An address linked to the Coldcard wallet thefts has started swapping stolen Bitcoin into Ether through THORChain, giving investigators a fresh trail while most of the funds remain untouched.
- About 10% of the tracked BTC was swapped
- Roughly 90% remained unmoved
- Researchers traced the swaps to a new Ethereum address
- Coldcard’s seed flaw still requires migration, not just a firmware update
Galaxy Research’s Alex Thorn said the activity began on Sept. 3 and appears tied to the third wave of Coldcard wallet thefts. In his update, Thorn said roughly 10% of the Bitcoin controlled by that address cluster had been moved, while about 90% was still sitting at the original addresses.
That is the part criminals hate and everyone else should understand: moving stolen BTC through a cross-chain swap protocol is not the same thing as making it disappear. THORChain is a protocol that lets users swap native assets across blockchains without a centralized exchange in the middle. That can make tracking harder, but it does not wipe the trail clean. Public ledgers stay public. Bad news for thieves, useful for investigators.
Thorn said the swaps were traced to a newly identified Ethereum address, which he shared with law enforcement, crypto companies, and other organizations watching the stolen assets. He also said THORChain was reportedly refunding some swap attempts, which forced the attacker to retry. The exact reason for those refunds was not immediately confirmed.
“The hacker appears to be having some issues swapping all the funds through THORChain, they keep getting refunded and he keeps retrying, ”, Alex Thorn
The wording matters here. This is not a clean story of one neat villain moving one neat pile of coins. The broader Coldcard incident appears to involve multiple attack waves, and Galaxy’s attribution covers a wide set of addresses rather than a single, tidy wallet. The latest movement seems tied to one third-wave exploiter, but it should not be stretched into a claim that one person is responsible for every stolen satoshi in the case.
Galaxy previously attributed 1, 789.28 BTC across 8, 865 addresses to the Coldcard vulnerability, worth about $114.7 million when stolen. Those figures were not pulled from thin air. Galaxy said part of its tally relied on 221 victim reports covering 790.72 BTC, so the full picture combines confirmed reports with high-confidence attribution from onchain analysis.
Earlier coverage had already shown the laundering path shifting. CertiK reported in August that wallets linked to the broader incident sent 64 BTC and 200 ETH toward cryptocurrency mixers. Mixers blend funds together to obscure transaction trails. THORChain works differently: it changes the asset and the chain, moving native Bitcoin into Ether without requiring a centralized exchange deposit. Different tool, same objective, muddy the trail before the money hits a chokepoint.
That chokepoint is often a centralized exchange. Once stolen funds touch a KYC-heavy platform, compliance teams and investigators often get a much better shot at flagging or freezing them. Cross-chain swaps and mixers can buy time, but they do not grant immunity. They just make the paper chase messier.
The underlying Coldcard issue is the part that should alarm users most. Coinkite says affected firmware generated weak entropy when creating seeds. A seed, or recovery phrase, is the cryptographic starting point for a wallet. If the randomness behind it is weak, some keys can become predictable under the wrong conditions. That is not “user clicked a bad link” territory. That is a broken foundation.
Coinkite has also been explicit that updating the firmware does not fix an already generated vulnerable seed. Users with affected seeds must create a new seed using corrected firmware and move their Bitcoin to addresses controlled by the new wallet. In plain English: if you made the seed on the bad firmware, the seed itself is the problem. Updating alone is not a magic eraser.
Thorn also said that on Aug. 29, an address linked to the operation swept Bitcoin from a deliberately weakened researcher wallet. That suggests the attacker is still actively probing for exposed keys rather than simply cashing out and disappearing. For anyone still holding a vulnerable Coldcard seed, that is not a subtle hint. It is a flashing warning sign.
As of the latest reporting, there was no public recovery, arrest, or official identification of the attacker. The funds are still moving, investigators are still tracing, and the race between laundering and attribution is still underway.
What Coldcard users need to know
If a seed was generated on affected Coldcard firmware, it should be treated as compromised until it has been migrated to a new wallet setup. The critical point is that the vulnerable seed itself must be replaced.
The safest path is straightforward:
- Check whether the seed was generated on affected firmware.
- Update to corrected firmware.
- Generate a brand-new seed.
- Move funds to fresh addresses controlled by the new wallet.
For a hardware wallet, firmware matters, but seed generation matters more. If the randomness is broken, the device is already carrying a bad hand. Bitcoin does not care how polished the casing looks.
What THORChain changes, and what it does not
THORChain is useful for legitimate users who want non-custodial swaps between native assets. That is the upside of permissionless infrastructure: fewer gatekeepers, fewer custodial risks, more direct control.
The downside is just as clear. The same infrastructure can be used to move stolen funds across ecosystems before they hit a compliance wall. That is the tradeoff. Neutral rails do not care who is using them, at least until the money reaches a place that does.
That does not make THORChain the villain in this mess. It does, however, show why open protocols are always double-edged. Freedom and abuse often arrive on the same train.
Key takeaways
-
What happened with the stolen Coldcard BTC?
An address linked to the Coldcard thefts began swapping stolen Bitcoin into Ether through THORChain on Sept. 3, according to Galaxy Research’s Alex Thorn. -
How much of the tracked Bitcoin moved?
Thorn said about 10% had been swapped, while roughly 90% remained unmoved at the time of his update. -
Does THORChain hide stolen crypto completely?
No. It can make tracing harder by moving funds across chains, but blockchain analysis can still follow the trail, especially when funds later touch centralized services. -
Can a Coldcard firmware update fix the problem?
No. Coinkite says affected seeds must be migrated to a new seed; updating firmware alone does not repair an already vulnerable wallet. -
Was one attacker responsible for everything?
Not necessarily. The broader Coldcard incident appears to involve multiple waves, and Galaxy’s attribution covers a larger address set rather than a single confirmed actor. -
Has the attacker been identified or arrested?
No public identification, recovery, or arrest had been announced when the transfers were reported.
This is the ugly side of crypto security: a technical flaw at the wallet layer, followed by a scramble to move funds, then a cat-and-mouse game across chains, mixers, and exchanges. The blockchain keeps receipts. The only question is who gets there first, the launderer or the people tracing the mess.
Further reading
For more background on the wallet thefts, THORChain’s role, and the security fallout, these sources add useful context.
- Coldcard hacker uses THORChain to swap stolen BTC
- Coldcard Hacker Swaps Stolen Bitcoin for ETH via THORChain
- Coldcard Firmware Update Advisory on Seed Generation
- THORChain project and protocol overview
- THORChain hit by suspected $10M+ cross-chain exploit
- Bitcoin, Ethereum, XRP bottom zones and BTC support levels
- Ethereum researchers propose SPHINCS+ post-quantum wallet signatures