The hacker behind the third wave of Coldcard wallet thefts has finally started moving stolen funds — swapping roughly 10% of the stolen Bitcoin for Ether through THORChain, according to Galaxy Research.
Alex Thorn, Galaxy’s head of research, reported on Wednesday that the third-wave exploiter moved about 10% of the stolen hoard, leaving the remaining 90% untouched since the thefts occurred. According to Thorn, this marked the first time funds from any of the three waves of Coldcard-related thefts had moved onchain from the original hacker addresses — a notable milestone in a case where stolen coins had sat dormant for months.
“The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying,” Thorn said on X.
Onchain Tracing to Ethereum
The swap attempts have not gone smoothly for the attacker, and those failures are proving useful for investigators. Thorn said onchain analysts traced the funds through THORChain’s cross-chain swaps to a new Ethereum address. He added that the address has been shared with relevant authorities and crypto companies.
It remains unclear whether the attacker will attempt to further obscure the assets or move them through an exchange, Thorn noted. The repeated refunds from THORChain — reportedly caused by swap execution issues — have kept a meaningful portion of the funds in motion patterns that analysts can follow, complicating the hacker’s efforts to quietly launder the proceeds.
The Scale of the Coldcard Exploits
The movement follows an exploit campaign that Galaxy Research linked to the theft of at least 1,789 Bitcoin from 8,865 addresses, worth approximately 114.7 million USD at the time the funds were stolen. The thefts have been grouped into three distinct waves, each tied to compromised Coldcard hardware wallet devices.
Blockchain security firm CertiK reported in August that hackers linked to the exploit had already sent 64 Bitcoin and 200 Ether to cryptocurrency mixers, including Tornado Cash, in earlier laundering attempts. The new THORChain activity suggests the attacker has been cycling through laundering venues — mixers first, cross-chain swaps now — as each route presents its own friction.
The Attack That Kept Testing
The latest movement comes just days after Thorn said the Coldcard attackers remained active. On Aug. 28, researchers deliberately loaded a weakened wallet with funds as a test, designed to measure the attackers’ ability to find vulnerable keys. The wallet was swept shortly afterward, confirming that the exploitation infrastructure was still live and monitoring for susceptible targets.
That finding has kept security researchers on alert, as the attackers appear to retain an automated capability to identify and drain weakened keys rather than relying on manual targeting. The Coldcard case has become one of the more troubling hardware wallet security episodes of 2026, given the scale of losses and the persistence of the exploitation campaign across multiple waves.
Context: Cross-Chain Laundering Under Watch
The use of THORChain for laundering purposes echoes a broader pattern in the industry. Cross-chain bridges and swap protocols have become recurring chokepoints in money laundering trails, as they allow attackers to move value across chains without passing through centralized exchanges that enforce know-your-customer controls.
Separately, addresses linked to North Korea’s Lazarus Group recently moved 30 million USD in stolen funds through the Hyperliquid decentralized exchange, part of a larger laundering operation that analysts have been tracking. Like the Coldcard case, that episode showed how onchain analytics firms are increasingly able to trace stolen funds across protocols in near-real-time — and share identified addresses with exchanges and authorities before cash-out.
For now, 90% of the third-wave Coldcard funds remain in their original addresses, untouched. Whether the attacker retries THORChain successfully, pivots to mixers, or attempts an exchange deposit, the Ethereum address identified by analysts gives investigators a fixed point to monitor. Given that the hacking campaign has already spanned three waves and months of dormancy, few expect the attacker to simply give up — but the window for quiet laundering appears to be narrowing.
The case also underscores a growing debate within the industry about the role of decentralized protocols in laundering pipelines. THORChain’s swap infrastructure has historically been positioned as censorship-resistant, and the protocol’s community has previously resisted calls to block specific addresses. That stance leaves analytics firms and authorities tracking funds after the fact rather than preventing transfers — a model that has repeatedly proven effective for attribution, even when recovery lags behind.
Market context: Bitcoin traded at 76,734 USD at press time, down 1.72% in 24 hours, while Ether changed hands at 2,379.51 USD, down 3.22%, per CoinGecko data.
Disclaimer: This article is for informational purposes only and does not constitute financial advice.
getting refunded by THORChain over and over while the whole industry watches the address. worst week ever for this hacker lol
1,789 btc from 8,865 addresses and the guy fumbles his THORChain swaps lol getting refunded over and over is poetic
^ thorn said every refunded swap keeps the funds in traceable patterns. dude is doing the investigators job for them
90% still sitting untouched. Moving 10% through THORChain first reads like a test run before a bigger cashout attempt.
@Viggo agreed, and the traced ETH address is already shared with exchanges. If he sends the rest anywhere KYC he is done
if it is a test run the results look terrible. every refunded swap burns fees and galaxy maps each retry in real time
They loaded a bait wallet with a weakened key on aug 28 and it got swept almost immediately. So the scanning infra is automated and still live. That part worries me more than the laundering.
Galaxy catching failed swaps in real time is wild. The refunds basically gift-wrapped the trail for analysts
The key line is that the new ETH address was shared with authorities and exchanges. The moment he touches a KYC venue with those funds, the trail closes on him.
cash-out options narrow fast once exchanges have the address. OTC desks screen too, so the ETH side of the swap is also a dead end
Coldcard owners in wave 3 waiting on refunds should keep receipts from support. Took months for some folks in the earlier waves.
1,789 btc from 8,865 addresses and 90% still frozen at the original wallet. slowest heist in crypto history