← All articles
TechBearish context

Coldcard Hacker Drains $7.7M From 293 Bitcoin Vaults

A wallet tied to the Coldcard hardware hack is moving stolen bitcoin in largest-vault-first order, with roughly half the haul still untouched.

Sofia Marquez

Sofia Marquez

Regulation & Tech Editor, RefreshCoin

Tech
RefreshCoin · Market deskBrief #BTC

A hacker who exploited a Coldcard bitcoin hardware wallet flaw is now moving roughly $7.7 million in stolen funds through a sprawling network of 293 cold-storage vaults, draining them in order of size. On-chain analysts tracking the wallets say the thief is emptying the largest vaults first and leaving smaller balances for later, a deliberate pacing strategy that has so far transferred close to half of the estimated $16.4 million haul. The activity was first flagged on September 7, 2026, and has continued in batches over the following 48 hours.

How did the attacker build 293 separate vaults?

After the initial theft, the wallet operator did not consolidate funds into a single address, the standard pattern for opportunistic hackers. Instead, the stolen bitcoin was split across 293 distinct vaults, each holding a different slice of the total. Analysts say this approach creates noise on the blockchain because each vault looks like an unrelated holder, and investigators have to reconstruct the common funding source manually. The vault count alone is unusual: most laundering operations rely on a few dozen wallets at most.

Splitting funds into hundreds of addresses is also a defense against address blacklisting. When exchanges or chain analytics firms flag a known hacker address, the thief can keep moving the remaining vaults that have not yet been tagged. The 293-vault structure makes a partial freeze possible while still leaving a large share of the proceeds usable. That calculation appears to have shaped the choice to drain largest vaults first: those addresses carry the highest balance per address and therefore attract the most attention from compliance teams.

Why is the drain order significant for investigators?

The decision to empty the largest vaults first is the opposite of what a hurried thief would normally do, because smaller vaults blend in more easily and take longer to be flagged. By draining big vaults first, the operator signals confidence in the laundering pipeline behind them and a willingness to accept some short-term risk of blacklisting. On-chain researchers have used that order to predict which vault will move next and to pre-position monitoring on the receiving addresses.

This pattern also helps separate the original hacker from any secondary buyers. Anyone purchasing stolen bitcoin at a discount will typically take possession via a fresh address that has no history with the theft. If the next receiving addresses are clustered and funded by known mixing services, that points to the same operator continuing the process. If they are scattered across unrelated wallets, it suggests a sale to third parties has begun.

What is the Coldcard flaw that made the theft possible?

Coldcard is a Canadian hardware wallet brand that has been on the market since 2018 and is widely used by long-term bitcoin holders who want air-gapped signing. In early September 2026, the manufacturer disclosed a vulnerability in the Mk4 firmware that, under specific conditions, could allow an attacker with brief physical access to the device to extract seed material. The disclosure was coordinated with several wallet security researchers, and Coldcard shipped a patched firmware build within days of the public advisory.

The hack itself, which produced the 293-vault structure now being drained, is not the same as the public advisory. It appears to predate the patched build and to target devices that had not yet been updated, or to use a vector that bypasses the user's normal update path. Coldcard has not commented on the specific theft, and the identity of the victims has not been released publicly. The size of the haul, roughly $16.4 million at the time of the theft, suggests a small number of high-balance wallets rather than a broad consumer attack.

How does this fit the wider pattern of crypto theft in 2026?

Crypto theft in 2026 has been dominated by a small number of large incidents rather than a long tail of small scams, according to public on-chain data. Theft campaigns increasingly rely on multi-stage laundering pipelines that split funds, mix them across services, and slowly reintroduce them into regulated exchanges through long, low-value transfers. The 293-vault structure is consistent with that approach: it trades immediate speed for a longer window during which each individual transfer is harder to flag.

The vault-drain order also mirrors what analysts call the third-wave pattern, where attackers wait weeks or months between the theft and the first movement to let compliance attention fade. The Coldcard hacker waited roughly that window before starting to move funds, and the largest-first drain is a documented refinement of that playbook. Each successful third-wave drain that cashes out without freezing raises the bar for the next one, which is why on-chain researchers pay close attention to the order in which vaults are emptied.

What are the on-chain signals traders and analysts are watching now?

The next 48 to 72 hours are likely to determine the pace of the drain. Analysts are watching for any consolidation transaction that combines outputs from multiple vaults into a single wallet, a classic signal that the operator is preparing the next stage of laundering. They are also monitoring known mixing services and cross-chain bridges for inbound transfers from the new addresses, since converting bitcoin to other assets through a bridge is a common step before attempting to cash out through exchanges with weaker compliance.

A second watch item is the behavior of exchanges that receive deposits from the new addresses. If major platforms freeze incoming funds tied to the hack, the thief may shift to smaller, less compliant venues, which would slow the drain but also fragment it further. If deposits are accepted, the drain could accelerate sharply and the remaining roughly $8.7 million could move in a matter of days. On-chain dashboards from firms such as Glassnode, Chainalysis, and Elliptic are being updated in near real time as new vault drains are confirmed.

What does this mean for hardware wallet users?

For hardware wallet users, the incident is a reminder that firmware updates are the primary defense against known attack vectors, and that delayed updates leave a window of exposure. The Coldcard advisory has already pushed several wallet makers to review their own update paths and to publish guidance on how to verify that a device is running patched firmware. Users with older devices that have not been updated since early September 2026 are being urged to update before receiving or signing any new transactions.

The incident is also a test case for how the hardware wallet industry communicates coordinated disclosures. Coldcard released a public advisory within days of the vulnerability being confirmed, which set a faster pace than some prior wallet disclosures that took weeks. That speed has been credited with limiting the blast radius of the broader vulnerability, even though it did not stop the specific theft that produced the 293-vault haul. The next test will be whether the remaining funds are recovered, frozen, or successfully laundered.

What to watch next in the Coldcard hack?

Three concrete signals will tell traders and investigators how the story is developing. First, the pace of vault drains: if the largest-first pattern continues, the next batch of vaults to move will be in the 50 to 100 BTC range, and the receiving addresses will likely be cluster-linked. Second, any exchange announcement of frozen deposits tied to the hack, which would mark the first successful intervention and could force the operator to reroute the remaining funds. Third, any public attribution, either from law enforcement or from the wallet manufacturer, that names a suspect or recovers a portion of the stolen bitcoin.

Beyond those near-term signals, the longer-term question is whether the third-wave playbook used here becomes a template for future hardware wallet thefts. If the remaining roughly $8.7 million is cashed out successfully, the incentives for similar attacks rise, and other wallet makers will face pressure to harden their supply chains and update verification. If the funds are largely frozen or recovered, the deterrent effect is significant. For now, the drain continues, vault by vault, in strict size order.

Mentioned in this article

Frequently asked questions

How much bitcoin has the Coldcard hacker already moved?

Roughly $7.7 million worth of bitcoin has been moved out of the largest vaults as of early September 2026. That represents close to half of the estimated $16.4 million total haul, with the remainder still sitting in the smaller vaults waiting to be drained.

Why are the vaults being drained in size order?

Draining the largest vaults first allows the attacker to move the most heavily watched balances while compliance attention is still fresh, then rely on slower scrutiny for the smaller vaults later. It also signals confidence in a laundering pipeline behind the new addresses.

Is the Coldcard vulnerability still active?

Coldcard shipped a patched firmware build shortly after disclosing the Mk4 vulnerability in early September 2026. Devices that have been updated are not affected, but devices that have not been updated since the advisory remain exposed to the original attack vector.

Comments(0)

No comments yet. Be the first to weigh in.

Related reading