Coldcard hacker uses THORChain to swap stolen BTC
A hacker associated with the third wave of Coldcard wallet thefts began converting stolen Bitcoin into Ether through THORChain on Sept. 3, according to Galaxy Research’s Alex Thorn.
- Third-wave Coldcard attacker moved roughly 10% of stolen Bitcoin through THORChain into Ether this week.
- Researchers traced the swaps to a new Ethereum address and shared details with relevant authorities.
- Around 90% of the third-wave funds remained unmoved when Galaxy researcher Alex Thorn reported transfers.
- THORChain repeatedly refunded some swap attempts, prompting the attacker to resubmit transactions, Thorn reported Wednesday.
- Coinkite says affected seeds require migration because installing corrected firmware cannot repair existing wallet credentials.
The transactions moved approximately 10% of the Bitcoin controlled by that attacker, Thorn said. Roughly 90% remained at its original addresses when he published the update.
Researchers traced the swaps through THORChain to a newly identified Ethereum address. Thorn said he shared the address with law enforcement, crypto companies and other organizations monitoring the stolen assets.
Coldcard hacker encounters failed THORChain swaps
THORChain allows users to exchange native assets across blockchains without depositing funds into a centralized exchange. The protocol can therefore convert native Bitcoin into Ether without relying on a conventional custodial platform.
However, not every transaction succeeded. Thorn said the hacker appeared to be experiencing technical problems while attempting to process the swaps.
“The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying,” Thorn said.
The cause of the refunds was not immediately confirmed. Possible explanations include liquidity limitations, transaction settings or protocol safeguards, but no verified technical assessment had established the reason.
The movement represented the first detected onchain transfer from the original addresses associated with the first three attack waves, according to Thorn. Analysts will now monitor whether the resulting ETH moves to centralized exchanges, bridges or privacy services.
Galaxy traced 1,789 Bitcoin to the thefts
Galaxy Research previously attributed the loss of 1,789.28 BTC across 8,865 addresses to the Coldcard vulnerability. The Bitcoin was worth approximately $114.7 million when stolen.
As crypto.news previously reported, approximately 87% of the identified Bitcoin remained unmoved as of Aug. 25. The estimate included funds linked to multiple attackers and attack waves, not only the wallet now using THORChain.
Galaxy’s figures partly relied on 221 victim reports covering 790.72 BTC. Onchain analysis identified additional affected addresses beyond those reported directly by customers.
The total remains an estimate because researchers have identified several attacker patterns with different levels of confidence. Galaxy has distinguished its high-confidence attribution from other addresses that may also relate to the vulnerability.
Earlier attackers used cryptocurrency mixers
The latest THORChain swaps are separate from earlier laundering activity attributed to other attackers. CertiK reported in August that wallets linked to the broader incident sent 64 BTC and 200 ETH toward cryptocurrency mixers.
In related coverage, crypto.news found that one attacker retained 1,159 BTC while another began mixing smaller amounts. The different movements suggest that several parties may have exploited the same weakness.
Mixers and cross-chain swaps can complicate tracking, but they do not automatically make funds untraceable. Investigators can continue following transfers when assets enter and leave public protocols.
Centralized exchanges remain potential intervention points because they conduct identity and sanctions checks. Thorn said the new Ethereum destination had been distributed to relevant companies so they could identify subsequent deposits.
Coldcard users still need new wallet seeds
The theft was linked to weak seed generation in Coldcard firmware released from 2021. The vulnerability reduced the randomness protecting some wallet credentials, allowing attackers to calculate private keys without physically accessing the devices.
Coinkite, Coldcard’s manufacturer, says corrected firmware is available across affected models. Its current security guidance states that previously generated vulnerable seeds still require migration.
Installing updated firmware does not repair a seed created under the affected software. Users must generate a new seed with corrected firmware and transfer their Bitcoin to addresses controlled by that new wallet.
Meanwhile, the attacker also remained active after the largest theft waves had ended. On Aug. 29, an address linked to the operation swept Bitcoin from a deliberately weakened researcher wallet, according to Thorn. Researchers created the wallet to test whether the attacker continued searching for predictable private keys. Its rapid compromise indicated that automated scanning remained active nearly one month after the first large thefts.
The incident has also prompted closer examination of how hardware wallets generate recovery phrases. Unlike phishing attacks, the Coldcard thefts did not require victims to approve transactions or reveal credentials. The exposed seeds contained insufficient randomness, allowing attackers to derive keys remotely and identify funded addresses on Bitcoin’s public ledger. As crypto.news previously explained, the firmware flaw weakened seeds generated on affected devices, meaning secure storage practices could not protect funds tied to those credentials.
Galaxy and other investigators are expected to continue watching the new Ethereum address. No public recovery, arrest or official identification of the attacker had been announced when the transfers were reported.