The attacker behind the third wave of the Coldcard hardware wallet exploit has begun moving stolen funds for the first time, swapping a portion of the Bitcoin into Ether through THORChain, according to Galaxy Research analyst Alex Thorn.
Roughly 10% of the Bitcoin tied to the wave-three attacker address has been converted so far, marking the first onchain movement from any of the wave 1–3 hacker wallets since the exploit was first detected in late July. Galaxy Research has been tracking the theft since it began, and its most recent tally put confirmed losses at 1,789.28 BTC — worth roughly $114.7 million at the time of theft — spread across nearly 8,900 addresses.
The vulnerability traces back to a March 2021 firmware build error on Coinkite’s Coldcard devices, which caused private keys to be generated with insufficient randomness. Every single-signature address created on an affected device before the flaw was patched remains exposed, and Galaxy has repeatedly urged holders to move funds to freshly generated seeds immediately.
The saga began on July 30 with a first wave of sweeps, followed by additional waves that pushed loss estimates from an initial $70 million to well past $100 million within days, according to a series of Galaxy Research updates published throughout early August.
Until now, more than 87% of the stolen Bitcoin had sat untouched in attacker-controlled wallets, a pattern Galaxy interpreted as evidence the thief was waiting out scrutiny before attempting to cash out. Moving funds into ETH via a cross-chain protocol like THORChain, rather than routing directly to a centralized exchange, suggests an attempt to break the onchain trail that has let researchers and law enforcement trace the funds this closely. Galaxy said it has already shared roughly 600 suspected attacker addresses with federal investigators, exchanges and compliance firms.
For holders still storing keys on a Coldcard, the practical takeaway hasn’t changed: any single-sig wallet generated on a vulnerable device before the fix should be treated as compromised, regardless of how long it has sat untouched.