Coldcard Wave 3 Hacker Moves Stolen Funds On-Chain, Swapping to ETH via THORChain
Key Takeaways
- β’The Coldcard Wave 3 hacker moved stolen funds on-chain for the first time, as reported by Galaxy's Head of Research Alex Thorn.
- β’The attacker converted the stolen assets into Ethereum using THORChain, a cross-chain decentralized liquidity protocol.
- β’THORChain has been used in previous high-profile crypto exploits because it enables swaps without the identity checks and withdrawal controls of centralized exchanges.
- β’Although the swaps avoid centralized chokepoints, all transactions remain visible on public blockchains, enabling wallet clustering and transaction tracing.
- β’Blockchain analytics firms, security researchers, exchanges, and compliance teams are expected to continue monitoring the wallets for further transfers or cash-out attempts.

The hacker behind the Coldcard Wave 3 breach has moved stolen cryptocurrency on-chain for the first time since the incident, according to Alex Thorn, Head of Research at Galaxy. Coldcard, made by hardware wallet manufacturer Coinkite, is a popular device for storing Bitcoin offline, and breaches of its supply chain or firmware have direct implications for users who rely on it for self-custody. The activity was identified by Thorn, who reported that the transaction involved swapping the stolen assets into Ethereum (ETH) through THORChain, a cross-chain decentralized liquidity protocol.
The movement marks the first known on-chain activity involving the stolen funds, drawing attention from blockchain analysts and investigators monitoring the wallets. Transactions of this kind are closely tracked because they may provide clues about how stolen assets are being managed or laundered. Notably, THORChain has been used in similar situations before: attackers in prior high-profile crypto exploits have routed stolen assets through the protocol precisely because it enables swaps without the identity checks and withdrawal controls of centralized exchanges.
THORChain Used for Cross-Chain Swap
According to Thorn, the attacker used THORChain to convert the stolen funds into Ethereum. Cross-chain protocols allow users to exchange assets across different blockchains without relying on centralized exchanges. While these protocols serve legitimate purposes, they can also be used by attackers attempting to move or obscure stolen funds across multiple networks. For investigators, the trade-off is that although such swaps avoid centralized chokepoints, they remain fully visible on public blockchains, allowing wallet clustering and transaction tracing to continue.
Blockchain analytics firms and security researchers will likely continue monitoring the associated wallet addresses for further activity.
UPDATE: Coldcard wave 3 hacker moved stolen funds onchain for the first time, swapping them to ETH through THORChain, says Galaxy's Alex Thorn. pic.twitter.com/XPPR6ouSuf β Cointelegraph (@Cointelegraph) September 3, 2026 (x.com)
Investigators Continue Monitoring
The latest movement of the Coldcard hacker funds highlights the role of blockchain transparency in tracking illicit transactions. Although the attacker has begun moving assets, every on-chain transaction creates a public record that investigators can analyze. Security firms, exchanges, and compliance teams are expected to continue monitoring the wallets for additional transfers and potential attempts to cash out the stolen cryptocurrency.