The operator linked to the third wave of the Coldcard hardware-wallet exploit has begun moving stolen Bitcoin into Ether after weeks of inactivity. About 20.5 BTC from the Wave 3 cluster was moved through the cross-chain exchange THORChain, with the resulting funds landing on Ethereum.
The transfers are the first confirmed movement from the original attacker addresses connected to the three documented Coldcard theft waves.
Alex Thorn, head of research at Galaxy, reported the transactions late Wednesday. His onchain analysis traced the Bitcoin from victim addresses through collection wallets and a series of 2-of-2 transactions before the funds reached THORChain.
COLDCARD WAVE 3 HACKER SWAPS FUNDS TO ETH VIA THORCHAIN
the wave 3 exploiter has moved stolen funds for the first time, swapping to ETH them through the THORChain cross-chain DEX
these are the first funds from wave 1, 2, or 3 to move onchain from the original hacker addresses pic.twitter.com/jjOrX5wBR9
— Alex Thorn (@intangiblecoins) September 2, 2026
The movement is significant because most of the Bitcoin connected to Wave 3 had remained untouched. Thorn later noted that about 90% of the Wave 3 holdings were still unmoved, while several attempted swaps were refunded before later transactions succeeded.
The latest activity does not change the estimated scale of the overall theft. Galaxy’s later public figures have placed high-confidence losses at around 1,789 BTC across more than 8,800 addresses. Those coins were worth about $115 million at the time of the theft.
Wave 3 was different from the earlier thefts. Researchers identified hundreds of separate vaults rather than a single collection address. Until September 2, the transactions were understood to involve hash-locked outputs. The first spend revealed a 2-of-2 multisignature setup, followed by additional transfers using similar structures with different key pairs.
Thorn also observed differences in the wallet behaviour used for the latest cash-out. The transactions used replace-by-fee, recent locktimes and higher fees. THORChain deposits appeared to come through another interface and included an OP_RETURN memo and an affiliate tag.
These details can help researchers track activity on the blockchain, but they do not identify the person or group behind the transactions. The thefts were linked to a seed-generation flaw in certain Coldcard firmware. Coinkite disclosed that some firmware released from March 2021 onward could generate seeds with weaker entropy than intended.
The vulnerability did not allow attackers to remotely take control of Coldcard devices. Instead, attackers were able to reconstruct private keys offline and then spend funds from affected addresses.
Coinkite later released a firmware update and warned users that updating the software would not repair a seed that had already been created on vulnerable firmware. Users were advised to generate a new seed using fixed firmware and move their funds.
Co-founder Rodolfo Novak also apologised publicly and said the company had shipped a hotfix that removed the software fallback path. He urged users to migrate their funds before going through further technical details.
The company said TAPSIGNER, OPENDIME and SATSCARD use different code and were not covered by the same security advisory. It also said seeds created using at least 50 independent private dice rolls were considered an exception because the dice supplied the necessary entropy.
The latest Wave 3 transactions do not change that advice. Bitcoin still sitting in affected addresses remains exposed if the original seed was created using vulnerable firmware.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like










Leave a comment