Coldcard Hacker Just Swapped Stolen Bitcoin for ETH: Researchers Are Watching Every Move
Researchers have already pinpointed the new Ethereum address holding the funds, and the hacker doesn't seem to care.
The third-wave Coldcard exploiter moved roughly 10% of the total stolen Bitcoin through THORChain, converting it into ETH and routing it to a fresh Ethereum wallet. On-chain investigators traced the entire path in near real time, which raises an uncomfortable question: why is this person moving so openly?
THORChain Is the Launderer's Bridge of Choice Right Now
This isn't the first time bad actors have leaned on THORChain to hop between chains. The protocol's cross-chain swaps are permissionless and require no KYC, making it a preferred exit ramp for anyone trying to blur the trail between Bitcoin and Ethereum. What's different here is the scale and the audacity. The exploiter isn't waiting, isn't mixing, and isn't fragmenting into thousands of micro-transactions. They moved a significant chunk in one visible sweep.
That either signals extreme confidence, extreme carelessness, or something researchers haven't surfaced yet.
The Coldcard Exploit Timeline Is Getting Complicated
The fact that analysts are labeling this the "third-wave" Coldcard exploiter suggests this isn't a single clean theft. The funds have moved in stages, with each wave introducing new wallet clusters and new conversion strategies. The shift to Ethereum now expands the potential mixer and tumbler options available to the attacker, including Tornado Cash alternatives that have proliferated since the OFAC sanctions.
Tracking BTC is hard. Tracking ETH through a determined bad actor with access to privacy tooling is harder. The window for meaningful intervention is narrowing.
What the Market Should Watch
This move has two immediate implications for crypto holders.
First, THORChain is back in the crosshairs. Regulators have already scrutinized the protocol following previous high-profile exploit laundering events. Another confirmed instance of stolen funds routing through RUNE liquidity pools increases the probability of regulatory action, which would be a direct price risk for RUNE holders.
Second, the Ethereum address is live and being monitored. If researchers go public with the full wallet cluster, expect coordinated exchange flagging across Coinbase, Kraken, and Binance. Any attempt to cash out hits a wall, which historically pushes hackers toward more aggressive obfuscation, sometimes creating detectable on-chain noise traders can front-run.
Watch THORChain volume for unusual spikes. Watch the flagged ETH address for the next move. And if you hold RUNE, understand the regulatory overhang just got heavier.