Particle.news

Coldcard Attacker Routes Stolen Bitcoin to Ethereum Using THORChain

This first major on‑chain laundering from the Coldcard thefts signals investigators to a new Ethereum address they have shared with law enforcement.

Overview

  • Researchers reported on Sept. 3 that a Wave‑3 actor moved about 20.45–20.50 BTC through THORChain into Ether, marking the first significant on‑chain movement from the original Coldcard theft addresses.
  • Trackers recorded roughly 34 THORChain swaps that routed the BTC to a newly identified Ethereum address and disclosed that address to law enforcement and crypto firms for monitoring.
  • Some swap attempts failed or were refunded and the attacker retried transactions, a pattern that researchers say may reflect liquidity or technical limits in the cross‑chain swaps.
  • Galaxy Research and others have attributed about 1,789.28 BTC across thousands of addresses to the Coldcard firmware flaw that used a weak MicroPython fallback RNG instead of the device hardware RNG.
  • Coinkite says patched firmware is available but cannot fix seeds generated under the vulnerable builds, so affected users must create new seeds and move funds while investigators watch for deposits to regulated exchanges that could enable intervention.