobody else can guess, and for some users that assumption quietly failed in 2021.
Your keys, your coins — but only if your keys were truly random.
If your seed came from the vulnerable firmware, the fix isn’t an update. It’s a new seed, and ideally a setup where no single vendor’s mistake can empty it.