Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Coldcard hacker uses THORChain to swap stolen BTC

    September 3, 2026

    Golden State Warriors sign crypto deal with Coinbase amid FTX lawsuit

    September 3, 2026

    Australia gives crypto firms Sept. 30 licence deadline

    September 3, 2026
    X (Twitter) Instagram YouTube LinkedIn
    X (Twitter) Instagram YouTube LinkedIn
    Block Hub News
    • Lithosphere News Releases
    • Crypto
    • Ethereum
    • Bitcoin
      • Litecoin
      • Altcoins
      • Coinbase
    • Blockchain
    Block Hub News
    Home » Coldcard hacker uses THORChain to swap stolen BTC
    Crypto

    Coldcard hacker uses THORChain to swap stolen BTC

    James WilsonBy James WilsonSeptember 3, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link



    A hacker associated with the third wave of Coldcard wallet thefts began converting stolen Bitcoin into Ether through THORChain on Sept. 3, according to Galaxy Research’s Alex Thorn.

    Summary

    • Third-wave Coldcard attacker moved roughly 10% of stolen Bitcoin through THORChain into Ether this week.
    • Researchers traced the swaps to a new Ethereum address and shared details with relevant authorities.
    • Around 90% of the third-wave funds remained unmoved when Galaxy researcher Alex Thorn reported transfers.
    • THORChain repeatedly refunded some swap attempts, prompting the attacker to resubmit transactions, Thorn reported Wednesday.
    • Coinkite says affected seeds require migration because installing corrected firmware cannot repair existing wallet credentials.

    The transactions moved approximately 10% of the Bitcoin controlled by that attacker, Thorn said. Roughly 90% remained at its original addresses when he published the update.

    Researchers traced the swaps through THORChain to a newly identified Ethereum address. Thorn said he shared the address with law enforcement, crypto companies and other organizations monitoring the stolen assets.

    Coldcard hacker encounters failed THORChain swaps

    THORChain allows users to exchange native assets across blockchains without depositing funds into a centralized exchange. The protocol can therefore convert native Bitcoin into Ether without relying on a conventional custodial platform.

    COLDCARD WAVE 3 HACKER SWAPS FUNDS TO ETH VIA THORCHAIN

    the wave 3 exploiter has moved stolen funds for the first time, swapping to ETH them through the THORChain cross-chain DEX

    these are the first funds from wave 1, 2, or 3 to move onchain from the original hacker addresses pic.twitter.com/jjOrX5wBR9

    — Alex Thorn (@intangiblecoins) September 2, 2026

    However, not every transaction succeeded. Thorn said the hacker appeared to be experiencing technical problems while attempting to process the swaps.

    “The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying,” Thorn said.

    The cause of the refunds was not immediately confirmed. Possible explanations include liquidity limitations, transaction settings or protocol safeguards, but no verified technical assessment had established the reason.

    The movement represented the first detected onchain transfer from the original addresses associated with the first three attack waves, according to Thorn. Analysts will now monitor whether the resulting ETH moves to centralized exchanges, bridges or privacy services.

    Galaxy traced 1,789 Bitcoin to the thefts

    Galaxy Research previously attributed the loss of 1,789.28 BTC across 8,865 addresses to the Coldcard vulnerability. The Bitcoin was worth approximately $114.7 million when stolen.

    As crypto.news previously reported, approximately 87% of the identified Bitcoin remained unmoved as of Aug. 25. The estimate included funds linked to multiple attackers and attack waves, not only the wallet now using THORChain.

    Galaxy’s figures partly relied on 221 victim reports covering 790.72 BTC. Onchain analysis identified additional affected addresses beyond those reported directly by customers.

    The total remains an estimate because researchers have identified several attacker patterns with different levels of confidence. Galaxy has distinguished its high-confidence attribution from other addresses that may also relate to the vulnerability.

    Earlier attackers used cryptocurrency mixers

    The latest THORChain swaps are separate from earlier laundering activity attributed to other attackers. CertiK reported in August that wallets linked to the broader incident sent 64 BTC and 200 ETH toward cryptocurrency mixers.

