THORChain Used by Coldcard Attacker to Convert Stolen BTC into Ethereum

THORChain Used by Coldcard Attacker to Convert Stolen BTC into Ethereum

Approximately 10% of the illicitly obtained Bitcoin from the third-wave Coldcard breach has been transferred through THORChain, with security analysts successfully tracking the converted assets to a fresh Ethereum wallet.

An attacker connected to the third wave of security breaches targeting Coldcard wallets has begun converting stolen Bitcoin into Ether using the THORChain platform.

On Wednesday, Alex Thorn, who serves as Galaxy's head of research, shared on X that the exploiter behind the third wave had transferred approximately 10% of the pilfered cryptocurrency, leaving 90% of the stolen assets still untouched. According to Thorn, this represented the first instance where funds from any of the three distinct waves of attacks had been moved onchain from the hacker's original wallet addresses.

The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying.

According to Thorn, blockchain analysts successfully followed the cryptocurrency through THORChain to a previously unknown Ethereum address, and he noted that this information has been provided to both relevant law enforcement authorities and cryptocurrency companies. Whether the perpetrator will make additional attempts to conceal the assets further or transfer them through a centralized exchange platform remains to be seen, Thorn noted.

These recent transfers are connected to a Coldcard security breach that Galaxy Research associated with the theft of no less than 1,789 Bitcoin across 8,865 separate addresses, representing a value of approximately $114.7 million at the point in time when the cryptocurrency was stolen. In August, blockchain security firm CertiK disclosed that hackers associated with the security breach had transferred 64 Bitcoin along with 200 Ether to cryptocurrency mixing services including Tornado Cash.

This most recent activity in moving the stolen funds occurred just days following Thorn's statement that the Coldcard attackers continued to operate actively, pointing to the Aug. 28 draining of an intentionally vulnerable researcher wallet that had been created specifically to evaluate the attackers' capabilities in identifying compromised keys.

← Back to Blog