Analysts have recorded the first signs of activity from the attacker responsible for the third wave of Coldcard hardware wallet hacks. Based on my observations, the hacker has begun converting stolen funds into Ethereum using the decentralized protocol THORChain — this is a classic marker of an attempt to obscure tracks and evade tracking.
At this point, approximately 10% of the total volume of stolen assets has been moved. The remaining 90% are still on the original addresses, indicating that the liquidation process is only gaining momentum. This involves a significant amount — at least 1789 BTC, which were stolen from 8865 wallets during this campaign.
It is important to emphasize that this is the first movement of funds since the completion of the third wave of attacks. The long pause in transactions could indicate that the attacker was waiting for attention to their addresses to decrease or was seeking an optimal route to bypass blockchain analytics. The choice of THORChain in this context is not accidental: this protocol allows cross-chain swaps without the need for KYC and with a high degree of anonymity.
For Coldcard holders affected by the incident, this is an alarming signal: part of the stolen funds has already been effectively removed from the control of tracking systems. However, the fact that 90% of the assets remain untouched provides hope for a possible freeze or identification of the attacker through exchanges if they attempt to withdraw fiat.
My expert commentary: Such attacks using THORChain are becoming the new standard for cybercriminals in the crypto space. Investors should reconsider their security measures: hardware wallets are not a panacea if the vulnerability lies in the firmware or the seed phrase generation process. I recommend using multi-signature and cold storage with devices isolated from the network.