The attacker behind the third wave of Coldcard hardware wallet hacks has become more active: they have begun converting stolen bitcoins into Ethereum using the THORChain cross-chain protocol. This is the first significant step in an attempt to launder illegally obtained funds, and it has drawn close attention from analysts.
According to my data obtained through blockchain monitoring, the hacker has already moved about 10% of the total volume of stolen assets. The remaining 90% still sits at the original addresses, indicating a cautious, phased strategy for withdrawing funds. The total damage from this series of attacks is estimated at no less than 1789 BTC, affecting 8865 user addresses.
This transfer marks an important turning point: until now, funds linked to the third wave had remained untouched since the theft. The choice of THORChain is not accidental—this protocol allows assets to be exchanged without the need for KYC and with a high degree of anonymity, making it difficult for law enforcement and blockchain detectives to track the funds.
Situation Analysis and Risks
The fact that the hacker has begun laundering suggests they feel secure or, at the very least, confident in their methods. However, using THORChain does not guarantee complete anonymity—modern analysis tools make it possible to link transactions even across cross-chain bridges. In the coming weeks, we will likely see attempts to trace the final addresses and, possibly, pressure on exchanges where the funds may be withdrawn.
For Coldcard holders, this news is a reminder of the importance of security hygiene. Attacks on hardware wallets are often linked not to hacking the device itself, but to compromising the delivery process or seed phrases. I recommend that all hardware wallet users double-check the origin of their devices and use only verified purchase channels.
I will continue to monitor the movement of funds and update the analysis as new data emerges.