Coldcard Wave 3 Attacker Moves 10% of Stolen BTC via THORChain
Galaxy Research's Alex Thorn confirmed the first on-chain movement from the original Coldcard attacker addresses: ~10% of Wave 3 funds routed through THORChain and landed on a new Ethereum address. The attacker hit repeated refund errors but kept retrying. Over 90% remains parked.

The first on-chain funds movement from the original Coldcard hacker addresses confirms the attacker is testing exit routes, and 90% of stolen funds are still live.
Key takeaways
- The Wave 3 Coldcard attacker moved approximately 10% of stolen funds through THORChain and into ETH on a new Ethereum address, marking the first confirmed on-chain movement from the original Wave 1, 2, or 3 hacker addresses.
- Galaxy Research's Alex Thorn, who traced the funds, says the attacker encountered repeated THORChain refund errors while retrying, suggesting this is a route test rather than a full cash-out. Over 90% of Wave 3 funds remain untouched.
- The underlying exploit targeted single-sig Coldcard wallets: a March 2021 firmware entropy failure left private keys reconstructable without physical device access. Multisig setups with diverse hardware were structurally immune.
The Wave 3 Coldcard attacker broke cover on September 3, 2026, routing approximately 10% of stolen funds through THORChain and into a new Ethereum address, according to Galaxy Research head of research Alex Thorn (@intangiblecoins) posting on X. It is the first confirmed on-chain movement from the original attacker addresses across all three waves of the Coldcard exploit, and over 90% of the stolen funds remain parked.
Galaxy Research linked the broader Coldcard exploit to the theft of at least 1,789 BTC from 8,865 addresses, worth approximately $114.7 million at the time of theft. The underlying vulnerability: a March 2021 Coldcard firmware build introduced a broken random number generator that generated seed phrases with insufficient entropy, leaving private keys mathematically reconstructable without ever touching the physical device. Affected models include the Mk3, Mk4, Mk5, and Q. Galaxy's running investigation is documented at @glxyresearch on X.
The Attacker's First Move and What It Signals
Per Cointelegraph, Thorn reported that the hacker "appears to be having some issues swapping all the funds through THORChain, they keep getting refunded and he keeps retrying." Thorn said he shared the destination Ethereum address with relevant authorities and crypto companies.
This movement is a probe, not a liquidation. The attacker sat on these coins for more than a month after Wave 3 before making a move. Routing a small slice through THORChain while encountering repeated refund errors is a test of exit infrastructure, not a bulk cash-out. The 90% still in original addresses is the figure that matters: it is still exposed, still traceable, and still represents an active threat to victims who have not migrated.
The THORChain exit route is not incidental. Cross-chain swaps from BTC into ETH on a fresh address disrupt the transaction graph that blockchain forensics tools use to flag stolen UTXO sets. ETH on a new address with no Coldcard-linked history is harder for exchanges to blacklist. The attacker chose this route deliberately, and it kept getting blocked and retried anyway. That detail does not reflect well on the attacker's operational security, but the permissionless architecture kept the door open regardless.
This is not the first time funds connected to the Coldcard exploit moved through obscuring infrastructure. CertiK reported in August 2026 that approximately 64 BTC linked to Coldcard exploit addresses had been sent to Wasabi and 200 ETH had been sent to Tornado Cash. The Coldcard blockchain trail has been documented across multiple on-chain investigative threads.
The Custody Lesson the Numbers Make Clear
Average dormancy of stolen Coldcard BTC: 3.18 years. These were not traders. They were long-term holders who did everything the self-custody playbook said: buy a reputable hardware wallet, air-gap it, never touch it. They got wrecked because a firmware RNG was silently broken underneath them.
The falsifiable thesis here is specific: this attack is exclusively a single-sig problem. The Coldcard entropy flaw works because reconstructing one private key per address is sufficient to drain a wallet. A properly configured 2-of-3 multisig using keys from two or more different hardware wallet manufacturers requires compromising multiple independent devices. No attacker exploiting a single vendor's firmware flaw can scale to that setup. If Galaxy Research or an independent forensic team identifies a confirmed multisig wallet from affected Coldcard firmware era that was successfully drained, that thesis breaks. Until that evidence exists, multisig remains the structural fix.
TFTC has covered the Alex Thorn on-chain investigation and the long-term holder wallet exodus following the breach in depth. The self-custody community has been warned repeatedly. This attacker moving for the first time is the forcing function for anyone still sitting on single-sig Coldcard addresses.
What to Watch
Thorn said it remains unclear whether the attacker will attempt to further obscure or move assets through an exchange. The next signal to watch: whether the remaining 90% of Wave 3 funds moves in bulk or in tranches. Bulk movement suggests the attacker gained confidence from this test; tranches suggest ongoing exit-route stress-testing. Law enforcement and crypto companies now have the destination ETH address. Whether that translates to a freeze depends entirely on the downstream venue the attacker chooses.
Sources
- Alex Thorn (@intangiblecoins) on X, September 3, 2026 (first reported by Cointelegraph)
- Galaxy Research (@glxyresearch) on X
- Alex Thorn (@intangiblecoins), August 2026, on active attacker status: https://x.com/intangiblecoins/status/2083756710510895255
- Alex Thorn (@intangiblecoins), August 2026, on THORChain laundering pattern: https://x.com/intangiblecoins/status/2083792644048597326
Frequently Asked Questions
The firmware patch prevents future vulnerable seeds from being created. It cannot fix seeds already generated under the broken firmware. Any wallet address created on affected Mk3, Mk4, Mk5, or Q devices under the flawed firmware remains exposed regardless of subsequent updates. Migration to a fresh seed on an unaffected device is the only remedy.
Cross-chain swaps via THORChain sever the direct on-chain link from the original stolen UTXO set. ETH on a new Ethereum address with no Coldcard-linked history is harder for blockchain forensics to tag and harder for exchanges to action on. ETH is not private, but it interrupts the transaction graph, which is the operational goal.
Yes. The entropy flaw allows reconstruction of individual private keys, which is sufficient to drain a single-sig wallet. A 2-of-3 multisig with keys held on two or more different hardware wallet manufacturers requires compromising multiple independent devices. This attack vector does not scale to that custody model.


