My colleagues at Galaxy Research have recorded the first signs of an active phase of laundering funds stolen from Coldcard hardware wallet users during the third wave of targeted attacks. This concerns the movement of bitcoins that the attacker has held since the hack, and he has now moved on to cleaning them.
The key tool in this scheme is CoinJoin transactions. This method combines the outputs of many independent transfers into a single transaction, which radically complicates blockchain analysis and breaks the correlation between source and recipient addresses. For analysts, this is a classic challenge: standard heuristics, such as clustering by common inputs, work less effectively here, and deeper data filtering is required.
Notably, this is not the hacker's first step in an attempt to cover his tracks. Earlier, he had already partially converted the stolen coins into ether via the THORChain cross-chain protocol. Such a hybrid approach—first converting into another asset, then mixing via CoinJoin—indicates a high level of technical skill and a deliberate use of privacy-oriented tools.
Let me remind you that the third wave of attacks on Coldcard was linked to the compromise of devices at the supply chain stage. In total, user losses were estimated at several million dollars, and part of the funds had already been returned under previous incidents. However, the current activity shows that the attacker has no intention of stopping and is methodically building a complex chain of movements.
From my expert perspective, the use of CoinJoin combined with THORChain is a signal of the professionalization of cybercrime in the crypto space. For investors and hardware wallet owners, this is another reminder of the critical importance of verifying device authenticity and using multisignature schemes, even when it comes to "cold" storage. As for analysts, they will need to develop new tracking methods, since classic transaction graph analysis is no longer sufficient here.