EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard hackers used THORChain to transfer stolen bitcoins. Why did the attack take a new turn?

2026-09-04 06:11:21
Bookmark

A hacker linked to the third wave of Coldcard wallet theft has first begun transferring stolen bitcoins. According to Alex Thorn of Galaxy Research, on September 3, attackers exchanged about 10% of bitcoins for ether through THORChain. When Thorn marked the move, the remaining 90% of the bitcoins remained intact in the original address. Researchers traced the redeemed funds to a newly discovered Ethereum address and handed them over to law enforcement and other agencies that tracked the theft.

Before the transfer, Coldcard wallets had been stolen for several weeks due to flaws in some wallet seed generation methods. The attack was carried out in multiple waves, and the total number of stolen bitcoins eventually exceeded 1,700, or more than US$100 million based on its value at the time. Most of the funds in the third wave of theft had been left untouched, but now this was the first clear signal that attackers were beginning to move funds.

The third wave of Coldcard theft hackers exchanged funds for ether through THORChain. The third wave of attackers transferred stolen funds for the first time and exchanged them for ether through the cross-chain decentralized exchange THORChain. This is the first time that funds were transferred from the original hacker address in the first, second or third wave of thefts. -- Alex Thorn (@intangiblecoins) September 2, 2026

The actual source of the attack

What is unusual about this case is that the attacker never needed to crack the victim's device or trick anyone into handing over the password. The problem lies in the wallet itself. There is a vulnerability in older versions of Coldcard firmware that allows some private keys to be predictable. Anyone who knows the pattern can recreate these keys and take over the affected Bitcoin addresses. Keeping devices offline-which is the core of hardware wallets-does nothing to protect these users.

These attacks are not one-time large-scale sweeps. Researchers discovered multiple waves of attacks, in which attackers processed affected addresses one by one and changed the collection method along the way. By early August, Galaxy Research had identified a third wave, followed by another wave of attacks that scattered hundreds of bitcoins to a large number of victim addresses. This pattern doesn't look like a single theft, but more like someone slowly walking through a huge pool of fragile wallets.

This puts the victim in trouble. Once a vulnerable wallet is identified, moving the remaining funds becomes a race against the attacker. Coinkite, the company behind Coldcard, has informed affected users of migration funds because installing revised firmware cannot repair poorly generated credentials. Software patches cannot retroactively fix exposed keys.

What has Ether Exchange actually changed

Stolen bitcoins no longer stay in their original form or address where they first discovered them. THORChain allows native assets from different blockchains to be exchanged directly without going through a centralized exchange, which provides an alternative path for attackers to transfer funds before attempting to exchange again. However, this exchange was not completely smooth. Thorn said some of the attacker's THORChain attempts were returned, and the attacker then tried again. The specific reason for these returns has not been confirmed, so it cannot be mistakenly assumed that a particular protective measure prevented them. What is obvious is that transferring large amounts of stolen cryptocurrency is not simply sending from wallet to wallet. Each additional transaction creates a new observation point for researchers. Therefore, the next step is more important than the first exchange itself. Researchers will pay close attention to this new Ethereum address, whether it flows to a centralized exchange, other chains, or cross-chain bridges. Each option reveals different information to investigators about the attacker's intentions. Thorn has shared the address with authorities and cryptocurrency companies. Now, these funds are being monitored far beyond the Bitcoin network.

This is a problem for self-hosting, not just Coldcard

This incident impacted one of Bitcoin's core selling points-self-custody. Hardware wallets are designed to isolate private keys from connected devices, and users are often told that they do not need to trust exchanges or other third parties to control their own keys. The Coldcard case shows that this protection has limitations. If the process used to create the key is flawed, keeping the device offline will not solve the problem. This doesn't mean that hardware wallets are no longer useful. Security depends not only on where the private key is stored, but also on how the key is created, whether the firmware used to generate the key is reliable, and whether the manufacturer has flagged the problem. The Coldcard incident was particularly serious because the victims were not careless users, many of whom followed the basic rules of self-custody but still lost their Bitcoin. This attack also reminds us that monitoring the movement of stolen cryptocurrency is not the same as being able to stop it. Bitcoin's public ledger makes transactions visible, but visibility does not equal control. Once attackers start moving coins across different networks, investigators must follow every step and coordinate with the parties controlling the next station (exchanges, protocols, and sometimes law enforcement) to try to stop the funds before they are realized.

What happens next

The current focus will be on the remaining 90% of the funds in the third wave of theft. If attackers continue to transfer bitcoins, researchers are likely to track each exchange and look for signs that funds are flowing to the redemption point. The THORChain redemption failure also means that the attacker may continue to test different paths rather than transferring all assets at once. The Coldcard case may also continue to spark discussions about hardware wallet security. The biggest question now is whether the remaining coins can be transferred without providing investigators with enough information to stop them.

At the same time, Coinkite issued a security advisory warning that cryptocurrencies stored in specific Coldcard hardware wallets may be at risk due to a vulnerability that affects seed generation for multiple firmware versions.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP