An attacker linked to thefts from vulnerable COLDCARD hardware wallets has begun swapping stolen Bitcoin for Ether through THORChain, moving about 10% of the tracked funds to a new Ethereum address while most remains in the original Bitcoin wallets. Galaxy Research attributed the thefts to weak seed-phrase generation in firmware released from 2021 through July 2026, which made affected private keys computationally predictable; continued draining of a deliberately weakened test wallet indicated automated scanning remained active.
Coinkite issued critical firmware updates 5.6.2 for COLDCARD Mk4/Mk5 and 1.5.2Q for COLDCARD Q, restoring visibility into full device entropy, adding offline seed-mixing verification, and hardening multiple device functions. Updating alone does not secure wallets whose seeds were generated by affected firmware: users must generate a new seed on patched firmware and migrate all assets to new addresses.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
An attacker associated with the third COLDCARD theft wave began converting stolen Bitcoin to Ether through THORChain. About 10% of the Bitcoin under its control was swapped, with the operations traced to a new Ethereum address shared with law enforcement and asset-tracking organizations.
COLDCARD released experimental EDGE 6.6.1X for Mk4 and 6.6.1QX for Q devices, incorporating synchronized fixes for seed entropy, USB, Virtual Disk, PSBT, BIP-322, and signing issues. The vendor said these previews were not qualified to the standard of normal releases.
An address linked to the operation withdrew Bitcoin from a deliberately weakened test wallet created by researchers, indicating that automated scanning for predictable private keys was still active.
An earlier estimate found that approximately 87% of identified Bitcoin stolen across several COLDCARD attack waves and attackers remained unmoved as of August 25.
COLDCARD's August 20 release added required user-sourced entropy during seed generation and additional security hardening.
COLDCARD stated that firmware released on July 31 corrected the seed-generation failure for newly created seeds. Previously generated seeds remained at risk and would require replacement.
Galaxy Research attributed the thefts to insufficient randomness in seed-phrase generation in COLDCARD firmware released from 2021 onward, which allegedly made private keys remotely derivable without physical access to the devices.
COLDCARD released critical firmware 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q devices, restoring visibility into device entropy, adding offline seed-mix verification, and introducing multiple USB, transaction-validation, Virtual Disk, and wallet-state hardening changes. The vendor warned that upgrading alone does not secure seeds generated by affected firmware between 2021 and July 2026; users must generate new seeds and migrate funds.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
blog.coinkite.com
Open sourcexakep.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.