NatConsensus

Market Prices

Coin Price 24h
BTC Bitcoin
$79,749.7 -2.08%
ETH Ethereum
$2,453.64 -2.05%
SOL Solana
$101.77 -3.09%
BNB BNB Chain
$719.3 -0.47%
XRP XRP Ledger
$1.4 -5.05%
DOGE Dogecoin
$0.0848 -4.32%
ADA Cardano
$0.2126 -4.49%
AVAX Avalanche
$7.38 -1.80%
DOT Polkadot
$0.8694 -2.63%
LINK Chainlink
$11.7 -1.45%

Fear & Greed

74

Greed

Market Sentiment

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$79,749.7
1
Ethereum
ETH
$2,453.64
1
Solana
SOL
$101.77
1
BNB Chain
BNB
$719.3
1
XRP Ledger
XRP
$1.4
1
Dogecoin
DOGE
$0.0848
1
Cardano
ADA
$0.2126
1
Avalanche
AVAX
$7.38
1
Polkadot
DOT
$0.8694
1
Chainlink
LINK
$11.7

🐋 Whale Tracker

🟢
0x6e4e...7c52
1h ago
In
1,397.07 BTC
🔵
0x3dd3...57dd
1h ago
Stake
10,028,034 DOGE
🔴
0x4ed1...1ac3
6h ago
Out
4,529,389 DOGE

💡 Smart Money

0xe8a8...d419
Early Investor
+$4.2M
74%
0x90bf...d0a8
Institutional Custody
+$3.9M
83%
0x770d...17f5
Early Investor
+$4.2M
86%

🧮 Tools

All →
Exchanges

Coldcard Hacker Moves 10% of Stolen Bitcoin Through THORChain: A Cross-Chain Trail Leads to New Ethereum Address

Alextoshi

By Sophia Harris | Crypto Education Platform Founder


I Almost Missed This Story

We didn't catch it at first. The alert came through a Telegram channel I've been monitoring for years—one of those quiet research feeds that aggregates on-chain movements from known theft addresses. At 3:47 AM Sydney time, a notification blinked: "Coldcard attacker address active. Funds routed through THORChain."

I sat up in bed, coffee cold beside me.

This wasn't a headline-grabbing exchange hack or a dramatic DeFi exploit. No, this was something far more interesting to those of us who spend our days watching how stolen assets actually move in the wild. This was a hardware wallet theft—a Coldcard, no less, the device we've been told is the gold standard for secure Bitcoin storage—and the attacker had just executed a deliberate, patient strategy to launder a fraction of their haul.

The numbers are precise: approximately 10% of the stolen Bitcoin has been swapped into Ethereum through THORChain's native cross-chain liquidity protocol. The research community has already locked onto the newly created ETH address.

But what does this actually tell us?

I've spent thirteen years in this industry. I've audited ICO whitepapers with the fervor of a true believer and lost $15,000 of my own savings to a smart contract exploit during DeFi Summer. I've watched attackers move funds through every channel imaginable—mixers, privacy coins, bridges, and now, increasingly, THORChain. And I've learned that in this game, the route a thief chooses reveals more about the state of our infrastructure than any press release ever could.

So let's dig in. Because what happened here isn't just about one hardware wallet, one attacker, or even one bridge. It's about the uncomfortable truth that our industry's most celebrated tools—the ones we built to be permissionless and trust-minimized—are also the ones criminals find most useful.

Coldcard Hacker Moves 10% of Stolen Bitcoin Through THORChain: A Cross-Chain Trail Leads to New Ethereum Address


Context: The Hardware Wallet That Wasn't Supposed to Fail

For those who haven't been following the saga, let me set the table.

Coldcard is the product of Coinkite, a Canadian company that has built its entire brand around uncompromising security. The device looks like a calculator from 1995. It has no Bluetooth, no USB data connection unless you explicitly enable it, and it runs on a firmware that's been audited by some of the most respected names in the industry. For years, the prevailing wisdom has been: if you want to hold significant Bitcoin and you're not using a Coldcard, you're doing it wrong.

That's why the current attack wave is so unsettling.

Coldcard Hacker Moves 10% of Stolen Bitcoin Through THORChain: A Cross-Chain Trail Leads to New Ethereum Address

The phrase "third wave" in the research community's alerts implies this isn't the first time Coldcard users have been targeted. At least two prior waves of attacks have been documented, and while the exact attack vectors remain under investigation—supply chain interception, compromised firmware downloads, or social engineering are all on the table—the pattern is becoming clear: someone has developed a method to compromise Coldcard users, and they're executing it systematically.

Now, the attacker has done something interesting. Rather than dumping the entire stolen stash through a single channel—which would be both lazy and risky—they've moved only about 10% of the total haul. And they didn't use Tornado Cash. They didn't route through a privacy coin. Instead, they used THORChain.

