Stolen bitcoins were transferred for the first time in the third wave of Coldcard attacks, and some were converted to Ethereum through THORChain.
Bitcoin stolen in the third major wave of Coldcard attacks has begun to move from its original attacker's address, marking the first time such a movement has occurred in the funds. Part of the funds have been converted to Ethereum (ETH) through THORChain. The attacker tested multiple cross-chain mobility protocol paths and exchanged approximately 4.2 BTC for approximately 135 ETH. Before retrying, several attempted redemption operations were refunded and the resulting ETH was traced to a newly created Ethereum address.
Third wave of funds leaves original address
This flow of funds marks the first time confirmed outward activity has occurred at the original merged address associated with Coldcard's first, second or third wave attacks. The third wave of attacks initially stole 207.7294 BTC from vulnerable wallets in early August and adopted a different transaction structure than the previous two waves of large-scale attacks. Currently, most of the bitcoins involved in the third wave of attacks have not yet been moved. The latest transaction represents an initial attempt to convert some of the stolen BTC into assets that are easier to flow on Ethereum and other blockchain infrastructure than native Bitcoin.
The target Ethereum address and related transaction paths have been provided to exchanges, compliance companies and law enforcement investigators, and efforts are continuing to identify potential monetization channels.
Coldcard theft totals at least 1,778 BTC
The broader Coldcard security vulnerability stems from weak seed generation issues caused by the introduction of incorrect firmware in March 2021. Failure to generate random numbers may cause the entropy of the private key of some wallets to be significantly reduced, allowing attackers with sufficient computing resources to remotely reconstruct the keys of the affected seeds.
As of mid-August, at least 1,778.84 BTC from more than 8,600 addresses had been confirmed as stolen. Other clusters with lower confidence levels may significantly increase the final total.
In addition to the three major attack waves, funds have also been flowing in smaller attack footprints, including funds routed through CoinJoin transactions, stripping chains, bridging services, and centralized services. The new THORChain activity is important because the original wallets associated with the three identified attack waves have remained untouched after receiving the stolen BTC.
Firmware update fails to fix existing seeds
Coinkite released updated Coldcard security firmware in August that requires increased user-provided randomness when generating new wallet seeds. However, updating affected hardware does not make existing vulnerable seeds safe. Bitcoins held under seeds generated using the affected firmware must be transferred to new wallets generated using patch software and sufficient fresh entropy.
After the first THORChain redemption, most of the bitcoins associated with the original third-wave address remained in place, while investigators were still tracking newly received ETH and any subsequent transfers from the target address.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH