Have you ever looked at a hardware wallet and felt that quiet, slightly smug sense of safety? I have. That little brick is supposed to be the grown-up version of crypto storage: keys offline, seeds locked down, no late-night click that empties the account. Then a story like this lands, and the smugness evaporates. A thief tied to the third wave of Coldcard wallet thefts has started converting stolen Bitcoin into Ether through THORChain, and the move is the first clear on-chain activity from the original stash addresses linked to those early waves.
What Changed When The Stolen Bitcoin Finally Moved
For weeks the coins just sat there. That is the part that always gets under my skin. Huge thefts often look dramatic on day one and then go quiet, as if the attacker is waiting for attention to fade. This time the wait ended. On-chain researchers watching the third-wave cluster saw a slice of the stolen Bitcoin routed through a cross-chain swap protocol and come out the other side as Ether.
The amount was not the whole pile. Far from it. Roughly 10% of the Bitcoin controlled by that particular attacker appears to have been pushed through the swap path. About 90% was still sitting at the original addresses when the first public update went out. That split matters. It tells you the operator is testing an exit, not dumping everything in a single panicked blast.
Researchers followed the path to a newly identified Ethereum address and circulated that destination among investigators, compliance teams, and firms that watch tainted funds. No public arrest, no confirmed recovery, no named suspect. Just a new hop on a ledger that never forgets.
The wave three exploiter has moved stolen funds for the first time, swapping them to ETH through a cross-chain DEX. These are the first funds from the earlier waves to leave the original attacker addresses.
I keep coming back to that phrase: first funds to move. After a theft measured in the thousands of Bitcoin, stillness can look like confidence. Movement looks like a plan. And plans, once they touch a public protocol, give watchers something to follow.
Why A Cross-Chain Swap Is A Different Kind Of Exit
THORChain is built for a specific job. It lets people exchange native assets across chains without parking coins on a conventional custodial exchange first. In plain English, someone can take native Bitcoin and receive Ether without handing the pile to a company that asks for an identity document. That is the appeal. It is also the headache for anyone trying to intercept stolen coins at the front door of a regulated venue.
Does that make the coins invisible? No. Public protocols still leave footprints. You can see the inbound Bitcoin, the swap mechanics, the outbound Ether, and the new address that receives it. What you lose is the easy choke point. A centralized exchange can freeze a deposit. A decentralized swap rail is closer to a public highway. Cars still have plates. The toll booth is just missing.
In my experience, this is the moment when commentary gets sloppy. People say “untraceable” when they mean “harder.” Harder is already bad enough for victims. Untraceable is a marketing word. Investigators will now watch whether that Ether travels toward a centralized venue, a bridge, or a privacy service. Each of those next hops changes the odds of recovery.
The Swap Did Not Go Smoothly
Here is the almost comic part, if a theft this large can have one. The attacker seemed to struggle with the swaps. Transactions came back as refunds. Then the same flow was submitted again. Then refunded again. It looked less like a masterclass and more like someone wrestling with a vending machine that keeps spit out the same coin.
Nobody has published a definitive technical autopsy of those refunds. Liquidity limits are one possible explanation. Slippage settings are another. Protocol safeguards could also reject a route that looks too large, too clumsy, or too poorly parameterized. I would not pretend to know which one it was. I would only note that retry behavior is useful to watchers. Repeated attempts create a pattern. Patterns are easier to attribute than a single clean transfer.
Perhaps the most interesting aspect is the human one. People imagine elite thieves as silent and precise. On-chain, they sometimes look impatient. They poke the same button. They leave a trail of failed attempts. That does not make the theft smaller. It does make the operator less mythical.
- Only a minority of the third-wave stash moved in the first observed swap burst.
- Most coins remained on the original Bitcoin addresses after the report.
- The destination was a fresh Ethereum address circulated to monitors.
- Several swap attempts were refunded before funds completed the route.
- Watchers now care less about the first hop and more about the second.
How Large The Coldcard Losses Really Were
On-chain analysis previously tied about 1,789.28 BTC across 8,865 addresses to the Coldcard vulnerability cluster. At the time of the thefts, that stack was valued around $114.7 million. Those numbers are estimates, not a courtroom ledger. Researchers have been careful to separate high-confidence clusters from addresses that only look related.
Part of the picture came from victim reports. Hundreds of people described losses totaling hundreds of Bitcoin. The rest came from ledger analysis that found additional funded addresses matching the same weak-key pattern. That mix of self-reporting and chain forensics is messy, but it is how these cases usually get sized in public.
