Coldcard Hacker Swaps Stolen Bitcoin for Ethereum via THORChain
The attacker used a decentralized protocol to move assets following a firmware flaw that compromised millions in BTC.
A hacker linked to the "third-wave" Coldcard exploit has moved stolen Bitcoin into Ethereum using the THORChain protocol. The movement marks a strategic shift in how the attacker is handling assets following one of the most significant hardware wallet compromises in recent history.
According to reports from Cointelegraph and analysis by Galaxy Research, the attacker utilized THORChain to swap Bitcoin (BTC) for Ethereum (ETH). This activity follows a series of thefts targeting Coldcard hardware wallet users, triggered by a critical firmware flaw. In total, the exploit resulted in the theft of approximately 1,367 BTC, with a market value estimated between $88 million and $111 million across three distinct waves of attacks.
The Coldcard Vulnerability
The thefts resulted from a recurring attack vector that evolved over time, culminating in the "third-wave" exploit. Coldcard, designed as an air-gapped security solution, was compromised via a firmware flaw that allowed attackers to bypass the device's primary security guarantees. This vulnerability enabled the unauthorized extraction of private keys or the signing of fraudulent transactions, leading to the massive loss of funds across multiple user accounts.
The Role of Cross-Chain Liquidity
The use of THORChain—a decentralized, non-custodial liquidity protocol—is a critical detail for blockchain analysts. Unlike centralized exchanges, which require Know Your Customer (KYC) documentation and can freeze accounts upon request from law enforcement, THORChain allows users to swap assets between different blockchains without a central intermediary. By crossing from the Bitcoin ledger to the Ethereum network, the attacker creates a break in the linear transaction history that typically allows researchers to track stolen funds.
Industry Implications
This incident highlights a growing trend where sophisticated attackers leverage decentralized bridges to obfuscate the trail of stolen assets. As security firms and law enforcement improve their ability to monitor single-chain movements, the shift toward cross-chain swaps increases the complexity of asset recovery. It demonstrates that even high-security hardware wallets are not immune to systemic flaws and that the decentralized nature of modern DeFi protocols can be weaponized to shield illicit gains.
Future Outlook
Analysts continue to monitor the Ethereum addresses receiving the swapped funds to determine if the attacker will attempt to cash out via a centralized gateway or further obfuscate the assets through mixing services. While the movement of funds via THORChain is confirmed, the total volume of the haul currently being laundered through this specific method remains under investigation.