Newsroom
4 September, 2026 / News / AI / Tags: thorchain, coldcard, addresses, bitcoin, hacker

A third-wave exploiter moved roughly 10 percent of linked Bitcoin holdings through the cross-chain protocol, marking the first on-chain activity from the original addresses
A hacker tied to the third wave of Coldcard hardware wallet thefts has started converting a portion of the stolen Bitcoin into Ether using the THORChain protocol. The transfers, reported on September 3, 2026, represent the first detected movement of funds from the original addresses associated with the main attack waves.
Galaxy Research head of research Alex Thorn stated that the attacker shifted approximately 10 percent of the Bitcoin under that actor’s control. About 90 percent of those holdings remained at their original addresses at the time of the update. On-chain analysts traced the swaps to a newly identified Ethereum address, which Thorn shared with law enforcement, crypto companies, and other monitoring organizations.
THORChain enables native asset exchanges across blockchains without requiring deposits into a centralized platform. The protocol allowed the conversion of Bitcoin directly into Ether. Not all attempts succeeded. Repeated refunds forced the attacker to resubmit transactions, though the precise technical reason for the failures remained unconfirmed. Possible factors include liquidity constraints or protocol settings.
Researchers described the activity as the first on-chain transfer from the original hacker addresses linked to the first three waves of the exploit. Investigators are now watching whether the resulting Ether proceeds to centralized exchanges, bridges, or privacy tools.
Galaxy Research has attributed the loss of 1,789.28 Bitcoin across 8,865 addresses to the vulnerability. The Bitcoin was valued at approximately $114.7 million at the time of the thefts. Earlier assessments indicated that the large majority of identified funds had stayed unmoved for weeks after the initial drains.
The broader incident involved multiple attackers and attack patterns. Galaxy’s analysis combined high-confidence attributions with additional addresses identified through on-chain methods and victim reports covering hundreds of Bitcoin.
In August, CertiK reported that wallets connected to the incident had already directed 64 Bitcoin and 200 Ether toward cryptocurrency mixers. Separate activity showed one party holding a large unmoved balance while others began smaller mixing operations, pointing to several distinct actors exploiting the same weakness.
The attacker remained active after the primary theft waves. On August 28 or 29, an address linked to the operation swept Bitcoin from a researcher-controlled wallet that had been deliberately weakened to test continued scanning for predictable keys. The rapid compromise indicated automated searches were still underway nearly a month after the first large drains.
The underlying issue stemmed from weak seed generation in Coldcard firmware released beginning in 2021. Insufficient randomness in the affected software allowed private keys to be calculated without physical access to the devices. Coinkite, the manufacturer, has released corrected firmware for affected models. However, the company states that seeds generated under the vulnerable versions cannot be repaired by a firmware update alone. Users must create new seeds with the fixed software and move funds to addresses controlled by those new wallets.
Centralized exchanges remain potential points for intervention because of identity and compliance checks. The newly identified Ethereum destination has been distributed to relevant firms to flag any subsequent deposits. No public recovery of funds, arrests, or official identification of the responsible parties had been announced when the THORChain transfers were reported.









