
Coldcard third-wave hacker begins swapping stolen BTC into ETH via THORChain
Galaxy’s Alex Thorn said about 10% moved while roughly 90% of the stolen funds remain untouched.
A hacker tied to the third wave of Coldcard wallet thefts has started moving funds onchain, swapping a portion of stolen Bitcoin into Ether through THORChain. The activity marks the first observed movement from the original hacker addresses across all three theft waves, even as most of the stolen BTC remains idle.
Coldcard Third-Wave Funds Finally Move: BTC-to-ETH Swaps via THORChain
Galaxy head of research Alex Thorn said a hacker linked to the third wave of Coldcard wallet thefts has begun swapping stolen Bitcoin (BTC) for Ether (ETH) through THORChain, a cross-chain liquidity protocol that allows native-asset swaps without using a centralized exchange.
Thorn said the third-wave exploiter moved about 10% of the stolen funds through THORChain, with about 90% remaining untouched. The more important detail for market participants is not the fraction moved so far, but that Thorn described this as the first time funds from any of the three Coldcard theft waves had moved onchain from the original hacker addresses.
The transfers sit on top of a larger theft set. Galaxy Research previously linked the Coldcard exploit to the theft of at least 1,789 BTC from 8,865 addresses, worth about $114.7 million at the time the bitcoin was stolen. Even partial mobilization of that inventory can matter for short-term liquidity narratives in BTC and ETH, and for venue-specific risk if the flow eventually resolves into exchange deposits rather than remaining in onchain routing.
Tracing the Route: Refund Friction on THORChain and a New Ethereum Destination
The onchain path Thorn described was not clean execution. “The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying,” he said, describing repeated refunds and retries during the swap attempts.
That kind of friction matters because it tends to stretch a laundering phase out in time, and it creates more observable transaction attempts for analysts to follow. Thorn said onchain analysts traced the funds through THORChain to a new Ethereum address, and he said he shared that address with relevant authorities and crypto companies.
What happens after the ETH lands is still the open question. Thorn said it remains unclear whether the attacker will attempt to further obscure the assets or move them through an exchange.
There is also precedent inside this same exploit cluster for obfuscation tooling. Blockchain security company CertiK reported in August that hackers linked to the Coldcard exploit sent 64 BTC and 200 ETH to cryptocurrency mixers including Tornado Cash, an Ethereum-based mixer used to break the onchain link between sender and receiver.
Where This Could Go Next: Mixers, Exchange-Deposit Risk, and the 90% Still Sitting
The next market-relevant signal is whether additional chunks of the remaining roughly 90% leave the original hacker addresses Thorn referenced, because that would confirm the current activity is not a one-off test transaction but the start of a broader distribution phase.
A second tell is whether new THORChain swap attempts keep showing the same refund-and-retry pattern Thorn described. If the retries persist, the route may stay observable for longer. If the pattern disappears, it can mean the attacker changed execution tactics or switched rails.
Third, any follow-on movements from the newly identified Ethereum address Thorn said was shared with authorities and crypto companies will matter more than the initial swap itself, particularly if the ETH is split into smaller lots, bridged again, or deposited into known services.
Finally, traders should be alert to renewed mixer interactions tied to the exploit. CertiK’s August disclosure of 64 BTC and 200 ETH sent to mixers including Tornado Cash is the closest thing in the record to a “playbook,” and it raises the odds that newly swapped ETH is routed into obfuscation tooling rather than immediately sold.
My Read: The First Movement Is a Regime Change for This Hack’s Market Risk
The move is being sized like a 10% flow story, but the procedural detail that matters is Thorn’s claim that this is the first onchain movement from the original hacker addresses across all three Coldcard theft waves. That is the line between a dormant overhang and an active laundering phase, and markets tend to price those two states very differently even before any exchange deposit is visible.
The threshold that matters is whether the remaining roughly 90% starts leaving in additional tranches, because that is when this shifts from a contained onchain curiosity into a sustained flow problem that can spill into venue risk and BTC/ETH liquidity narratives.