EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard Wave 3 attackers begin exchanging stolen bitcoins for Ethereum through THORChain

2026-09-03 21:15:04
Bookmark

Stolen bitcoins were transferred for the first time in the third wave of Coldcard attacks, and some were converted to Ethereum through THORChain.

Bitcoin stolen in the third major wave of Coldcard attacks has begun to move from its original attacker's address, marking the first time such a movement has occurred in the funds. Part of the funds have been converted to Ethereum (ETH) through THORChain. The attacker tested multiple cross-chain mobility protocol paths and exchanged approximately 4.2 BTC for approximately 135 ETH. Before retrying, several attempted redemption operations were refunded and the resulting ETH was traced to a newly created Ethereum address.

Third wave of funds leaves original address

This flow of funds marks the first time confirmed outward activity has occurred at the original merged address associated with Coldcard's first, second or third wave attacks. The third wave of attacks initially stole 207.7294 BTC from vulnerable wallets in early August and adopted a different transaction structure than the previous two waves of large-scale attacks. Currently, most of the bitcoins involved in the third wave of attacks have not yet been moved. The latest transaction represents an initial attempt to convert some of the stolen BTC into assets that are easier to flow on Ethereum and other blockchain infrastructure than native Bitcoin.

The target Ethereum address and related transaction paths have been provided to exchanges, compliance companies and law enforcement investigators, and efforts are continuing to identify potential monetization channels.

Coldcard theft totals at least 1,778 BTC

The broader Coldcard security vulnerability stems from weak seed generation issues caused by the introduction of incorrect firmware in March 2021. Failure to generate random numbers may cause the entropy of the private key of some wallets to be significantly reduced, allowing attackers with sufficient computing resources to remotely reconstruct the keys of the affected seeds.

As of mid-August, at least 1,778.84 BTC from more than 8,600 addresses had been confirmed as stolen. Other clusters with lower confidence levels may significantly increase the final total.

In addition to the three major attack waves, funds have also been flowing in smaller attack footprints, including funds routed through CoinJoin transactions, stripping chains, bridging services, and centralized services. The new THORChain activity is important because the original wallets associated with the three identified attack waves have remained untouched after receiving the stolen BTC.

Firmware update fails to fix existing seeds

Coinkite released updated Coldcard security firmware in August that requires increased user-provided randomness when generating new wallet seeds. However, updating affected hardware does not make existing vulnerable seeds safe. Bitcoins held under seeds generated using the affected firmware must be transferred to new wallets generated using patch software and sufficient fresh entropy.

After the first THORChain redemption, most of the bitcoins associated with the original third-wave address remained in place, while investigators were still tracking newly received ETH and any subsequent transfers from the target address.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP