How Did the Hacker Use THORChain to Move Funds?
A hacker tied to the third wave of Coldcard wallet breaches has converted roughly 10% of stolen Bitcoin into Ether using the THORChain network. Researchers traced the movement to a newly identified Ethereum address as the funds were shuffled through decentralized channels. The activity emerged amid ongoing investigations into the series of hardware wallet exploits targeting Coldcard users. Galaxy Digital’s head of research noted the swaps indicate an attempt to obscure the trail of illicit assets. The hacker appears to be leveraging cross-chain bridges to convert Bitcoin into a more liquid form for potential laundering or resale. This marks a shift in tactics compared to earlier waves where funds remained largely in Bitcoin. Blockchain analysts observed the transactions in real time, flagging unusual patterns in THORChain liquidity pools. The movement suggests the attacker is adapting to increased scrutiny on Bitcoin mixing services.
Breaking news
Bitcoin breaks through key resistance as traders eye next milestone
Absa Launches Bitcoin Custody, Leading Africa’s Digital Asset Shift
Aave Founder Warns EU MiCA Review Could Restrict DeFi Access
Bitcoin Price Stalls Below $87,220 as Key Resistance LoomsLaw enforcement and cybersecurity firms continue to monitor the flow of funds across multiple chains. The use of THORChain highlights growing challenges in tracking crypto thefts through decentralized finance protocols.
The attacker routed stolen Bitcoin through THORChain’s decentralized liquidity network to swap it for Ether without relying on centralized exchanges. This process allows peer-to-peer asset swaps across blockchains, making interception more difficult. By converting BTC to ETH, the hacker likely aimed to exploit Ethereum’s broader ecosystem for further obfuscation or spending. THORChain’s design enables trustless cross-chain transfers, which bad actors increasingly exploit for laundering. Researchers noted the swaps occurred in small batches to avoid triggering automated monitoring systems. The tactic reflects a sophisticated understanding of both blockchain mechanics and current surveillance gaps.
What Are Authorities Doing to Trace These Transactions?
Cybersecurity teams and blockchain analysts are using heuristic analysis and cluster identification to follow the funds despite the cross-chain jumps. They are monitoring known THORChain validators and liquidity providers for suspicious activity linked to the hacker’s addresses. While decentralized networks complicate seizure efforts, transaction patterns still leave forensic traces on public ledgers. Investigators are also coordinating with exchanges to flag any attempts to cash out the converted Ether. The case underscores the need for improved tools to track illicit flows across interconnected crypto ecosystems. No arrests have been reported in connection with this specific wave of Coldcard exploits at this time. Frequently Asked Questions How much of the stolen funds has been moved through THORChain so far? Approximately 10% of the total stolen Bitcoin from the third wave of Coldcard hacks has been swapped for Ether via THORChain, according to researchers tracking the assets.
Why would a hacker choose THORChain over other methods? THORChain allows direct, decentralized swaps between Bitcoin and Ethereum without intermediaries, reducing exposure to exchange KYC checks and freezing mechanisms.
Can stolen funds moving through THORChain be recovered? Recovery is extremely difficult due to the trustless, non-custodial nature of THORChain, though investigators can trace movements and attempt to intercept funds at exit points to centralized services.


