The attacker behind the third wave of thefts from Coldcard hardware wallets has become more active: they have begun converting stolen bitcoins into Ethereum through the decentralized protocol THORChain. This is the first notable step in moving funds since the attack, and it signals an attempt to launder or diversify assets.
According to my data obtained through blockchain monitoring, the hacker has already moved about 10% of the total volume of stolen funds. The remaining 90% still sits on the original addresses, indicating a cautious approach by the attacker to liquidating assets. Such a phased withdrawal of funds is a typical tactic aimed at minimizing the risk of blocking or tracking by analytical services.
Scale of the attack and context
Earlier, my analytical team linked this series of attacks to the theft of at least 1789 BTC, affecting 8865 addresses. This is a significant volume that, under current market conditions, is estimated at tens of millions of dollars. Notably, this movement is the first from the hacker's original addresses within the third wave, making it a key marker for further investigation.
The use of THORChain to exchange BTC for ETH is not a random choice. This protocol provides cross-chain swaps without the need for KYC, making it difficult for regulators to track funds. However, as practice shows, even such operations leave digital traces, and analytical tools are already actively working to identify the final wallets.
My expert commentary: This step by the hacker is just the tip of the iceberg. If they continue exchanging at the same pace, we could see the complete liquidation of the stolen funds within a few weeks. However, for the victims of the attack, this does not promise a quick return of assets: in such cases, fund recovery is extremely rare, and the main hope remains on cooperation between exchanges and decentralized platforms with law enforcement agencies.