    In related coverage, crypto.news found that one attacker retained 1,159 BTC while another began mixing smaller amounts. The different movements suggest that several parties may have exploited the same weakness.

    Mixers and cross-chain swaps can complicate tracking, but they do not automatically make funds untraceable. Investigators can continue following transfers when assets enter and leave public protocols.

    Centralized exchanges remain potential intervention points because they conduct identity and sanctions checks. Thorn said the new Ethereum destination had been distributed to relevant companies so they could identify subsequent deposits.

    Coldcard users still need new wallet seeds

    The theft was linked to weak seed generation in Coldcard firmware released from 2021. The vulnerability reduced the randomness protecting some wallet credentials, allowing attackers to calculate private keys without physically accessing the devices.

    Coinkite, Coldcard’s manufacturer, says corrected firmware is available across affected models. Its current security guidance states that previously generated vulnerable seeds still require migration.

    Installing updated firmware does not repair a seed created under the affected software. Users must generate a new seed with corrected firmware and transfer their Bitcoin to addresses controlled by that new wallet.

    Meanwhile, the attacker also remained active after the largest theft waves had ended. On Aug. 29, an address linked to the operation swept Bitcoin from a deliberately weakened researcher wallet, according to Thorn. Researchers created the wallet to test whether the attacker continued searching for predictable private keys. Its rapid compromise indicated that automated scanning remained active nearly one month after the first large thefts.

    coldcard hackers are still active. here, a hacker swept keys that were generated with 5 dice rolls of added entropy 🎲 https://t.co/vJ9U7w9JxL

    — Alex Thorn (@intangiblecoins) August 28, 2026

    The incident has also prompted closer examination of how hardware wallets generate recovery phrases. Unlike phishing attacks, the Coldcard thefts did not require victims to approve transactions or reveal credentials. The exposed seeds contained insufficient randomness, allowing attackers to derive keys remotely and identify funded addresses on Bitcoin’s public ledger. As crypto.news previously explained, the firmware flaw weakened seeds generated on affected devices, meaning secure storage practices could not protect funds tied to those credentials.

    Galaxy and other investigators are expected to continue watching the new Ethereum address. No public recovery, arrest or official identification of the attacker had been announced when the transfers were reported.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    James Wilson

    Related Posts

    Australia gives crypto firms Sept. 30 licence deadline

    September 3, 2026

    Thailand SEC plans Travel Rule requiring five-year crypto transfer records

    September 3, 2026

    Backpack US appoints Solana investor Kyle Samani

    September 3, 2026
    Leave A Reply Cancel Reply

    Demo
    Top Posts

    Revolut drops Tether USDT as MiCA rules force major crypto shift

    July 5, 2026

    Allocation Update: Q4 2022 | Ethereum Foundation Blog

    July 5, 2026

    Axiom traders panic as Pump Fun temporarily bans selling memecoins

    July 5, 2026

    Nigel Farage faces watchdog probe over alleged Tether lobbying

    July 5, 2026
    Don't Miss

    Coldcard hacker uses THORChain to swap stolen BTC

    By James WilsonSeptember 3, 2026

    A hacker associated with the third wave of Coldcard wallet thefts began converting stolen Bitcoin…

    Golden State Warriors sign crypto deal with Coinbase amid FTX lawsuit

    September 3, 2026

    Australia gives crypto firms Sept. 30 licence deadline

    September 3, 2026

    Does a bitcoin rally to $100K repay El Salvador’s IMF loans?

    September 3, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Coldcard hacker uses THORChain to swap stolen BTC

    September 3, 2026

    Golden State Warriors sign crypto deal with Coinbase amid FTX lawsuit

    September 3, 2026

    Australia gives crypto firms Sept. 30 licence deadline

    September 3, 2026
    Most Popular

    Revolut drops Tether USDT as MiCA rules force major crypto shift

    July 5, 2026

    Allocation Update: Q4 2022 | Ethereum Foundation Blog

    July 5, 2026

    Axiom traders panic as Pump Fun temporarily bans selling memecoins

    July 5, 2026

    Type above and press Enter to search. Press Esc to cancel.