A hacker linked to the third wave of Coldcard wallet thefts has begun moving stolen funds for the first time, converting roughly 10% of the stolen Bitcoin into Ether through the cross-chain decentralized exchange THORChain, according to Galaxy Research head Alex Thorn.
Thorn said approximately 90% of the third-wave funds remained unmoved at their original addresses when he reported the transfers on Sept. 3. The swaps were traced to a newly identified Ethereum address, which has been shared with law enforcement, crypto companies, and other organizations monitoring the stolen assets.
The attacker appears to have encountered technical friction during the swaps. Thorn noted that THORChain repeatedly refunded some transaction attempts, prompting the hacker to resubmit them. While the exact cause of the refunds was not confirmed, possible explanations include liquidity limitations, transaction settings, or protocol safeguards.
Galaxy Research previously attributed the loss of 1,789.28 BTC across 8,865 addresses to the Coldcard vulnerability, worth approximately $114.7 million at the time. The broader estimate includes 221 victim reports covering 790.72 BTC and additional onchain findings. Earlier attackers also sent 64 BTC and 200 ETH toward cryptocurrency mixers, according to CertiK.
The underlying issue was weak seed generation in Coldcard firmware released from 2021, which reduced randomness and allowed attackers to derive private keys remotely. Coinkite, Coldcard’s manufacturer, has released corrected firmware, but warns that affected users must generate a new seed and transfer funds; installing updated firmware does not repair previously generated vulnerable seeds. Researchers also noted that automated scanning remained active as late as Aug. 29, when an address linked to the operation swept Bitcoin from a deliberately weakened test wallet.