Crypto Prices

Third-wave Coldcard hacker converts stolen Bitcoin to Ether via THORChain

18 hours ago
1 min read
4 views

Coldcard Wallet Hacks: A New Development

The ongoing saga of the Coldcard wallet hacks has taken a significant turn as the hacker, identified as part of the third wave of exploiters, has begun converting a portion of the stolen assets. Reports indicate that approximately 10% of the pilfered Bitcoin has been exchanged for Ether using the decentralized exchange THORChain, while the vast majority, estimated at 90%, remains untouched.

Tracing the Stolen Assets

Alex Thorn, the head of research at Galaxy, publicly detailed these transactions on social media platform X, highlighting that this activity marks a notable first: funds from any of the three exploit waves have now been traced on-chain from the original addresses associated with the hacker.

Thorn noted that the hacker seems to face challenges during the swapping process on THORChain, encountering multiple refunds and repeatedly attempting the transactions.

Analysts from the blockchain community followed the trajectory of these funds and successfully linked them to a newly created Ethereum address. Thorn has since shared this information with relevant authorities and various players in the crypto industry, although it remains unknown whether the hacker intends to further obscure these assets or transfer them through traditional exchanges to facilitate covert access.

Investigation and Implications

This recent development is part of a more extensive investigation following the Coldcard exploit, which Galaxy Research has tied to the theft of at least 1,789 Bitcoin from a staggering 8,865 individual addresses, with the total value calculated at around $114.7 million at the time of the theft.

In a separate report, blockchain security firm CertiK revealed in August that hackers connected to this exploit had funneled 64 Bitcoin and 200 Ether into cryptocurrency mixers like Tornado Cash, aiming to obfuscate the origin of the stolen funds.

These movements of stolen cryptocurrency come shortly after Thorn raised concerns about the ongoing activities of the Coldcard attackers, referencing a particular incident on August 28 where they had successfully targeted a researcher wallet that was intentionally designed to lure such exploits, revealing the attackers’ ability to find and exploit vulnerable keys.

Popular