By late August, researchers estimated that roughly 87% of the identified Bitcoin still had not moved. That figure covered more than one attacker and more than one wave. It was not a snapshot of the single wallet now using THORChain. Keep that distinction in your head. Several operators appear to have exploited the same weakness, and they are not behaving like a single coordinated desk.
| Piece of the case | What researchers reported | Why it matters |
| Total attributed BTC | About 1,789 BTC across thousands of addresses | Sets the scale of the firmware-linked losses |
| Third-wave movement | Roughly 10% swapped toward Ether | First clear exit attempt from original addresses |
| Still idle | About 90% of that attacker’s coins unmoved at report time | Suggests a staged cash-out, not a full dump |
| Earlier laundering | Smaller amounts sent toward mixers by other wallets | Shows multiple playbooks, not one method |
I’ve found that tables like this help because crypto incidents get flattened into one headline. “The hacker did X.” There is rarely one hacker. There is a weakness, then a crowd that notices, then a set of different exit styles. Some sit. Some mix. Some swap. The Coldcard case has already shown all three.
This Swap Is Not The Same As Earlier Mixer Traffic
Before this THORChain activity, other wallets tied to the broader incident had already tried a more familiar laundering path. Security researchers reported that some related addresses sent tens of Bitcoin and a couple hundred Ether toward mixers. Separate coverage of the same cluster found one operator still holding well over a thousand Bitcoin while another started mixing smaller cuts.
That divergence is the story under the story. If this were one person with one strategy, the chain would look cleaner. It does not. One stash barely twitches. Another leaks into mixing services. A third starts cross-chain swapping and keeps getting refunded. You can believe those are different desks. You can also believe one desk is experimenting. Either way, the operational picture is fragmented.
Mixers and cross-chain swaps both muddy the water. Neither erases the water. Assets still enter a public contract or a public pool. Assets still leave. The analytics problem becomes a graph problem: more edges, more decoys, more time. Time is often the attacker’s friend. It is also the investigator’s raw material.
Cross-chain rails and mixers can slow a chase. They do not automatically end it. The dangerous moment is usually the return to a venue that checks names.
Centralized exchanges remain the practical intervention point. They run identity checks. They watch sanctions lists. They can hold a deposit long enough for a conversation with law enforcement. That is why the new Ethereum destination was shared quickly. If those coins later hit a known deposit address, someone on a compliance team might actually have a lever.
The Real Flaw Was Weak Seed Generation
This was not a classic phishing story. Victims did not approve a malicious transaction. They did not paste a seed into a fake site. They generated recovery phrases on affected Coldcard firmware released from 2021, and those phrases did not contain enough randomness. Once the entropy is weak, an attacker can calculate private keys without touching the device.
That last sentence is the one that should make hardware-wallet fans sit up. Physical custody is not the whole game. If the seed itself is predictable, the steel box becomes a prop. The attacker can sit somewhere else, derive candidate keys, scan the public Bitcoin ledger, and wait for funded addresses to appear. No shoulder surf. No stolen laptop. Just math and patience.
The manufacturer has shipped corrected firmware across affected models. That is necessary. It is not sufficient for anyone who already generated a vulnerable seed. Updated software does not heal an old phrase. The seed is the credential. If the credential was born weak, you migrate. You generate a new seed on fixed firmware. You move the coins. You treat the old wallet as burned.
- Confirm whether your device ran affected firmware when the seed was created.
- Generate a fresh seed on corrected firmware, not a patched version of the old phrase.
- Create new receiving addresses from that new seed.
- Move funds in deliberate batches and verify the destination on the device screen.
- Retire the old seed as if it were already public.
People hate this advice because it is housework. Migration is boring. It is also the only repair that matches the actual failure. I have watched too many users install an update and assume the past is cleaned. Firmware can stop the next weak seed. It cannot rewrite the last one.
The Attacker Did Not Clock Out After The Big Waves
One detail from late August is easy to skip and should not be. An address linked to the operation swept Bitcoin from a deliberately weakened researcher wallet. The wallet had been created as bait, with thin extra entropy from a handful of dice rolls. It was compromised quickly. That is a grim little experiment with a clear result: automated scanning was still alive nearly a month after the first large thefts.
Think about what that implies. The profitable wave may have passed. The scanner did not get the memo. Scripts do not feel shame. They keep grinding candidate keys and watching the chain. If you generated a weak seed years ago and still have a dusty balance on it, the calendar is not your friend.
Is every leftover balance doomed? Not automatically. High-confidence clusters are not the same as every Coldcard ever sold. Still, the conservative posture is obvious. If there is any chance your seed was born on affected firmware, treat migration as unpaid insurance. The premium is time. The deductible is everything in the wallet.
