Coldcard hacker swaps stolen Bitcoin for ETH via THORChain
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
A hacker involved in the third wave of Coldcard wallet thefts has begun swapping stolen Bitcoin for Ether using THORChain. Galaxy head of research Alex Thorn reported that about 10% of the stolen funds have moved onchain from the original addresses, with 90% still unmoved. Thorn also noted difficulties the hacker faces in successfully swapping all of the stolen Bitcoin. The funds have been traced through THORChain to a new Ethereum address, which has been shared with authorities and crypto companies.
Why it matters
This movement of stolen funds marks the first time any assets from the Coldcard theft waves have been actively moved onchain from the original hacker addresses. The activity signals ongoing attempts by the attacker to liquidate or obscure stolen assets, which is relevant for tracking and potential recovery efforts. The source does not elaborate further on broader market or policy impacts.
Key context
The Coldcard exploit is linked to the theft of at least 1,789 Bitcoin from 8,865 addresses, valued around $114.7 million at the time of theft. Earlier, hackers had sent some stolen funds to mixers like Tornado Cash. The source also references a recent sweep of a weakened test wallet by the attackers, indicating their continued activity.
Key numbers and entities
The main entities are Galaxy Research and its head of research Alex Thorn, THORChain, Coldcard wallets, and blockchain security company CertiK. The theft involved approximately 1,789 Bitcoin (worth about $114.7 million originally), with 64 Bitcoin and 200 Ether previously sent to mixers. The hacker moved roughly 10% of the stolen funds recently.
What remains unclear
It remains uncertain whether the attacker will continue to move, convert, or further obscure the stolen assets through other means or exchanges. The extent to which the recovered Ethereum address can lead to further actionable insights is not detailed. The complete strategy or intent of the hacker beyond these recent transactions is also not established.