The methodical movement of stolen funds following the Coldcard hardware wallet attacks is entering a new phase. According to research from Galaxy, the attacker categorized as part of the third wave of Coldcard breaches has now moved approximately 45% of the Bitcoin they stole — a development that signals active laundering efforts and raises urgent questions about the traceability of funds that have sat dormant for months.

Galaxy's broader analysis of all three waves of Coldcard-related attacks paints a picture of largely frozen loot. Some 82% of the total Bitcoin stolen across every attack wave still sits in the original addresses where it landed after the thefts. That figure, while offering a degree of cold comfort to the broader community, also reflects the high-stakes cat-and-mouse dynamic between blockchain forensics teams and sophisticated adversaries who know that moving funds too quickly can trigger immediate identification and exchange-level blocks.

Three Waves, One Escalating Problem

The Coldcard attack narrative has unfolded in distinct phases, each representing a separate cluster of victims and, apparently, separate threat actors or coordinated groups operating with different timelines and strategies. The fact that Galaxy has segmented the incidents into at least three identifiable waves suggests that the vulnerability or social engineering vector exploited against Coldcard users was not a one-time event but rather a sustained, evolving campaign. That the third-wave attacker is now the one actively liquidating stolen holdings — having moved nearly half their cache — indicates this group may be the most operationally aggressive of the three, or simply the most recently emboldened.

The 18% of total stolen Bitcoin that has entered apparent laundering channels is the number that should concentrate the minds of exchanges, compliance teams, and regulators. On-chain funds rarely vanish cleanly. Blockchain forensics has become sophisticated enough that even layered mixing attempts leave traceable artifacts, and the 45% movement figure from the third-wave attacker will now be under intense scrutiny from tracing firms and law enforcement alike. Every hop in a laundering chain is a potential point of interdiction, and the longer these funds remain on-chain — even in intermediate wallets — the more data investigators accumulate.

What the 82% Dormancy Figure Actually Tells Us

The fact that 82% of stolen funds remain unmoved is not necessarily evidence of restraint or incompetence on the part of the attackers. In many high-profile thefts, sophisticated actors deliberately allow significant time to pass before attempting to liquidate, hoping that exchange surveillance flags expire, investigative attention fades, and new mixing or bridging infrastructure emerges that makes tracing harder. The Lazarus Group, for example, has historically sat on stolen funds for over a year before beginning to move them through mixers and cross-chain bridges. Dormancy is a tactic, not a sign that the funds are unrecoverable.

For victims, the high dormancy rate does preserve some theoretical possibility of asset recovery — particularly if law enforcement can secure freezing orders with major exchanges before the funds arrive. But that window is narrow. Once funds enter a high-volume mixing protocol or are converted into privacy coins, the practical probability of recovery drops sharply. The 18% already moving suggests that at least some attackers have decided the wait-and-see phase is over.

Hardware Wallet Security Under Renewed Scrutiny

The multi-wave nature of these attacks forces a harder conversation about the security assumptions that underpin the hardware wallet industry. Coldcard has long been regarded as one of the more security-hardened options available to self-custody Bitcoin holders — a product built explicitly for users who take operational security seriously. How attackers were able to extract private keys or seed phrases at scale across multiple distinct attack waves remains a critical open question. Whether the vector was a supply chain compromise, a targeted phishing campaign against specific user cohorts, or an exploitation of firmware-level vulnerabilities will shape how the broader industry responds.

Until a definitive technical postmortem is published, users of all hardware wallets face the uncomfortable reality that the attack surface for self-custody extends well beyond the device itself — encompassing seed phrase storage, backup procedures, physical security, and supply chain integrity. The Coldcard incidents, whatever their ultimate root cause, are a reminder that hardware wallets are a critical but not infallible layer in a defense-in-depth security stack.

What This Means

With the third-wave attacker now liquidating 45% of their stolen Bitcoin and 18% of all Coldcard attack proceeds already in apparent laundering motion, the forensics and law enforcement response enters its most consequential stage. Galaxy's on-chain surveillance data provides a real-time map of attacker behavior, but the clock is running. The 82% still sitting in original addresses will not remain there indefinitely — and as successive wave actors observe the third group moving funds without immediate consequence, the pressure to follow suit will grow. The window for recovery or interdiction is open, but it is narrowing with every confirmed transaction.

Written by the editorial team — independent journalism powered by Bitcoin News.