Roughly one-tenth of the Bitcoin stolen in the third Coldcard attack wave has now been converted to ETH through THORChain's cross-chain swap protocol, with the assets landing in a newly identified Ethereum address.
Alex Thorn, who has tracked the Coldcard exploit across its reported waves, said the transfer marks the first time funds from any of the three attack waves have moved on-chain from the original hacker addresses. The exploiter swapped the stolen Bitcoin to ETH using THORChain's decentralized exchange, routing the assets to a freshly traced Ethereum destination.
The movement represents roughly 10 percent of the total funds stolen in the third wave, leaving approximately 90 percent still sitting in the original addresses. Thorn previously reported that at least 15 attackers exploited the Coldcard vulnerability, with losses spread across multiple waves targeting the hardware wallet. In a follow-up analysis, he noted that assistance for Coldcard victims was in progress as teams handled a high volume of tracing requests and maintenance needs.
The use of THORChain as a cross-chain corridor for stolen funds could draw increased regulatory scrutiny to the protocol's anti-money-laundering controls, particularly as blockchain analytics firms and law enforcement monitor the remaining stolen Bitcoin. THORChain operates as a decentralized liquidity network that enables swaps between Bitcoin, Ethereum, and other chains without a centralized intermediary. Its permissionless architecture makes it difficult for compliance teams to block transactions from flagged addresses, a feature that has increasingly attracted illicit fund movers seeking to break the on-chain trail between Bitcoin and Ethereum.
Whether the exploiter continues shifting the remaining stolen Bitcoin through THORChain or pivots to other cross-chain venues will determine the scope of the laundering operation. The first on-chain movement from the wave-three addresses also provides tracing teams with fresh transaction fingerprints to follow, potentially narrowing the window for the attacker to offload the remaining funds before exchanges and analytics firms update their watchlists. For Coldcard users, the ongoing exploit highlights persistent security risks facing hardware wallets, even as the devices are widely considered among the most secure options for self-custody.
This article is for informational purposes only and does not constitute investment advice.