A hacker tied to Coldcard’s third theft wave moved about 10% of stolen Bitcoin (BTC) through THORChain into Ether (ETH), creating a new Ethereum trail while 90% remains untouched.
Key Points:
- The movement marks the first observed transfer from original hacker addresses across the three confirmed Coldcard theft waves.
- Onchain analysts followed the assets through THORChain to a new Ethereum address.
- Most of the third-wave funds have not moved.
Bitcoin Fund Movements
Galaxy head of research Alex Thorn said the attacker had begun swapping stolen Bitcoin for Ether, while repeated failures were forcing several transactions to be retried. It was the first time funds from the original addresses used in any of the three waves had moved onchain.
“The hacker appears to be having some issues swapping all the funds through THORChain ... they keep getting refunded and he keeps retrying,” Thorn said.
The repeated refunds did not stop the attacker from continuing attempts to move the assets.
Thorn said analysts traced the swaps to a new Ethereum address and shared it with relevant authorities and crypto companies, preserving a usable trail after the cross-chain transfers.
Also Read: Ukraine Exposes $1M Crypto Scam That Drained Wallets Across 20 Countries
Alex Thorn Analysis
Thorn said it remained unclear whether the attacker would try to obscure the funds further or send them to an exchange, leaving investigators to watch how the newly identified Ethereum address is used. That question has become more important now that the original theft addresses are no longer completely dormant.
Even after the THORChain swaps, analysts identified the destination on Ethereum, showing that moving between networks did not immediately sever the visible transaction path in this case.
Thorn’s disclosure also gives exchanges and compliance teams another address to watch for activity tied to the stolen funds.
Galaxy Research previously linked the Coldcard exploit to at least 1,789 Bitcoin taken from 8,865 addresses, worth about $114.7 million when stolen. Its Aug. 25 update said 1,561 Bitcoin, or 87.3% of the attributed losses, remained unspent at that point.
Earlier Coldcard-linked activity had already reached privacy tools, with CertiK reporting in August that 64 Bitcoin and 200 Ether were sent to mixers including Tornado Cash. On Aug. 28, researchers also saw attackers sweep a deliberately weakened test wallet, indicating the operation was still active before the latest movement.
Read Next: Nvidia Buys Hugging Face For $12.9B To Expand Beyond AI Chips





