The attacker behind the third wave of attacks on Coldcard hardware wallets has become more active: they have begun converting stolen bitcoins into Ethereum through the decentralized protocol THORChain. This is the first significant step in an attempt to legitimize illegally obtained assets after a long pause.
According to my data, the hacker has already moved about 10% of the total volume of stolen funds, while the remaining 90% are still on the original addresses that I am tracking as part of the analysis of this campaign. This involves a substantial amount — at least 1789 BTC, stolen from 8865 wallets during the third wave of attacks. This confirms that the incident was widespread and affected a significant number of users.
The choice of THORChain for the exchange is no coincidence: this protocol allows cross-chain swaps without the need for KYC verification, making it a favored tool for laundering funds in the industry. Moving only 10% of the assets may indicate that the hacker is testing the liquidity and security of the channels before proceeding with a large-scale withdrawal of funds.
The observed activity is an alarming signal for Coldcard holders affected by the attack. Apparently, the attacker has no intention of stopping and is gradually preparing for the full liquidation of the stolen reserves. In the coming weeks, further transactions should be expected, which could put additional pressure on the market.
My comment: The fact that the hacker has begun moving funds indicates confidence in the security of the chosen scheme. However, the use of THORChain leaves traces in the public blockchain, and with proper chain analysis, there is a possibility of tracking the final wallets, especially if part of the funds is converted into stablecoins or withdrawn through centralized platforms.