A hacker linked to the third wave of the Coldcard wallet compromise began converting stolen Bitcoin into Ether through THORChain. Onchain monitoring indicates that the attacker moved roughly 10% of the stolen funds, leaving the remaining 90% untouched across the original addresses.
COLDCARD WAVE 3 HACKER SWAPS FUNDS TO ETH VIA THORCHAIN
the wave 3 exploiter has moved stolen funds for the first time, swapping to ETH them through the THORChain cross-chain DEX
these are the first funds from wave 1, 2, or 3 to move onchain from the original hacker addresses pic.twitter.com/jjOrX5wBR9
— Alex Thorn (@intangiblecoins) September 2, 2026
Galaxy head of research Alex Thorn reported transfers through THORChain on September 2, 2026. Thorn noted this development marks the first time that assets from any of the three initial exploitation waves have moved from their primary repository addresses.
THORChain operates as a decentralized settlement protocol facilitating cross-chain swaps between native layer-1 assets without requiring custodial deposits or identity verification. For attackers, this structure offers an alternative to centralized exchanges that enforce compliance and sanction screening.
The conversion encountered technical friction on the cross-chain platform. Due to liquidity limits and slip tolerance, THORChain repeatedly refunded transfer attempts, prompting the attacker to resubmit swap orders across multiple consecutive execution rounds.
Fund Tracing and Destination Addresses
Forensic researchers traced the completed swaps across THORChain directly to a newly established Ethereum recipient address. Thorn confirmed that this destination has been shared with law enforcement bodies and cryptocurrency analytics firms to monitor subsequent routing attempts.
Investigators have not established whether the attacker will route funds through centralized exchanges or further decentralized bridges. Depositing the converted Ether into centralized services would subject the holdings to compliance checks, while additional mixing could obscure the trail.
The broader theft involves substantial sums across an expansive victim pool. Galaxy Research linked the vulnerability to the drainage of at least 1,789 Bitcoin from 8,865 addresses, representing an estimated value of $114.7 million at the time of the theft.
Obfuscation History and Mixer Activity
The THORChain swaps follow earlier efforts to sever transaction records. In August 2026, blockchain security firm CertiK documented earlier transfers to mixers, identifying the redirection of 64 Bitcoin and 200 Ether into privacy protocols such as Tornado Cash.
Those transactions confirmed a systematic attempt to disrupt forensic tracing. However, the bulk of the stolen assets remained dormant for weeks, as the attacker likely waited for sufficient market depth to process high-value conversions without excessive price slippage.
coldcard hackers are still active. here, a hacker swept keys that were generated with 5 dice rolls of added entropy 🎲 https://t.co/vJ9U7w9JxL
— Alex Thorn (@intangiblecoins) August 28, 2026
The threat actors remained fully operational in the days preceding this swap. Alex Thorn detected activity on August 28 after an automated sweep drained a test wallet configured intentionally with weak entropy to evaluate attacker monitoring capabilities.
The researcher wallet had been generated using five dice rolls of added entropy, creating an intentionally fragile cryptographic state. The attacker discovered and swept the experimental funds almost immediately, proving that automated scanners were actively querying the network for exploitable keys.
Device Security and Seed Migration
That incident confirmed that automated scanning scripts remained actively searching for vulnerable keys nearly one month after the initial breaches. The persistent surveillance demonstrates that the exploit infrastructure was not dismantled after the initial wave of thefts.
The continuing activity highlights ongoing industry scrutiny surrounding hardware wallet security vulnerabilities and the structural limits of offline key storage when entropy generation or supply-chain processes face security compromises.
Hardware manufacturer Coinkite stated that firmware patches cannot repair recovery phrases generated under flawed entropy environments. Consequently, affected wallet holders must migrate assets to entirely new seeds rather than relying on software updates alone.
Onchain intelligence teams continue to monitor the identified Ethereum address for further movement toward liquidity pools or centralized platforms. Law enforcement agencies have not announced any official arrests or asset freezes in connection with the case.
This article is for informational purposes and does not constitute financial advice.

