Coldcard Hacker Reported Moves 10% Bitcoin via THORChain

A deliberately weakened researcher wallet set up to test whether attackers could locate vulnerable keys was swept on August 28.
"The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying," Galaxy's Alex Thorn said.
THORChain is a cross-chain decentralized liquidity network that allows users to swap cryptocurrencies between different blockchains without relying on centralized exchanges.
The hacker behind the third wave of Coldcard wallet thefts has made the first recorded movement of stolen funds, swapping roughly 10% of the Bitcoin haul for Ether through THORChain and sending it to a new Ethereum address Galaxy Research. The remaining 90% of the approximately 1,789 Bitcoin—worth about $114.7 million at the time of theft—remains in the original attacker wallets CryptoSlate. The transfer marks a major shift in the investigation, suggesting the thieves are now actively attempting to obscure or convert their assets.
The swaps have not gone smoothly. According to Galaxy Research's Alex Thorn, "The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying." Multiple attempted transfers failed before one finally succeeded, suggesting the attackers may be learning the mechanics of cross-chain swaps in real time Hokanews.
THORChain is a decentralized liquidity network that lets users swap cryptocurrencies between different blockchains without using a centralized exchange Grafa. This means traders can move Bitcoin to Ethereum (or vice versa) while staying off traditional exchanges that track and report suspicious activity. For thieves, it offers a way to fragment stolen funds across multiple blockchains, making them harder to trace and seize.
The Coldcard attack was not a single incident. Instead, it unfolded in three waves of exploitation targeting the hardware wallet used by roughly 8,865 addresses Bitbo. A deliberately weakened researcher wallet designed to test for vulnerabilities was swept on August 28, kicking off the investigation CryptoSlate. The total damage: at least 1,789 Bitcoin stolen from compromised addresses.
Security researchers have identified the fresh Ethereum address where the stolen Ether now sits and have shared it with law enforcement and major crypto firms KuCoin. However, the attackers' next steps remain a mystery. They could attempt more swaps through other decentralized protocols, move funds through privacy mixers like Tornado Cash (which they used earlier), or try to cash out on unregulated exchanges.
The failed swaps and repeated attempts hint that the attackers are testing different laundering methods rather than executing a polished plan. Galaxy Research notes they remain active and are clearly still learning how to move their stolen assets undetected. The fact that they took weeks to move any funds at all suggests they were either laying low or waiting for investigative attention to cool before attempting their first transfers CryptoSlate.
Publishers
17
Articles
14
Reach
31