What Hardware Wallets Were Supposed To Solve
Hardware wallets exist because hot wallets are sloppy. Phishing works. Malware works. Clipboard hijacks work. The pitch has always been simple: keep the key material off the internet-connected machine, confirm transactions on a trusted screen, and sleep. That pitch is still mostly right. This case does not kill the category. It punches a hole in a specific assumption about seed quality.
Randomness sounds abstract until it fails. A recovery phrase is only as strong as the entropy that produced it. If the generator leans on a narrow range of possible outcomes, the phrase stops being a secret and starts being a search problem. Attackers love search problems. Computers are good at those.
Secure storage habits cannot rescue a weak credential. A metal backup plate will not help if the words stamped into it were guessable. A fireproof box will not help. A passphrase on top can raise the cost, depending on how it was chosen, but the core lesson remains ugly and simple: generation quality is part of custody. Not an extra. Part.
Custody stack, stripped down: 1. Strong seed generation 2. Honest device screen 3. Careful destination checks 4. Migration when a generation flaw appears Skip step one and the rest becomes theater.
Why Most Of The Coins Are Still Sitting There
Idle stolen Bitcoin is a genre now. After a big grab, coins often freeze. Sometimes the thief is waiting for price. Sometimes the thief is waiting for analytics firms to get bored. Sometimes the thief cannot cash out without walking into a venue that will ask questions. Sometimes there are several thieves and they do not share a playbook.
The third-wave operator moving 10% feels like a probe. Send a slice. See if the route works. See if the new Ethereum address draws heat. See if refunds keep happening. If the slice survives, larger cuts may follow. If the slice gets marked everywhere that matters, the rest may stay parked for months.
I’ve found that readers want a movie ending. Either the coins vanish into fog or the villain gets cuffed before the credits. Real cases linger in the middle. Addresses get labeled. Exchanges get circulars. A few deposits get frozen. A lot of value just waits. Waiting is not innocence. Waiting is strategy.
What Investigators Will Watch Next
The first question is simple. Does the new Ether stay put, or does it travel? If it travels, where? A regulated exchange deposit is the scenario victims should root for, because that is where policy and law still have teeth. A bridge into another ecosystem expands the maze. A privacy tool compresses the useful signal.
The second question is whether other idle clusters copy the move. Copycats are common once a route looks viable. If THORChain refunds keep happening, the operator may switch rails. If the swaps clear cleanly, expect more volume. Either outcome is information.
The third question is operational continuity. The bait wallet sweep suggested the hunting process never fully stopped. That means newly funded weak addresses can still be vacuumed. It also means researchers can keep planting canaries. Canaries are grim. They work.
- Watch the fresh Ethereum address for outgoing transfers.
- Watch whether remaining Bitcoin on original addresses starts to move in matching patterns.
- Watch for deposits to venues that can freeze funds.
- Watch for a shift from swaps to mixers, or the reverse.
- Watch for more bait wallets getting emptied, which would confirm ongoing scanning.
What This Means If You Hold Bitcoin On A Device
Let me be blunt. If your seed was created on affected Coldcard firmware, the debate is over. Move. Not later this quarter. Now. Generate a new seed on current firmware and treat the old one as compromised even if nothing has left the address yet. Empty addresses can still be watched. Funded ones are invitations.
If you are not sure which firmware created the seed, assume uncertainty is a risk factor. Check the manufacturer’s current guidance. Check the device version history if you kept notes, and most people did not. When notes are missing, migration is cheaper than a philosophical argument with yourself at 2 a.m.
If your seed was created on a different device family, do not use this incident as cheap panic. Do use it as a prompt. How was your phrase generated? Did you add real entropy, or did you trust a black box? Did you ever type that phrase into a computer? Did anyone photograph a backup card? Hardware is only one layer. Habits are the rest.
And if you are tempted to leave coins on a weak seed because “the attacker already took the easy money,” that is a story people tell themselves. Automated scanners do not get full. They get scheduled.
The Uncomfortable Lesson About Trust In Gadgets
Crypto culture loves objects. The steel plate. The air-gapped box. The seed carved into something that could survive a house fire. Those objects are useful. They also become talismans. People start believing the object is the security model. It is not. The security model is the quality of secrets plus the discipline around those secrets.
When a firmware generator underperforms, the talisman fails quietly. No red warning on the screen. No dramatic exploit demo on a conference stage. Just a smaller-than-advertised universe of possible phrases, and someone out there enumerating that universe. Quiet failures are worse than loud ones. Loud ones get patched in public. Quiet ones sit in drawers for years.
