Home Coldcard Hacker Converts About 20.5 Bitcoin To ETH After Weeks Of Inactivity

Coldcard Hacker Converts About 20.5 Bitcoin To ETH After Weeks Of Inactivity

Share
Coldcard Hacker Converts About 20.5 Bitcoin To ETH After Weeks Of Inactivity
News
Share

The operator linked to the third wave of the Coldcard hardware-wallet exploit has begun moving stolen Bitcoin into Ether after weeks of inactivity. About 20.5 BTC from the Wave 3 cluster was moved through the cross-chain exchange THORChain, with the resulting funds landing on Ethereum.

The transfers are the first confirmed movement from the original attacker addresses connected to the three documented Coldcard theft waves.

Alex Thorn, head of research at Galaxy, reported the transactions late Wednesday. His onchain analysis traced the Bitcoin from victim addresses through collection wallets and a series of 2-of-2 transactions before the funds reached THORChain.

The movement is significant because most of the Bitcoin connected to Wave 3 had remained untouched. Thorn later noted that about 90% of the Wave 3 holdings were still unmoved, while several attempted swaps were refunded before later transactions succeeded.

The latest activity does not change the estimated scale of the overall theft. Galaxy’s later public figures have placed high-confidence losses at around 1,789 BTC across more than 8,800 addresses. Those coins were worth about $115 million at the time of the theft.

Wave 3 was different from the earlier thefts. Researchers identified hundreds of separate vaults rather than a single collection address. Until September 2, the transactions were understood to involve hash-locked outputs. The first spend revealed a 2-of-2 multisignature setup, followed by additional transfers using similar structures with different key pairs.

Thorn also observed differences in the wallet behaviour used for the latest cash-out. The transactions used replace-by-fee, recent locktimes and higher fees. THORChain deposits appeared to come through another interface and included an OP_RETURN memo and an affiliate tag.

These details can help researchers track activity on the blockchain, but they do not identify the person or group behind the transactions. The thefts were linked to a seed-generation flaw in certain Coldcard firmware. Coinkite disclosed that some firmware released from March 2021 onward could generate seeds with weaker entropy than intended.

The vulnerability did not allow attackers to remotely take control of Coldcard devices. Instead, attackers were able to reconstruct private keys offline and then spend funds from affected addresses.

Coinkite later released a firmware update and warned users that updating the software would not repair a seed that had already been created on vulnerable firmware. Users were advised to generate a new seed using fixed firmware and move their funds.

Co-founder Rodolfo Novak also apologised publicly and said the company had shipped a hotfix that removed the software fallback path. He urged users to migrate their funds before going through further technical details.

The company said TAPSIGNER, OPENDIME and SATSCARD use different code and were not covered by the same security advisory. It also said seeds created using at least 50 independent private dice rolls were considered an exception because the dice supplied the necessary entropy.

The latest Wave 3 transactions do not change that advice. Bitcoin still sitting in affected addresses remains exposed if the original seed was created using vulnerable firmware.

Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV

Share
Written by
Kapil Rajyaguru -

Kapil Rajyaguru is a news editor at 3.0 TV with over 15 years of professional writing experience and more than four years dedicated to the cryptoverse.

An engineer by education and a writer by passion, Kapil brings a rare mix of technical insight and storytelling finesse. A firm believer that cryptocurrencies, blockchain and AI are the building blocks of the future, he crafts in-depth news and analysis to educate, empower and prepare the masses for the next frontier of Web3.

Leave a comment

Leave a Reply

Latest News

Tether’s USDT0 Launches On Stellar, Bringing Cross-chain USDT Liquidity
News

Tether’s USDT0 Launches On Stellar, Bringing Cross-chain USDT Liquidity

Tether-backed cross-chain stablecoin liquidity is now available on Stellar with the launch of USDT0. The integration connects USDT0 across compatible blockchains using...

ASIC Sets September 30 Deadline For Crypto Firms To Apply For Financial Services License
News

ASIC Sets September 30 Deadline For Crypto Firms To Apply For Financial Services License

Australian cryptocurrency companies have until September 30, 2026, to apply for financial services licenses, according to ASIC. In order to operate under...

SEC Moves To Clarify Crypto Fundraising With New $5M & $75M Tiers
News

SEC Moves To Clarify Crypto Fundraising With New $5M & $75M Tiers

A new framework for some investment contracts, including cryptocurrency assets, has been proposed by the SEC, dubbed Regulation Crypto Assets. For qualified...

XRP & Solana Spot ETFs Log 11 Consecutive Days Of Net Inflows
News

XRP & Solana Spot ETFs Log 11 Consecutive Days Of Net Inflows

U.S. spot XRP exchange-traded funds have attracted fresh money for 11 consecutive trading sessions, bringing roughly $170 million of additional inflows even...

Related Articles

Crypto Mining Apps: How They Work & How To Spot Scams

Introduction Search for crypto mining apps today and you will find hundreds...

The Secret Behind Solana’s Memecoin Success

Memecoins have become a unique phenomenon in the crypto space, with the...

Glamsterdam Upgrade 2026: Why Ethereum’s Next Phase Could Change ETH

Ethereum (ETH) has been facing a strange problem for years. Ethereum is...

Top AI Deflationary Tokens Of 2026

Artificial intelligence (AI) and blockchain are becoming increasingly connected as decentralized networks...