A hacker linked to the third wave of the Coldcard hardware wallet exploit has begun moving stolen Bitcoin by swapping a portion of the funds into Ether through THORChain. The activity marks the first on-chain movement from the original attacker addresses associated with the main waves of the thefts.
Galaxy Research’s Alex Thorn reported that roughly 10% of the Wave 3 funds were swapped, while the majority remained untouched. The transfers were traced to a new Ethereum address.
The Drivers of This Development
The underlying Coldcard incident stemmed from a firmware vulnerability dating to a 2021 build error that caused insufficient entropy in seed generation on affected devices. Attackers regenerated private keys and systematically drained vulnerable addresses beginning in late July 2026, with total confirmed losses exceeding 1,700 BTC across multiple waves. For weeks, the bulk of the stolen Bitcoin sat dormant in attacker-controlled addresses. The recent use of THORChain, a cross-chain decentralized exchange, represents an initial step toward converting and potentially obfuscating a portion of the proceeds. The hacker encountered technical difficulties, including refunds that required repeated swap attempts. For perspective, most of the stolen funds from the primary waves had remained static until this movement, limiting earlier laundering activity to smaller or separate flows.
It is important to note the fundamental difference between simply holding stolen assets in known addresses and actively routing them through decentralized cross-chain protocols: the latter introduces additional complexity for tracing while still leaving on-chain footprints that analysts can follow.
Impact and Broader Context
The swaps convert a slice of the ill-gotten Bitcoin into Ether and shift it to a new address, potentially preparing the funds for further mixing, bridging, or eventual cash-out attempts. On-chain researchers have shared the relevant addresses with authorities and crypto firms. The broader Coldcard exploit has already highlighted risks in hardware wallet seed generation and prompted users of affected devices to migrate funds to newly generated secure wallets. Most of the overall stolen total continues to sit unmoved, preserving a window for monitoring and potential recovery efforts.
This development sparks important discussions about post-exploit fund movement strategies and the role of cross-chain DEXs in laundering. Supporters of robust on-chain analytics argue that transparent protocols like THORChain still allow skilled investigators to track flows and alert intermediaries. Critics note that decentralized swapping tools can accelerate the dispersion of stolen assets and complicate timely freezes. Analysts observe that the delayed movement of the main Coldcard hauls is somewhat atypical compared with faster-laundering operations, yet the eventual use of THORChain aligns with common techniques for converting Bitcoin into more flexible assets.
Looking ahead, further movements of the remaining funds and any successful interventions by exchanges or law enforcement will shape the ultimate outcome for victims. This analysis is based on reports from Galaxy Research and contemporaneous on-chain tracking for accuracy and reliability. Fund movements and recovery prospects remain subject to ongoing blockchain monitoring and investigative efforts.
