A wallet attacker linked to the third wave of Coldcard-related thefts has started moving stolen Bitcoin through THORChain and converting it into Ether, marking the first reported onchain activity from the original attacker addresses across the three theft waves.
Onchain researcher Thorn reported on Sept. 3 that roughly 10% of the stolen funds associated with the latest movement had been routed through THORChain, while the remaining holdings had not moved. The reported transfers included 20.5 Bitcoin converted into Ether and sent onward to a newly created Ethereum address.
The activity gives the attacker a cross-chain route out of Bitcoin without relying on a conventional centralized trading platform. THORChain is a decentralized liquidity protocol that enables native-asset swaps between blockchains, allowing users to exchange Bitcoin for Ether through the protocol’s network rather than depositing assets with a custodian.
Thorn said the attacker made several unsuccessful swap attempts before retrying the transactions. Some of those attempts were refunded by the protocol, according to his account of the onchain activity. Researchers subsequently traced the assets that completed the route to the new Ethereum address.
Thorn said the destination address had been shared with relevant authorities and cryptocurrency companies. Moving the funds to Ethereum may create additional tracing opportunities, since the attacker would need to navigate Ethereum’s more visible ecosystem of wallets, decentralized protocols and potential conversion points to move the assets further.
Theft campaign involved at least 1,789 Bitcoin
The latest transfers follow a theft campaign that Galaxy Research linked to the loss of at least 1,789 Bitcoin from 8,865 addresses. Galaxy Research valued the stolen Bitcoin at approximately $114.7 million when the theft occurred.
The scale of the incident places it among the larger recent wallet-security thefts tied to compromised key material rather than an attack on a major blockchain’s underlying network. The affected Bitcoin was spread across thousands of addresses, suggesting the attacker or attackers were able to identify and drain a large pool of wallets vulnerable to the same compromise.
The source material describes the thefts as occurring in three waves, with the Sept. 3 THORChain activity tied to the third. Thorn said it represented the first movement from the original attacker addresses across all three waves, after the stolen holdings had largely remained stationary.
The decision to begin swapping through THORChain may indicate that the attacker is testing how quickly funds can be moved across chains without immediately exposing them to centralized compliance controls. A Bitcoin-to-Ether conversion does not erase the transaction trail: the Bitcoin inputs, THORChain transactions and Ethereum destination can all be examined on public blockchains. It can, though, complicate tracking by forcing investigators to follow assets through multiple networks and protocols.
Earlier transfers used cryptocurrency mixers
The reported THORChain swaps came after previous attempts to obscure the stolen assets. In August, blockchain security firm CertiK reported that hackers linked to the same exploit had sent 64 Bitcoin and 200 Ether to cryptocurrency mixers, including Tornado Cash.
Mixers pool and redistribute funds in an effort to make direct links between deposits and withdrawals more difficult to follow. Their use in a theft-related case can add complexity for investigators, especially where assets are subsequently bridged, swapped, or distributed across newly created addresses.
The amounts cited by CertiK were substantially smaller than Galaxy Research’s estimate of the total Bitcoin taken. That gap is consistent with Thorn’s account that most of the stolen holdings remain dormant.
Thorn reported that 1,561 Bitcoin from the earlier theft waves remained untouched in the original collection addresses. Large inactive balances can be easier to monitor on public ledgers than funds moving through successive swaps, though a dormant wallet does not guarantee that its holder has lost access to the assets.
Researcher wallet was swept on Aug. 28
Evidence that the attackers remain operational emerged days before the THORChain transactions. Thorn reported an Aug. 28 sweep of a deliberately weakened researcher wallet that had been set up to test whether the attackers could locate vulnerable keys.
The reported sweep suggests the theft operation may not be limited to managing previously stolen funds. If the attackers can still identify wallets generated or used under compromised conditions, holders of potentially affected devices or seed phrases face a continuing risk rather than solely a historical exposure.
Users who suspect their wallet recovery phrase or private key was created on compromised firmware should treat that credential as unsafe. Moving funds to a newly generated wallet created on a trusted, updated device would remove assets from addresses controlled by the older key material. Reusing an exposed recovery phrase in a new device would not solve the problem, since the phrase itself controls the funds.
A multisignature arrangement can also reduce the damage from a single compromised signing key. In a multisignature wallet, spending requires approval from more than one key, often stored on separate devices. That structure would not repair an already compromised setup, but it can make a future theft harder if one device or one recovery phrase is exposed.
Most reported victims lost more than one Bitcoin
The supplied victim data indicates that more than half of 221 reported victims lost over one Bitcoin each. That distribution illustrates how a compromise affecting wallet-generation conditions can produce losses far above the small-balance thefts often associated with opportunistic phishing or malicious browser extensions.
The reported conversion of 20.5 Bitcoin into Ether is a limited portion of the total assets linked to the wider theft campaign, but it changes the immediate investigative picture. The attacker has shifted from holding Bitcoin in known collection addresses to actively using cross-chain infrastructure, creating a new Ethereum trail that researchers, affected companies and authorities can monitor.
With the bulk of the reported stolen Bitcoin still sitting in identifiable addresses, the next pressure point is likely to be the attacker’s ability to convert those holdings into usable funds without creating transaction paths that lead to services capable of freezing, flagging or identifying them.
Learn how to keep your funds safer from wallet exploits in our guide on crypto wallet mistakes to avoid and essential protections.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
