BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Coldcard Hacker Moves Stolen Bitcoin Through THORChain, Here’s Why the Attack Has Taken a New Turn

A hacker linked to the third wave of the Coldcard wallet thefts has started moving the stolen Bitcoin for the first time. On September 3, the attacker converted about 10% of the Bitcoin into

AnonymousCryptoCompass newsroom
September 3, 2026
6 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

A hacker linked to the third wave of the Coldcard wallet thefts has started moving the stolen Bitcoin for the first time. On September 3, the attacker converted about 10% of the Bitcoin into Ether through THORChain, according to Galaxy Research’s Alex Thorn. The other 90% was still sitting untouched in its original addresses when Thorn flagged the movement. Researchers traced the swapped funds to a newly identified Ethereum address and passed it along to law enforcement and other groups tracking the theft.

The move comes after weeks of theft from Coldcard wallets linked to a flaw in how some wallet seeds were generated. The attacks unfolded in several waves, with the total eventually topping 1,700 BTC, worth more than $100 million at the time it was stolen. Most of the third wave’s funds had sat untouched until now. This is the first clear sign the attacker is starting to move them.

Where the attack actually came from 

This case is unusual because the attacker never had to break into a victim’s device or trick anyone into handing over a password. The problem came from the wallet itself. Older Coldcard firmware had a flaw that made some private keys predictable. Anyone who understood the pattern could recreate those keys and take over the affected Bitcoin addresses. Keeping the device offline, normally the whole point of a hardware wallet, didn’t protect these users at all.  

The attacks also did not happen in one large sweep, either. Researchers spotted different waves as the attacker worked through affected addresses, changing collection methods along the way. By early August, Galaxy Research had identified a third wave, then another that moved hundreds of Bitcoin across a wide spread of victim addresses. The pattern looks less like a single theft and more like someone slowly working through a large pool of vulnerable wallets.

That has left victims in a difficult spot. Once a vulnerable wallet is identified, moving what’s left of it becomes a race against the attacker. Coinkite, the company behind Coldcard, has told affected users to migrate their funds, since installing corrected firmware won’t repair credentials that were already generated badly. A software patch doesn’t retroactively fix a key that’s already exposed.  

What the Ether swap actually changes 

The stolen Bitcoin is no longer sitting where researchers first found it, in the same form or the same addresses. THORChain lets native assets from different blockchains swap directly, without routing through a centralized exchange, giving the attacker another path for moving funds before trying to convert them again.

But the swap has not been completely smooth. Thorn said some of the attacker’s THORChain attempts were refunded. The attacker just tried again. The exact reason for those refunds has not been confirmed, so it would be wrong to assume that a particular safeguard stopped them. What is clear is that moving a large amount of stolen crypto is not as simple as sending it from one wallet to another. Every additional transaction creates another point that researchers can watch.

The next step is therefore more important than the first swap itself. Researchers will be watching the new Ethereum address closely, whether the ETH heads to a centralized exchange, another chain, or a bridge. Each option tells investigators something different about what the attacker is trying to do. Thorn has already shared the address with authorities and crypto companies. The money is being watched well beyond the Bitcoin network now.  

Why this is a problem for self-custody, not just coldcard 

This incident strikes at one of Bitcoin’s core selling points, self-custody. self-custody. Hardware wallets are designed to keep private keys away from internet-connected devices, and users are often told that controlling their own keys removes the need to trust an exchange or other third party. The Coldcard case shows that this protection has limits. If the process used to create the key is flawed, keeping the device offline cannot solve the problem.

That does not mean hardware wallets are no longer useful. Security depends on more than where a private key sits. It also depends on how that key was created, whether the firmware generating it was sound, and whether the manufacturer has flagged a problem. The Coldcard incident is particularly serious because the victims were not necessarily careless users; many had followed the basic rules of self-custody and still lost their Bitcoin.

This attack is also a reminder that watching stolen crypto move isn’t the same as being able to stop it. Bitcoin’s public ledger makes the transactions visible, but visibility is not the same as control. Once the attacker starts moving coins across different networks, investigators have to trace every step and coordinate with whoever controls the next stop, an exchange, a protocol, sometimes law enforcement, to try to stop the funds before they turn into usable cash.

What to expect

The immediate focus will be on the remaining 90% of the third-wave funds. If the attacker continues moving the Bitcoin, researchers will likely track each swap and look for signs that the funds are heading towards a cash-out point. The failed THORChain swaps also mean the attacker may continue testing different routes rather than moving everything at once. The Coldcard case is also likely to keep the debate around hardware-wallet security alive. The biggest question now is whether the remaining coins can be moved without giving investigators enough information to stop them. 

Meanwhile, Coinkite issued a security advisory warning that cryptocurrency stored in certain Coldcard hardware wallets could be at risk because of a flaw affecting seed generation on multiple firmware versions.

 

Enjoyed this? BookmarkDeFi Planet, explore related topics, and follow us onTwitter,LinkedIn,Facebook,Instagram,Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

The post Coldcard Hacker Moves Stolen Bitcoin Through THORChain, Here’s Why the Attack Has Taken a New Turn appeared first on DeFi Planet.