A hacker linked to the third wave of Coldcard wallet thefts has started moving stolen Bitcoin, using THORChain to convert part of the funds into Ethereum.
The transactions were detected on Sept. 3 by blockchain researchers monitoring addresses associated with the Coldcard exploit. Roughly 10% of the Bitcoin controlled by this particular attacker was moved through THORChain, while around 90% remained at the original addresses when the activity was reported.
Researchers have traced the swaps to a newly identified Ethereum address and shared the information with law enforcement agencies and crypto companies monitoring the stolen funds.
Coldcard hacker begins moving stolen Bitcoin
Galaxy Research’s Alex Thorn reported that an attacker associated with the third wave of Coldcard thefts had started converting stolen BTC into ETH.
The attacker used THORChain, a decentralized cross-chain liquidity protocol that allows users to swap native cryptocurrencies across different blockchain networks.
Unlike a centralized cryptocurrency exchange, THORChain can facilitate a Bitcoin-to-Ethereum swap without requiring users to deposit their assets with a traditional custodial trading platform.
According to Thorn, approximately 10% of the Bitcoin controlled by the attacker had been moved through the protocol when the activity was identified.
Around 90% remained unmoved at the original Bitcoin addresses.
Researchers were able to follow the cross-chain transactions and identify an Ethereum address receiving the resulting assets.
That address was reportedly shared with law enforcement, cryptocurrency companies and other organizations monitoring the stolen funds.
THORChain swaps reportedly faced repeated problems
The hacker’s attempt to convert the stolen Bitcoin did not appear to proceed smoothly.
According to Thorn, several THORChain swap attempts were refunded, forcing the attacker to repeatedly submit new transactions.
The exact reason for the failed transactions was not immediately confirmed.
Possible explanations could include liquidity conditions, transaction parameters or protocol-level safeguards, but researchers had not established a verified technical cause when the transfers were reported.
The activity is significant because it represented the first detected on-chain movement from the original addresses associated with the first three Coldcard attack waves.
Researchers will now be watching where the converted ETH moves next.
Potential destinations could include centralized exchanges, blockchain bridges or other crypto services.
Galaxy links 1,789 BTC to Coldcard thefts
Galaxy Research previously estimated that approximately 1,789.28 BTC across 8,865 addresses was connected to the Coldcard vulnerability.
The stolen Bitcoin was worth approximately $114.7 million at the time of the theft.
The estimate was based partly on 221 victim reports involving approximately 790.72 BTC.
Blockchain analysis identified additional potentially affected addresses beyond those directly reported by Coldcard users.
However, the overall figure remains an estimate.
Researchers have identified several attacker patterns with different levels of confidence, meaning some addresses can be linked to the vulnerability more confidently than others.
As of Aug. 25, approximately 87% of the Bitcoin identified across the broader Coldcard incident reportedly remained unmoved.
That figure covered multiple attackers and different waves of the exploit rather than only the attacker currently using THORChain.
Multiple attackers may have exploited the same vulnerability
The different movement patterns have strengthened the possibility that several attackers exploited the same Coldcard weakness.
While the latest attacker is using THORChain to convert Bitcoin into Ethereum, other wallets associated with the broader incident previously moved funds toward cryptocurrency mixers.
Blockchain security firm CertiK reported in August that wallets connected with the incident transferred approximately 64 BTC and 200 ETH toward mixers.
Separate analysis found that one attacker continued holding roughly 1,159 BTC while another began moving smaller amounts through mixing services.
The different strategies suggest that the stolen funds may not all be controlled by a single party.
Instead, multiple attackers may have independently discovered or exploited the same underlying weakness.
Cross-chain swaps make tracking more complicated
Moving cryptocurrency across blockchain networks can make investigations more difficult because researchers must follow assets through different protocols and address systems.
However, using THORChain or another cross-chain protocol does not automatically make cryptocurrency untraceable.
Transactions on public blockchains can still provide investigators with information about where assets move.
In this case, researchers were able to follow the Bitcoin swaps and identify the Ethereum address receiving the converted assets.
The next stage of tracking will depend on what happens to the ETH.
If the cryptocurrency reaches a centralized exchange, investigators could potentially have another opportunity to intervene.
