On-chain data has recorded the activation of an attacker linked to the third wave of attacks on Coldcard hardware wallets. A conversion of stolen bitcoins into Ethereum is being observed through the decentralized protocol THORChain. This is the hacker's first significant step toward laundering assets after a long pause.

My analysis shows that the attacker has moved only about 10% of the total stolen funds — approximately 179 BTC. The remaining 90% (around 1610 BTC) still remain untouched at the original addresses. This tactic indicates a cautious approach: the hacker is likely testing liquidity and laundering routes before deploying the bulk of the funds.

Let me remind you that within this campaign, the attackers managed to compromise at least 1789 BTC, distributed across 8865 addresses. The scale of the incident highlights systemic risks associated with vulnerabilities in the supply chain of hardware wallets, even those positioned as maximally secure.

The choice of THORChain as a bridge for cross-chain exchange is not accidental. This protocol provides a high degree of anonymity and does not require KYC, making it an attractive tool for hackers seeking to complicate fund tracking. The use of Ethereum as the target asset is also logical: the second-largest cryptocurrency by market cap offers broad opportunities for further obfuscation of traces through DeFi protocols and mixers.

The current situation demonstrates that even after prolonged inactivity, attackers return to managing assets. For Coldcard holders, this is an alarming signal, emphasizing the need to review security measures. I recommend that everyone using hardware wallets conduct an audit of their devices for authenticity and provenance.

My conclusion: The ongoing movement of funds, even in small volumes, is a clear indicator that the hacker is preparing for a full liquidation of positions. The market should expect increased pressure on bitcoin in the medium term if the remaining 90% are moved to exchanges.