NewsCryptoColdcard Wave 3 Attacker Moves Stolen Funds for the First Time, Converting Some Assets to ETH

Coldcard Wave 3 Attacker Moves Stolen Funds for the First Time, Converting Some Assets to ETH

Author: CryptoMeter ioΒ·

Key Takeaways

  • β€’The attacker moved stolen Coldcard Wave 3 funds for the first time, converting part of the assets into ETH through THORChain.
  • β€’This is the first known movement from the original hacker addresses linked to the Wave 1, Wave 2, or Wave 3 incidents.
  • β€’Several THORChain swap attempts were refunded, but the attacker kept retrying transactions, and roughly 90% of Wave 3 funds remain untouched.
  • β€’The resulting Ethereum address has been identified and shared with authorities and cryptocurrency firms, and the new transfers create additional on-chain traces.
  • β€’Thorn's analysis suggests different tools may have been used during the vaulting, cash-out, and THORChain stages of the incident.
Coldcard Wave 3 Attacker Moves Stolen Funds for the First Time, Converting Some Assets to ETH

The attacker behind the Coldcard Wave 3 wallet breach has moved stolen cryptocurrency for the first time, marking a new phase in the ongoing security incident. According to Alex Thorn, head of research at Galaxy Digital, the attacker converted part of the stolen assets into ETH using THORChain.

The transfer is the first known movement from the original hacker addresses connected to the Wave 1, Wave 2, or Wave 3 incidents. Up to this point, the stolen funds had remained in their initial on-chain locations.

THORChain Activity Draws Attention

On-chain activity indicates the attacker is attempting to shift a larger share of the stolen funds through THORChain, a cross-chain decentralized exchange. The process, however, has not proceeded smoothly.

THORChain has previously been used as a laundering route in other high-profile crypto thefts, including exploits attributed to North Korea's Lazarus Group, because its cross-chain swaps allow assets to move between blockchains without a centralized intermediary. That history means the platform's flows are closely watched by blockchain-analytics firms and exchanges, which typically flag funds tied to known hack addresses when they surface on major networks.

Several swap attempts appear to have been refunded, yet the attacker has continued retrying transactions despite these setbacks, according to Thorn's monitoring.

Roughly 90% of the Wave 3 funds remain untouched, leaving most of the stolen assets still in addresses associated with the incident even as the attacker begins testing routes for moving or converting them.

On-Chain Tracking Intensifies

The new activity could make the stolen assets easier to monitor, since transfers generate additional on-chain traces. Thorn said the resulting Ethereum address has been identified and shared with the relevant authorities and cryptocurrency firms.

The movement also gives analysts fresh insight into the attacker's behavior and the software used in the transactions. Thorn's analysis suggests that different tools may have been employed during the vaulting, cash-out, and THORChain stages.

The Coldcard incident has involved multiple waves of wallet drains linked to compromised seed generation. Coldcard is a hardware wallet marketed for air-gapped, self-custody security, and the incident has drawn attention because it targeted a device class users rely on specifically to keep private keys offline. The latest movement does not mean the remaining funds have been successfully liquidated, but it signals that the attacker has begun actively testing ways to move the assets.