NewsCryptoColdcard Wave 3 Attacker Begins Converting Stolen Bitcoin to ETH via THORChain

Coldcard Wave 3 Attacker Begins Converting Stolen Bitcoin to ETH via THORChain

Author: Crypto Adventure·

Key Takeaways

  • Stolen Bitcoin from Coldcard Wave 3 moved from its original consolidation addresses for the first time, with about 4.2 BTC swapped into roughly 135 ETH through THORChain.
  • The Coldcard compromise, rooted in faulty seed-generation firmware from March 2021, has confirmed thefts of at least 1,778.84 BTC from more than 8,600 addresses by mid-August.
  • Wave 3 originally drained 207.7294 BTC in early August, and most of those holdings remain unmoved after the initial THORChain conversions.
  • The destination Ethereum address and transaction paths have been shared with exchanges, compliance firms, and law enforcement to track potential off-ramps.
  • Coinkite's August firmware update requires extra randomness for new seeds, but existing vulnerable seeds are only secured by moving funds to a newly generated wallet.
Coldcard Wave 3 Attacker Begins Converting Stolen Bitcoin to ETH via THORChain

Bitcoin stolen in the third major Coldcard attack wave has begun moving from the attacker's original addresses for the first time, with a portion of the funds converted into Ether through THORChain, according to on-chain tracking shared by intangiblecoins on X.

Approximately 4.2 BTC was swapped into roughly 135 ETH as the attacker tested multiple routes through the cross-chain liquidity protocol. THORChain is a permissionless protocol that enables native asset swaps between different blockchains without wrapped tokens or centralized custodians, a design that has previously made it a recurring venue for moving illicit crypto assets because users do not pass through a regulated intermediary with identity checks. Several attempted swaps were refunded before being retried, and the resulting ETH was traced to a newly created Ethereum address.

Wave 3 Funds Leave Original Addresses

The movement marks the first confirmed outbound activity from the original consolidation addresses linked to Coldcard Waves 1, 2, or 3.

Wave 3 originally drained 207.7294 BTC from vulnerable wallets in early August, using a transaction structure distinct from the first two large attack waves.

Most of that Wave 3 Bitcoin remains unmoved. The latest transactions instead represent an initial attempt to convert part of the stolen BTC into assets that can move across Ethereum and other blockchain infrastructure more easily than native Bitcoin, whose network has no native smart-contract layer that would allow similarly flexible transfers or swaps on its own.

The destination Ethereum address and related transaction paths have been shared with exchanges, compliance firms, and law-enforcement investigators as efforts continue to identify potential off-ramps. Once funds exist as ETH, they can be routed through decentralized exchanges, bridges, and mixing services across the Ethereum ecosystem, expanding the number of paths investigators must monitor compared with tracking static Bitcoin outputs.

Coldcard Theft Reached at Least 1,778 BTC

The broader Coldcard compromise stemmed from weak seed generation introduced by faulty firmware dating back to March 2021. A random-number-generation failure could leave some wallets with dramatically weaker private-key entropy, allowing attackers with sufficient computing resources to reconstruct affected seeds remotely.

At least 1,778.84 BTC was confirmed stolen from more than 8,600 addresses by mid-August, according to Galaxy research. Additional lower-confidence clusters could push the ultimate total considerably higher.

Movement had already occurred from smaller attacker footprints outside the three primary waves, including funds routed through CoinJoin transactions, peel chains, bridges, and centralized services. The new THORChain activity is significant because the original wallets tied to the three largest identified attack waves had remained untouched after receiving the stolen BTC.

Firmware Fix Cannot Repair Existing Seeds

Coinkite released updated Coldcard security firmware in August that requires additional user-supplied randomness when generating new wallet seeds.

Updating affected hardware does not make an existing vulnerable seed secure. Bitcoin held under seeds generated on affected firmware must be transferred to a newly generated wallet created with patched software and sufficient fresh entropy.

Most Bitcoin associated with the original Wave 3 addresses remained in place after the first THORChain swaps, while investigators continue tracking the newly received ETH and any subsequent transfers from the destination address. Whether further conversions follow from the still-unmoved Wave 3 holdings, and whether exchanges flag any deposits tied to the destination address, will shape the next phase of the tracing effort.