Hackers transfer stolen bitcoins, leaving new traces on Ethereum
A hacker linked to Coldcard's third wave of theft converted about 10% of stolen bitcoins (BTC) into Ethereum (ETH) through THORChain, leaving a new transaction trail on Ethereum, while the remaining 90% of bitcoins remained unused.
Key Points:
This transfer is the first time funds have been observed flowing out of original hacker addresses in three confirmed waves of Coldcard theft. On-chain analysts tracked these assets through THORChain and found that they were flowing to a new Ethereum address. Most of the third wave of stolen funds have not yet been moved.
Bitcoin Money Trends
Alex Thorn, director of research at Galaxy, said that attackers had begun to exchange stolen bitcoins for Ethereum, but some transactions had to be retried due to multiple failures. This is the first time in any of the three waves that there has been an on-chain transfer of funds at the original address.
"Hackers seem to be having some problems exchanging all funds through THORChain... they keep receiving refunds and then keep trying again," Thorn said. Frequent refunds did not stop attackers from continuing to try to move assets.
Thorn said analysts traced the redemption operations to a new Ethereum address and have shared it with relevant law enforcement agencies and cryptocurrency companies, thereby retaining a traceable trail after the cross-chain transfer.
Alex Thorn's analysis
Thorn said it was unclear whether the attacker would further obscure the flow of funds or send them to the exchange, and investigators would pay close attention to the subsequent use of the newly discovered Ethereum address. This issue has become even more important today because the original stolen address is no longer completely dormant.
Analysts were able to identify the target address on Ethereum even after the THORChain exchange operation, indicating that in this case, the cross-chain transfer did not immediately cut off the visible transaction path. Thorn's disclosure also provides the exchange and compliance team with another address that needs to be monitored to track activity related to stolen funds.
Galaxy Research previously linked the Coldcard vulnerability to the theft of at least 1,789 bitcoins from 8,865 addresses and were worth approximately $114.7 million at the time of the theft. In an update dated August 25, it noted that 1,561 bitcoins (87.3% of confirmed losses) remained unused at the time.
Earlier activities related to Coldcard have involved privacy tools, with CertiK reporting in August that 64 bitcoins and 200 Ethereum were sent to mixers including Tornado Cash. On August 28, researchers also observed that the attacker emptied a deliberately weakened test wallet, indicating that the operation was still active before the latest transfer.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH