An attacker linked to the third wave of attacks on Coldcard wallets has finally begun moving funds. My analysis shows that the hacker has initiated a process of exchanging stolen bitcoins for Ethereum through the decentralized THORChain protocol. This is a landmark step that may indicate an attempt to launder assets or prepare for their further liquidation.

At this point, about 10% of the total stolen funds have been moved, while the remaining 90% are still held at the original addresses controlled by the attacker. This tactic—phased movement—is typical of professional hackers seeking to minimize tracking risks and avoid a sharp market crash from large transactions.

Let me remind you that in this series of attacks, at least 1789 BTC were compromised, distributed across 8865 addresses. This is one of the most massive incidents in the history of hardware wallets, and it raises serious questions about the security of even those devices considered the gold standard of protection. It is important to emphasize that this movement is the first since the completion of the third wave, making it a key indicator of the hacker's intentions.

The use of THORChain for cross-chain exchange is no coincidence: this protocol provides a high degree of anonymity and liquidity, which complicates the freezing of funds on centralized exchanges. However, as my experience shows, tracking such operations through analytical tools, for example, using Galaxy data, is still possible, and this leaves a window for the potential recovery of assets.

My expert conclusion: The hacker clearly does not intend to stop, and if the pace of conversion continues, we could see the complete liquidation of the stolen bitcoins in the coming weeks. This will create additional pressure on the ETH market, but for bitcoin, the risks are limited, as the volume has already been taken out of circulation. Investors should closely monitor the movement of these funds—any large transfers could signal new attacks or attempts at manipulation.