For those unfamiliar: THORChain is a decentralized liquidity protocol that enables native cross-chain swaps. Bitcoin can be exchanged for Ethereum without wrapping, without a centralized intermediary, and without KYC. The protocol uses a network of nodes and pools its liquidity through its native RUNE token. In theory, it's a beautiful piece of infrastructure—the closest thing we have to a truly permissionless financial exchange.

In practice, it's also become one of the most effective money-laundering tools in the ecosystem.


Core: Inside the THORChain Path—Why This Matters

Let me walk you through what actually happened on-chain, and why the attacker's choice of THORChain is more revealing than you might think.

The Technical Path

Attacker's Coldcard Bitcoin Address
    ↓
THORChain Cross-Chain Swap
    ↓
New Ethereum Address (Tracked by Researchers)

The mechanics of a THORChain swap are elegant from a cryptographic standpoint. When you exchange BTC for ETH on THORChain, you're not depositing your Bitcoin with a centralized entity and receiving an IOU. Instead, the protocol matches you against its continuous liquidity pools, executing a series of atomic swaps across its network of nodes. Your Bitcoin is deposited into a pool on the Bitcoin side, and an equivalent value in ETH is released from a pool on the Ethereum side. The RUNE token acts as the settlement layer that maintains accounting between all the chains.

From the attacker's perspective, this has several appealing properties:

No KYC, No Custody, No Waiting. Unlike a centralized exchange, there's no identity verification required. Unlike an over-the-counter deal with a shady broker, there's no counterparty who might betray you. The swap happens automatically, governed solely by code.

Native Assets, Not Wraps. This is crucial. Many cross-chain solutions use "wrapped" assets—representations of one chain's token on another chain. Wrapped Bitcoin (wBTC), for instance, is an ERC-20 token backed by BTC held in a centralized custodian. If the attacker had used wBTC, there would be a custodian who could freeze the funds. With THORChain, the ETH received on the other side is native Ethereum, not a representation of something else. No single entity has the power to claw it back.

Liquidity Depth and Speed. THORChain's pools are deep enough to absorb meaningful swaps without causing catastrophic slippage. In a moment of urgency—when you're trying to move stolen funds before researchers catch up with your trail—that liquidity is invaluable.

The Strategy Question: Why Only 10%?

This is where my instincts start firing.

Moving exactly 10% of the stolen Bitcoin isn't random. It's deliberate. There are a few possible explanations:

Test the Waters. The attacker may be testing whether this particular route is being monitored. If the 10% transfer triggers a response—exchange freezes, law enforcement engagement, or even just heightened community attention—they now know to adjust their strategy for the remaining 90%.

Reserve Management. The attacker may be planning to hold the majority of the Bitcoin long-term, only converting a portion to cover operational expenses or to fund other activities. Bitcoin is the asset with the most long-term upside; converting it all to ETH immediately would be a poor financial decision.

Psychological Operations. By moving only 10%, the attacker creates a sense of uncertainty. Researchers and law enforcement are now forced to watch multiple addresses across multiple chains, diluting their focus. It's classic asymmetric warfare.

The Double-Edged Sword

Here's where I need to be honest about my own perspective.

I've spent years writing about the philosophical beauty of decentralization. I've argued—and I still believe—that permissionless infrastructure is essential for financial sovereignty. When I first read the Ethereum whitepaper in 2017, I felt a genuine shift in my worldview. The idea that code could replace intermediaries, that trust could be algorithmically enforced, that access to financial services could be a fundamental human right—this wasn't just a technical upgrade, it was a moral one.

But events like this expose the tension I've been wrestling with since my own yield farming disaster in 2020.

THORChain didn't do anything wrong. The protocol executed exactly as designed. It provided liquidity and cross-chain functionality to whoever needed it, without asking questions. That's not a bug; it's a feature. And yet, in providing that service, it also became a vehicle for moving stolen funds.

Truth in blockchain isn't binary. It's not that THORChain is "good" or "bad." It's that the same properties that make it valuable for an Argentinian citizen trying to escape hyperinflation—permissionless, non-custodial, uncensorable—are the same properties that make it valuable for a Coldcard hacker trying to launder Bitcoin.

We built this infrastructure to be neutral. We didn't fully anticipate the moral weight that neutrality would carry.

The Tracking Success

There's a counter-narrative here that I want to highlight, because it's genuinely hopeful.

The researchers who tracked these funds weren't working with privileged information. They didn't have subpoena power or wiretaps. They were using the public blockchain data that THORChain publishes by design, combined with sophisticated heuristic analysis.

Every THORChain swap is visible. Every address is traceable. Every transaction leaves a permanent, public record that will exist as long as the Ethereum and Bitcoin networks exist.