Centralized exchanges generally operate identity verification, anti-money laundering and sanctions-compliance systems.
Thorn said the newly identified Ethereum address had already been distributed to relevant companies so they could watch for future deposits.
Coldcard vulnerability exposed weak wallet seeds
The Coldcard thefts were linked to a vulnerability involving weak seed generation in firmware released beginning in 2021.
A cryptocurrency wallet’s seed phrase ultimately protects access to the private keys controlling its assets.
Secure wallet generation depends heavily on randomness, or entropy, because attackers should not be able to predict the generated credentials.
The affected Coldcard firmware reportedly produced insufficient randomness for some wallet seeds.
That weakness potentially allowed attackers to calculate private keys remotely without physically accessing the hardware wallet.
This made the incident fundamentally different from typical phishing or wallet-drainer attacks.
Victims did not necessarily have to approve a malicious transaction, connect their wallet to a fraudulent website or reveal their seed phrase.
Instead, attackers could potentially derive vulnerable private keys by exploiting predictable wallet credentials and then identify funded addresses through Bitcoin’s public blockchain.
Updated Coldcard firmware does not fix old seeds
Coldcard manufacturer Coinkite has released corrected firmware for affected devices.
However, installing the updated firmware alone is not enough to secure a wallet if its existing seed was created using vulnerable software.
The firmware update can correct the seed-generation process going forward, but it cannot add randomness to a recovery phrase that has already been generated.
As a result, affected users need to migrate their funds.
Users with potentially vulnerable wallets must generate a completely new seed using corrected firmware and transfer their Bitcoin to addresses controlled by the new wallet.
Continuing to use an old vulnerable seed could leave funds exposed even after the hardware device itself has been updated.
Attacker was reportedly still scanning for vulnerable wallets
Researchers also found evidence suggesting that at least one attacker remained active after the largest theft waves had already occurred.
On Aug. 29, an address linked to the operation reportedly swept Bitcoin from a deliberately weakened wallet created by researchers.
The wallet was intentionally designed with predictable credentials to test whether attackers were still searching for vulnerable private keys.
According to Thorn, the wallet was compromised quickly.
That suggested automated scanning for predictable Bitcoin private keys remained active nearly a month after the first major Coldcard thefts.
The test also highlights the unusual nature of the vulnerability.
An attacker did not need to compromise a physical hardware wallet individually. Automated systems could potentially search for predictable keys and monitor the Bitcoin blockchain for addresses holding funds.
Hardware wallet security faces renewed scrutiny
The Coldcard incident has raised broader questions about how hardware wallets generate recovery phrases.
Hardware wallets are generally designed to keep private keys isolated from internet-connected devices.
However, strong physical security cannot compensate for weak cryptographic randomness.
If a wallet generates predictable credentials, an attacker may be able to reconstruct those credentials remotely.
That means a user could follow normal security practices, never expose their seed phrase and still remain vulnerable if the original seed-generation process was flawed.
The incident therefore demonstrates why entropy generation is one of the most critical components of cryptocurrency wallet security.
Investigators continue tracking stolen Coldcard funds
Galaxy Research and other blockchain investigators are expected to continue monitoring the newly identified Ethereum address.
A major question is whether the attacker will continue converting the remaining Bitcoin through THORChain or use other methods to move the funds.
Researchers will also watch whether the resulting ETH reaches centralized exchanges, bridges, mixers or other crypto protocols.
For now, most of the Bitcoin controlled by the third-wave attacker reportedly remains at its original addresses.
No public arrest, recovery of the stolen cryptocurrency or official identification of the attacker had been announced when the THORChain transactions were reported.
The latest movement nevertheless marks an important development because previously dormant stolen Bitcoin has begun moving across blockchains.
For affected Coldcard users, the security recommendation remains clear: installing corrected firmware is not sufficient if the wallet seed itself was generated using vulnerable software. Potentially affected funds need to be moved to a wallet created with a new, securely generated seed.












































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