I do not think this means hardware wallets are a joke. That conclusion is lazy. Software wallets on infected laptops remain a carnival of bad outcomes. The better conclusion is narrower and less satisfying: verify the generation story, not just the brand story. Ask how entropy is collected. Ask what happens if that process was flawed two firmware versions ago. Ask whether you can migrate without drama.
A hardware wallet is a tool for protecting a secret. If the secret was weak at birth, the tool is guarding an unlocked door.
Why Public Ledgers Still Help The Good Guys
It is fashionable to say Bitcoin thefts are unrecoverable because the chain is public and irreversible. Public is the painful part and the useful part at the same time. Irreversible transfers hurt victims. Public history helps analysts rebuild the path. That tension never goes away.
In this case, the public trail is what revealed the THORChain hops, the refund loop, the new Ethereum address, the idle majority, and the separate mixer flows. None of that required a confession. It required people who know how to read a ledger and enough patience to keep looking after the first headline cooled.
Will that trail produce a courtroom ending? Maybe not. Plenty of crypto thefts end in labeled addresses and shrugged shoulders. But a trail still constrains the thief. Every extra hop is a chance to make a mistake. Every regulated deposit is a chance to get stuck. Constraint is not justice. It is not nothing either.
A Cleaner Way To Think About Cross-Chain Risk
Cross-chain protocols are not villains in this story. They are infrastructure. Infrastructure gets used by whoever shows up. The same rail that helps a trader move native Bitcoin into Ether without a custodian also helps a thief test an exit. Blaming the rail is like blaming a highway for a stolen car. Useful as a rant. Weak as analysis.
The sharper question is operational. Do these protocols have enough liquidity to absorb large tainted flows without weird refunds? Do they create durable identity anchors that analytics firms can cluster? Do destination chains have better or worse exchange coverage for freezes? Those are the adult questions. “Decentralized equals dark” is a slogan.
In my view, the refunds are a reminder that even slick rails have friction. Friction produces retries. Retries produce telemetry. Telemetry is how a sloppy cash-out becomes a research note.
What Victims Can Still Do
If your coins were already swept, migration advice arrives too late. The remaining options are slower and less cinematic. Document the old addresses. Preserve device details and purchase records. File reports where they can actually be received. Share transaction identifiers with investigators who already understand this cluster rather than starting from zero with a generic inbox.
Should you expect the money back next week? I would not sell that hope. Some frozen deposits do come back in other cases. Many do not. The honest pitch is narrower: make the coins easier to recognize if they surface. Labeled funds are less convenient to spend. Inconvenience is sometimes the only pressure available.
If you still control a related wallet that was not emptied, prioritize the move. Split the transfer if the amount is large. Verify every character on the hardware screen. Do not reuse the old seed for “just one more receive.” That sentence has wrecked people.
The Broader Hardware Wallet Conversation This Forces
Every few years the industry rediscovers that seed generation is not a solved aesthetic problem. It is an engineering problem with human consequences. Dice workflows, secure elements, deterministic checks, and firmware audits all sound dry until a four-digit number of addresses get cleaned out.
Users also have a part in this, and I say that carefully because victim-blaming is cheap. Nobody should need a cryptography seminar to store savings. At the same time, people who treat a seed like a grocery list will keep getting hurt by flaws that are not phishing. Write the phrase down once, store it like it is a bearer instrument, and know which firmware created it. That is not maximalist cosplay. That is basic custody.
Manufacturers, for their part, have to live with an ugly standard: a silent generation bug is an existential product event. Patches help future devices. They do not automatically save the installed base. Communication has to be painfully clear on that point. “Update your firmware” is incomplete if the seed remains the same.
Where The Story Stands Today
As of the latest public tracing update, a third-wave operator has started swapping a minority of stolen Bitcoin into Ether through THORChain. The majority of that operator’s coins had not moved. The destination address was new, shared with monitors, and still sitting in the phase where everyone waits for the next hop. Other attackers in the wider cluster had already tried mixers. The manufacturer’s position remains that vulnerable seeds need replacement, not a software blessing.
No official identification of the attacker had been announced when the swaps were reported. No public recovery of the main stash either. The chain is still the chain. The coins are still coins. The only new fact is motion.
Motion is what converts a cold case into a live one. It may also be what converts a live one into a dead end if the next addresses are prepared well. That uncertainty is irritating. It is also honest. Anyone promising a neat ending this week is selling comfort.
I keep thinking about the first time I bought a hardware wallet and felt finished. Finished is a feeling, not a state. Custody is a practice. This week’s swaps are a reminder written in public ink: weak secrets do not stay theoretical, idle stolen coins do not stay idle forever, and the first messy cross-chain attempt can tell you more than a month of silence ever did.