During blockchain activity monitoring, I detected signs of the first major transactional activity linked to the third wave of Coldcard hardware wallet hacks. The attacker controlling the stolen funds has begun gradually converting bitcoins into Ethereum using the cross-chain protocol THORChain. This step indicates an attempt to launder assets through alternative networks and decentralized liquidity pools.
Based on my analysis of fund movements, I estimate that approximately 10% of the total stolen coins have been converted so far. The remaining 90% are still held at the original addresses, which may point to a phased withdrawal strategy aimed at minimizing the risk of blocking or tracking.
Scale of the attack and incident context
Earlier during the investigation, I was able to establish that the total damage from the third wave of attacks on Coldcard exceeds 1789 BTC, affecting 8865 unique addresses. This is one of the most massive incidents in the hardware wallet segment in recent months. Notably, this current fund movement is the first since the breach was recorded — until now, the hacker preferred to keep assets in a static state, likely waiting for attention from analytical services to wane.
The use of THORChain to exchange BTC for ETH is a characteristic pattern for professional groups seeking to break the on-chain link with original addresses. This significantly complicates the work of investigative teams and transaction tracking services.
My professional assessment: this activity is only the beginning of the process. Given the volume of funds and the attacker's technical sophistication, in the coming weeks we will likely witness further steps to fragment and distribute assets. Investors and Coldcard holders should remain vigilant, and exchanges should strengthen compliance procedures to identify potentially compromised coins.