Coldcard Wallet Hacker Moves $1.6 Million in Bitcoin via THORChain Swap
Hackers behind the $114.7 million Coldcard wallet exploit have begun moving stolen funds, transferring 20.5 Bitcoin via THORChain to obfuscate the trail, while 87.3% of the loot remains stationary.

The investigation into the high-profile Coldcard hardware wallet hack has taken a significant turn. After weeks of relative inactivity, approximately 20.5 Bitcoin (BTC), valued at roughly $1.6 million, has begun moving through THORChain, a decentralized liquidity protocol that enables cross-chain asset swaps. According to blockchain analysts, the stolen funds were moved across 34 separate transactions between September 2 and September 3.
This development indicates that the attacker is actively attempting to obfuscate the paper trail. Instead of leaving the cryptocurrency in the original addresses flagged by security firms, the hacker is swapping Bitcoin to the Ethereum blockchain, making it significantly harder for investigators to track the flow of funds.
First Movement Confirmed
The transaction activity was confirmed by Galaxy Research, which has been monitoring the exploit since its discovery. Alex Thorn, Head of Research at Galaxy, noted that this represents the first confirmed movement of funds from the attacker's original addresses associated with the first three waves of the hack.
During the THORChain swaps, the attacker reportedly encountered several refund errors but persisted with the transactions. This suggests the movement might be a test run to establish a viable laundering pathway rather than a full-scale conversion of the stolen assets.
While swapping assets across different blockchains via THORChain adds a layer of complexity for investigators and exchanges, it does not render the funds completely untraceable. Blockchain ledgers remain public, allowing blockchain intelligence firms to link addresses and transactions. Galaxy Research has already shared the newly identified addresses with major cryptocurrency exchanges, compliance firms, and law enforcement agencies to facilitate blacklisting.
Over $100 Million Still at Risk
Despite this recent movement, the vast majority of the stolen cryptocurrency remains stationary. According to Galaxy Research, the exploit compromised a total of 1,789.28 BTC across 8,865 addresses, valued at approximately $114.7 million at the time of the theft.
Currently, about 1,561 BTC—representing 87.3% of the total stolen funds—remains untouched in addresses controlled by the attacker. This explains why the movement of just 20.5 BTC has drawn intense scrutiny from the cybersecurity community, as it could signal the beginning of a larger cash-out operation.
A Remote Firmware Vulnerability
The Coldcard hack was highly unusual because it did not require physical access to the hardware wallets. According to joint investigations by Galaxy Research and TRM Labs, the exploit leveraged a vulnerability in a 2021 firmware version that compromised the cryptographic randomness of seed phrase generation.
This flaw allowed the attacker to reconstruct private keys for wallets initialized under the vulnerable firmware and drain them remotely. TRM Labs reported that the attacks began on July 30 and were executed in multiple waves.
At this stage, the recent transactions do not prove that the hacker has successfully laundered the funds or converted them into fiat currency. The bulk of the stolen assets remains monitored and frozen in place, but the industry is on high alert to see if this minor transfer is the precursor to a massive liquidation effort.





