The attacker behind the Coldcard hardware wallet breach has moved roughly $7.7 million in stolen Bitcoin, close to half of the funds tied to the most recent wave of the theft, according to Decrypt. Rather than dumping the coins in a single sweep, the attacker split the haul into 293 separate on-chain vaults and is now emptying them in order of size, starting with the largest.
That structure is the detail worth paying attention to. It points to a patient, scripted operation rather than a smash-and-grab.
A theft being unwound in stages
The movement disclosed this week is described as roughly half of a "third wave" of stolen Bitcoin, which means the funds are being processed in tranches rather than all at once. Building 293 distinct vaults and draining them sequentially is not how a rushed thief behaves. It is closer to how a treasury desk manages an inventory of positions: segment the holdings, then work through them on a schedule.
Ordering the withdrawals by size, largest first, is a rational choice for someone trying to realize value before defenders can react. The biggest vaults carry the most exposure to freezes, blacklisting, or coordinated tracing, so clearing them early locks in the largest share of the proceeds while the trail is still fresh.
At current prices, the sums are meaningful. Bitcoin traded around $79,395 as of September 7, 2026, down about 0.7% on the day, so the $7.7 million figure reflects real spot value rather than a paper estimate from a prior high.
A hardware wallet secures keys, not decisions
Coldcard is an air-gapped hardware wallet, one of the tools most often recommended to people who want to hold Bitcoin in self-custody instead of leaving it on an exchange. The device is built to keep private keys offline and away from an internet-connected computer. That design does its job well against remote key extraction.
What a hardware wallet cannot do is override the person authorizing a transaction. If an attacker obtains the seed phrase, tricks the owner into signing, or compromises the surrounding setup, the offline key material stops being a barrier. The device signs what it is told to sign. This case is a reminder that custody hardware narrows the attack surface but does not remove the human and operational layers around it.
The same logic applies to any hardware brand. A device from Ledger or any competitor faces the identical boundary: the silicon protects the key, not the workflow, the backup, or the moment of approval.
Reading the on-chain choreography
The 293-vault structure also complicates recovery. Spreading funds across hundreds of addresses forces investigators and any white-hat responders to track many parallel flows instead of one, and sequential draining means the window to freeze or claw back funds shrinks with each cleared vault. It is a deliberate obstacle to the kind of coordinated response that has, in other incidents this year, recovered large sums before they could be laundered.
For holders, the practical takeaways are narrow but concrete. Seed phrase hygiene, verifying the receiving address on the device screen itself, and treating any prompt to re-enter or "validate" a recovery phrase as hostile remain the controls that matter most. None of that is new advice. Incidents like this are what turn it from boilerplate into something worth acting on.
Overview
An attacker tied to the Coldcard breach has moved about $7.7 million in Bitcoin, roughly half of a third wave of stolen funds, by splitting the proceeds into 293 vaults and draining them largest-first. The methodical structure signals a scripted operation and makes coordinated recovery harder. The episode underscores a durable point about self-custody: hardware wallets protect keys extremely well, but the person and process controlling those keys remain the real perimeter. With Bitcoin near $79,395 as of September 7, 2026, the amounts in motion are material, and the sequential draining leaves a shrinking window for any response.



