Community Trust ScoreVerified
A hacker behind the Coldcard wallet exploits just made their first onchain move. About 10% of the stolen Bitcoin got swapped for Ether through THORChain — and it didn’t go smoothly.
Galaxy’s head of research, Alex Thorn, flagged the activity on Wednesday. The funds moved for the first time from the original hacker addresses, which had sat completely still until now. Thorn’s read: 90% of the stolen Bitcoin is still untouched. That’s a lot of money sitting in limbo — and a lot of potential moves still to come. The new Ethereum address where the swapped funds landed has already been shared with authorities and crypto companies to support ongoing investigations.
Not a clean getaway.
THORChain Swaps Hit Refund Loops
The hacker didn’t exactly pull this off without a hitch. Attempts to push the full amount through THORChain kept getting rejected — refunds came back, and the hacker had to retry repeatedly. It’s unclear why the platform kept bouncing the transactions, but the pattern probably points to size limits or liquidity constraints on the cross-chain protocol. Either way, the hacker’s persistence is pretty clear. They kept trying, kept getting kicked back, and still managed to move a chunk of it.
THORChain is a decentralized cross-chain liquidity protocol that lets users swap native assets — like Bitcoin to Ether — without wrapping or using a centralized exchange. It’s exactly the kind of tool someone trying to avoid a paper trail would reach for. No KYC. No account. Just a wallet and a transaction. The hacker knew what they were doing, even if the execution got messy.
The funds traced to a new Ethereum address. That’s the detail that matters most right now for investigators.
What Galaxy Found in the Coldcard Data
Galaxy Research tied the Coldcard hack to the theft of at least 1,789 Bitcoin, pulled from 8,865 separate addresses. At the time of the theft, that came out to roughly $114.7 million. It’s a big number — and most of it is still sitting there, which is almost as unnerving as watching it move.
Back in August, blockchain security firm CertiK reported that hackers tied to the Coldcard exploit had already pushed 64 Bitcoin and 200 Ether through cryptocurrency mixers, including Tornado Cash. Tornado Cash has been a go-to for bad actors trying to break the onchain link between stolen funds and their destination wallets. The fact that mixing activity happened before this THORChain swap suggests the hacker has been working through a layered strategy — not just rushing to cash out.
Thorn had flagged on August 28 that the attackers were still active. The evidence? They swept a researcher wallet that had been set up specifically to test whether the hackers could spot vulnerable keys. They could. They did. That detail matters because it means whoever is behind the Coldcard exploit isn’t just sitting on funds waiting for heat to die down — they’re still probing, still testing, still moving.
90% Still Untouched — and That’s the Problem
Here’s the uncomfortable part. The hacker moved maybe 10% and it already triggered a full response from analysts, authorities, and crypto firms. What happens when the other 90% starts moving?
Stolen funds sitting in original addresses can feel like a kind of stalemate. Analysts watch. Exchanges get flagged. Investigators build cases. But the moment funds start flowing — even a small percentage — the whole picture shifts fast. New addresses, new chains, new mixers. The trail gets harder to follow with every hop.
Crypto theft at this scale isn’t new. Decentralized platforms have become the preferred infrastructure for moving stolen assets precisely because there’s no central party to freeze accounts or reverse transactions. That’s a feature for legitimate users and a massive advantage for bad actors. Law enforcement has gotten better at tracing cross-chain activity, but it’s still a hard problem — especially when a hacker is patient enough to let funds sit for months before touching them.
The Coldcard case has been building for a while. The third wave of exploits, which Galaxy linked to these specific addresses, showed a level of technical sophistication that set it apart from opportunistic wallet drains. Identifying vulnerable keys across nearly 9,000 addresses isn’t casual work.
And now, with the first onchain movement confirmed, the investigation enters a new phase. Thorn’s team traced the Ethereum address. Authorities have been briefed. Crypto companies are watching for any attempt to deposit or convert at a centralized venue.
The hacker still holds roughly $103 million worth of Bitcoin — untouched, unmoved, sitting in addresses that everyone in the industry now knows about.
Frequently Asked Questions
How much Bitcoin did the Coldcard hacker steal in total?
Galaxy Research linked the hack to the theft of at least 1,789 Bitcoin from 8,865 addresses, valued at approximately $114.7 million at the time of theft.
Why did the hacker use THORChain to move the stolen funds?
THORChain is a decentralized cross-chain protocol that allows native asset swaps without KYC or a centralized intermediary, making it harder to trace or freeze funds compared to traditional exchanges.
Why It Matters
The movement of stolen Bitcoin, particularly the swap for Ether, highlights the ongoing challenges of tracking illicit activities within the cryptocurrency ecosystem. The fact that the majority of the stolen funds remain untouched points to a potential strategy by the hacker to avoid detection, raising concerns about security and regulatory responses in the crypto space. As market participants observe these developments, they may reassess the risks associated with certain wallets and decentralized exchanges, influencing future trading behaviors and regulatory scrutiny.