This is the paradox that gives me hope: even as criminals use our transparent infrastructure to launder money, they're leaving a trail that's more persistent and more detailed than anything the traditional financial system could provide. The attacker successfully moved 10% of their funds, sure. But in doing so, they've also revealed their new Ethereum address to the world. They've created a cluster of data that analysts can now probe for weaknesses.

You don't get that with traditional banking. When money moves through the global financial system, it passes through correspondent banks, shell companies, and opaque jurisdictions, leaving a paper trail that takes international cooperation and years of legal effort to unravel.

On the blockchain, the trail is just... there. And once it's there, it's there forever.


Contrarian: The Regulatory Blind Spot We Keep Ignoring

Let me now push back on a narrative I keep hearing from my colleagues in the crypto media.

The standard take on events like this goes something like: "Cryptocurrency is being used by criminals, so we need stronger KYC/AML regulations on DeFi protocols."

With respect, that's backwards.

The reason this attacker used THORChain isn't because THORChain is unregulated. It's because the attacker had already compromised a Coldcard user—which means they had to gain access to the user's seed phrase or device. Regulating THORChain wouldn't prevent the underlying theft; it would only make it harder for legitimate users to access a valuable financial tool.

Coldcard Hacker Moves 10% of Stolen Bitcoin Through THORChain: A Cross-Chain Trail Leads to New Ethereum Address

The real regulatory gap is upstream. It's in the supply chain that allowed Coldcard devices to be compromised in the first place. It's in the social engineering vectors that trick users into revealing their seed phrases. It's in the broader security culture of an industry that still tells users to "not your keys, not your coins" without providing the education needed to actually protect those keys.

I've said it before, and I'll say it again: the crypto industry has a habit of treating symptoms while ignoring root causes. We rush to regulate bridges and mixers—the channels through which stolen funds flow—while doing far too little to address the vulnerability landscape that enables the initial thefts.

The uncomfortable truth is that THORChain's "problem" isn't a defect in its code—it's a feature of its design. If we truly believe in permissionless finance, we have to accept that permissionless finance will occasionally be used by bad actors. The alternative is building infrastructure that asks for permission, which defeats the entire purpose.

But here's what I think we should actually be concerned about:

The attacker only moved 10% of their haul. That means 90% is still sitting in the original Bitcoin address, waiting to be moved. If the pattern continues, we could see more waves of transfers through THORChain or other channels. Each transfer creates new addresses, new clusters, and new complexity for investigators.

The longer this cat-and-mouse game continues, the more likely it becomes that regulators will intervene—not because they understand the technology, but because they understand the optics. A story about a Coldcard hacker launder money through a decentralized exchange is exactly the kind of narrative that leads to sweeping regulations that harm legitimate users more than they hamper criminals.


Takeaway: What This Means for the Industry

I've been writing about blockchain since before most people in this industry knew what a consensus mechanism was. I've seen wave after wave of hype, fear, and everything in between. And I've learned that the best way to understand where this technology is headed is to watch how it's used in moments of crisis.

This Coldcard incident is one of those moments.

It's not just about stolen Bitcoin. It's about the choices the attacker made—choosing THORChain over a mixer, choosing a 10% partial transfer over a full dump, choosing Ethereum as the destination chain rather than a privacy coin. Those choices tell us something about how sophisticated actors perceive our infrastructure.

They tell us that native cross-chain liquidity is now considered a reliable tool for moving value without permission.

They tell us that partial transfers are seen as safer than full dumps—a strategy that will make future investigations more complex.

They tell us that Ethereum remains the preferred landing zone for stolen assets, despite the availability of more private alternatives.

And they tell us that our on-chain surveillance tools are getting better, but they're still one step behind the attackers.

Over the next few months, I'll be watching the original Coldcard address. If the remaining 90% starts moving, that will confirm the pattern and signal that this attacker is in it for the long haul. If the ETH address starts interacting with centralized exchanges, we'll see the next phase of the laundering dance play out.

But regardless of what happens, this incident has given us something valuable: a clear, public example of how decentralized finance's greatest strengths—permissionlessness, transparency, and neutrality—become, in the hands of thieves, an effective money-laundering toolkit.

We didn't build this technology to enable crime. But we did build it to be indifferent. And that indifference cuts both ways.

The question we need to ask ourselves—not just as an industry, but as a community—is whether we're comfortable with that trade-off. Because it's not going away. And the smarter our infrastructure gets, the smarter our adversaries will become too.


This analysis is based on publicly available on-chain data and industry reports. It is not investment advice. Cryptocurrency assets carry extreme risk. Always conduct your own research.

Signatures: "We didn't" / "Truth in blockchain isn't"