COLDCARD hardware wallet between Bitcoin-orange and Ether-blue light trails

Coldcard Attacker Starts Moving Stolen Bitcoin Through THORChain Into Ether

September 3, 2026 11:16 am Comments

The attacker tied to the third wave of Coldcard wallet thefts has started moving Bitcoin from the original theft addresses, and the route is getting attention for a reason: part of the haul is being swapped into Ether through THORChain.

The transfer marks the first observed movement out of the original attacker addresses across the three documented waves, according to on-chain researcher Alex Thorn.

Cointelegraph says the Wave 3 attacker moved roughly 10% of that wave’s funds while about 90% remained untouched, with researchers following the activity through THORChain to a newly identified Ethereum address; Galaxy Digital research chief Alex Thorn described the transaction as the first time funds from any of the three waves had left the original hacker addresses, turning a dormant theft trail into an active cross-chain investigation. The report also says the attacker struggled to complete every swap, received refunds on some attempts, tried again, and left investigators with both the remaining Bitcoin addresses and a fresh Ethereum destination to monitor as the stolen assets moved from storage toward possible liquidation, while Thorn shared the destination information with relevant authorities and crypto companies that could encounter the funds later; the swaps therefore created new surveillance points without resolving the larger theft or moving the majority of the stolen balance still under observation, and each retry now gives analysts another transaction path, timing signal, service interaction, and potential exchange deposit to compare against the known theft clusters as the case develops, including whether the attacker consolidates the Ether, bridges again, or tests a centralized service with identity controls.

The next movement could show whether those newly identified monitoring points create a practical choke point.

The timing also separates this event from the original theft itself: the keys were compromised earlier, the funds remained parked, and the reported THORChain activity now marks a distinct cash-out phase. That distinction matters because investigators can compare the attacker’s new operational choices with the original address clusters instead of treating every balance as static evidence.

The Crypto Times put the amount routed into the swap process at about 20.5 BTC. Its report said payouts landed on Ethereum, while repeated refunds showed that moving stolen funds across chains is not always as frictionless as a block explorer’s final balance can make it look.

THORChain allows users to exchange native assets across different blockchains without first handing them to a centralized exchange. That makes it useful for ordinary traders who want direct cross-chain liquidity, but the same open design can also attract anyone trying to move assets without immediately entering a conventional exchange account.

THORChain did not cause the theft and does not control the attacker. The route still leaves a public trail, allowing researchers to follow the Bitcoin movement and identify where the Ether arrived.

Thorn said the destination information was shared with relevant authorities and crypto companies. That creates a new set of monitoring points if the attacker tries to move the Ether again, bridge it elsewhere, or send it toward a service with account controls.

The Coldcard thefts have been linked to weak wallet entropy, the randomness used when private keys are generated. If an attacker can narrow the possible key space enough, an offline wallet is no longer protected simply because it never connected to the internet.

Thorn highlighted continuing activity in a separate update, including a case involving keys generated with only five dice rolls of added entropy.

The lesson is uncomfortable but useful: self-custody removes one kind of counterparty risk while leaving seed generation, firmware provenance, backup handling, and sufficient entropy squarely on the owner. A hardware wallet cannot rescue a private key that was predictable from the start.

Most of the Wave 3 funds were still sitting in the original locations when the movement was reported. Researchers now have both the remaining Bitcoin and the newly identified Ethereum destination to watch.

Every attempted exit creates more evidence for investigators, even though an observable trail does not guarantee recovery for affected users. Funds beginning to move through cross-chain routes reveal behavior that a dormant balance could not.

The next question is whether the attacker can move beyond testing small portions without hitting more refunds, surveillance, or service-level controls. The answer will show how much practical freedom the stolen Bitcoin really has after leaving its original addresses.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.