Coldcard Attacker Reportedly Swaps Roughly 10% of Stolen BTC Through THORChain
Key Takeaways
- •The attacker linked to the Coldcard breach is reported to have swapped about 10% of the stolen Bitcoin via the decentralized protocol THORChain.
- •On-chain observers and secondary write-ups, including one describing a swap into ETH, echoed the report, but no complete transaction trace with hashes, addresses, and timestamps has verified it.
- •THORChain's lack of a centralized intermediary means no operator can freeze or reverse the swaps, complicating tracing and recovery of the funds.
- •The available evidence shows no confirmed law-enforcement action, recovery, or established protocol liability, and neither the theft timeline nor exploit method is established.
- •The episode has renewed debate over hardware-wallet key-management risks, with multisignature setups cited as a commonly discussed mitigation.

The central claim is simple: a Coldcard attacker is reported to have swapped approximately 10% of the stolen BTC via THORChain, according to crypto.news. At this stage, the movement is a reported event rather than an independently confirmed on-chain reconstruction, and neither the underlying theft timeline nor the exploit method is established in the available evidence.
Coldcard is a hardware wallet used to store Bitcoin offline, while THORChain is a decentralized protocol that allows users to swap assets across different blockchains without a centralized intermediary. What matters here is the route, not the size: THORChain gives whoever controls the coins a direct way to exit Bitcoin into other tokens, and because it operates without a centralized intermediary, there is no single service operator that can freeze or reverse a swap the way an exchange might. Cross-chain routing of stolen funds is not unique to this case; attackers in earlier high-profile cryptocurrency thefts have likewise moved loot through decentralized swapping protocols to complicate recovery. Coldcard's security has faced scrutiny before, including a vendor warning over an entropy flaw tied to a BTC sweep.
What supports the THORChain swap claim
Beyond the primary report, the swap narrative has been echoed by on-chain observers. Posts from the account intangiblecoins on X flagged the movement, including one observation tied to the wallet activity:
https://x.com/intangiblecoins/status/2095297452681158840
A separate write-up carried via TradingView framed the swap as a move from Bitcoin into ETH.
These are attributed observations from individual trackers and secondary write-ups, not a verified wallet-by-wallet trace. The current evidence does not include a full on-chain reconstruction with transaction hashes, sender and receiver addresses, and timestamps, so the wallet-tracking details should be read as claims made by those observers rather than settled fact.
The broader Coldcard drain has produced conflicting on-chain readings before, including reports of a 39,600 BTC shift into small wallets following the hack. That history is one reason to keep the framing cautious here.
Why the swap route matters more than the market reaction
This is a security story, not a price story. Moving stolen Bitcoin through a cross-chain protocol complicates tracing because the funds change form and network, breaking the simple "follow the BTC" approach that works when coins stay on one chain. Once converted into another asset on a different chain, the funds can be dispersed across addresses and services that Bitcoin-focused tracking tools do not directly cover, which lengthens the work for blockchain-analytics firms and any investigators involved. That is the practical takeaway from the THORChain route.
It is worth being explicit about what the evidence does not show. There is no confirmed law-enforcement outcome, no recovery, and no established protocol liability in the available material. The significance lies in the movement path itself, not in any measured market impact.
The episode also feeds an ongoing debate about hardware-wallet risk. Developer Peter Todd has previously warned about single-signature Bitcoin risks in connection with the Coldcard drain, a reminder that key-management design shapes how exposed users are when a wallet line comes under attack. Multisignature setups, which require more than one key to move funds, are one commonly discussed mitigation in that debate.
For now, the responsible read is a narrow one: a reported swap of part of the stolen funds through THORChain, corroborated by on-chain watchers but not yet fully verified. What to watch next is whether a full transaction trace — with hashes, addresses, and timestamps — emerges from on-chain analysts or the vendors involved, and whether any further movement of the remaining funds is observed. Confirmation will depend on a complete transaction trace, which the current evidence does not provide.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.