An attacker involved in the recent Coldcard wallet exploit has begun laundering stolen Bitcoin, converting a portion of the funds into Ether using the cross-chain protocol THORChain, according to blockchain researchers tracking the movement.
Tracing the Stolen Funds
Investigators say the perpetrator behind what has been described as the "third wave" of the Coldcard exploit shifted roughly 10% of the pilfered cryptocurrency through THORChain, a decentralized protocol that allows users to swap assets across different blockchains without relying on a centralized intermediary.
The conversion moved value from Bitcoin into Ether, with the proceeds landing at a freshly created Ethereum address. Analysts flagged the transfer as they monitored on-chain activity linked to the compromised wallets, noting that the use of cross-chain swaps is a common tactic among attackers seeking to obscure the trail of stolen assets.
Moving Bitcoin into Ether through a decentralized bridge is a familiar playbook for attackers trying to shake off pursuers.
Why THORChain Draws Bad Actors
THORChain has repeatedly surfaced in the aftermath of major crypto thefts because its permissionless design lets funds flow between blockchains without the identity checks imposed by centralized exchanges. That structure complicates recovery efforts and makes it harder for investigators to freeze or reclaim assets once they have been swapped.
By breaking a large sum into smaller transfers and routing them across chains, attackers can slow down tracing efforts and create additional hurdles for anyone attempting to follow the money. Security teams often rely on the transparency of public ledgers to reconstruct these movements, even when funds pass through multiple hops.
Key details emerging from the incident include:
- Roughly 10% of the stolen Bitcoin was routed through THORChain
- The funds were converted into Ether
- The proceeds moved to a newly generated Ethereum address
What It Means for Coldcard Users
The activity underscores ongoing risks tied to wallet security, even for hardware devices marketed on their strong protections. Users of affected wallets are typically urged to remain vigilant, verify the integrity of their devices and monitor for any suspicious transactions.
Researchers are continuing to follow the remaining balance of stolen funds, and further movements could reveal more about the attacker's laundering strategy. As on-ch
