EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard hacker tests THORChain routing, transferring 10% stolen funds

2026-09-04 00:36:08
Bookmark

Hackers transfer stolen bitcoins, leaving new traces on Ethereum

A hacker linked to Coldcard's third wave of theft converted about 10% of stolen bitcoins (BTC) into Ethereum (ETH) through THORChain, leaving a new transaction trail on Ethereum, while the remaining 90% of bitcoins remained unused.

Key Points:

This transfer is the first time funds have been observed flowing out of original hacker addresses in three confirmed waves of Coldcard theft. On-chain analysts tracked these assets through THORChain and found that they were flowing to a new Ethereum address. Most of the third wave of stolen funds have not yet been moved.

Bitcoin Money Trends

Alex Thorn, director of research at Galaxy, said that attackers had begun to exchange stolen bitcoins for Ethereum, but some transactions had to be retried due to multiple failures. This is the first time in any of the three waves that there has been an on-chain transfer of funds at the original address.

"Hackers seem to be having some problems exchanging all funds through THORChain... they keep receiving refunds and then keep trying again," Thorn said. Frequent refunds did not stop attackers from continuing to try to move assets.

Thorn said analysts traced the redemption operations to a new Ethereum address and have shared it with relevant law enforcement agencies and cryptocurrency companies, thereby retaining a traceable trail after the cross-chain transfer.

Alex Thorn's analysis

Thorn said it was unclear whether the attacker would further obscure the flow of funds or send them to the exchange, and investigators would pay close attention to the subsequent use of the newly discovered Ethereum address. This issue has become even more important today because the original stolen address is no longer completely dormant.

Analysts were able to identify the target address on Ethereum even after the THORChain exchange operation, indicating that in this case, the cross-chain transfer did not immediately cut off the visible transaction path. Thorn's disclosure also provides the exchange and compliance team with another address that needs to be monitored to track activity related to stolen funds.

Galaxy Research previously linked the Coldcard vulnerability to the theft of at least 1,789 bitcoins from 8,865 addresses and were worth approximately $114.7 million at the time of the theft. In an update dated August 25, it noted that 1,561 bitcoins (87.3% of confirmed losses) remained unused at the time.

Earlier activities related to Coldcard have involved privacy tools, with CertiK reporting in August that 64 bitcoins and 200 Ethereum were sent to mixers including Tornado Cash. On August 28, researchers also observed that the attacker emptied a deliberately weakened test wallet, indicating that the operation was still active before the latest transfer.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP