- Galaxy Research head of research Alex Thorn said on Sept. 3 that a hacker linked to the third wave of the Coldcard thefts moved about 20.5 Bitcoin, roughly 10% of that wave’s stolen funds, and started swapping it for Ether through THORChain.
- The swaps repeatedly failed, with about 17.7 Bitcoin refunded, and the proceeds reached a new Ethereum address that Galaxy said it shared with law enforcement and major crypto firms.
- It is the first onchain movement from any of the three theft waves; Galaxy has traced 1,789 Bitcoin stolen from 8,865 addresses.
A hacker linked to the third wave of the Coldcard wallet thefts has started moving the stolen Bitcoin, converting some of it to Ether through the cross-chain protocol THORChain. It is the first time funds from any of the three theft waves have left the original attacker addresses.
Galaxy Research head of research Alex Thorn reported the movement on Sept. 3. The hacker shifted about 20.5 Bitcoin, or roughly 10% of the third wave’s stolen coins, leaving about 90% of that wave untouched. Galaxy has said the third wave should not be assumed to involve the same attacker as the earlier ones.
The swaps did not run cleanly. Galaxy traced the coins through a series of intermediary wallets before they reached THORChain, where about 17.7 Bitcoin was refunded during the attempts before the funds went through.
“The hacker appears to be having some issues swapping all the funds through THORChain, they keep getting refunded and he keeps retrying”, Thorn said. The proceeds reached a new Ethereum address, which Galaxy said it passed to law enforcement and major crypto firms.
Read more: Robinhood Chain Nears $1B DEX Volume as TVL and Stablecoin Liquidity Surge
The Firmware Defect Behind the Thefts
The thefts trace to a defect in Coinkite’s Coldcard, an air-gapped Bitcoin hardware wallet.
A firmware change made in March 2021 routed seed generation through faulty code that produced far too little randomness, and Coinkite has said some seeds carried as little as about 40 bits of entropy instead of the intended 128, leaving the private keys guessable. Attackers began draining wallets on July 30, taking 1,082 Bitcoin from 1,196 addresses in about 41 minutes in the first wave, according to Galaxy.
Coinkite shipped emergency firmware the next day, but the patch does not repair a seed already created, and the company has told affected users to move their coins to a newly generated one.
Galaxy has traced 1,789 Bitcoin (US$114.7 million / AU$159 million) stolen from 8,865 addresses at the time of the theft, across at least three waves and at least 15 separate attackers. Its count rests on 221 victim reports covering 790.72 Bitcoin, with the remaining addresses identified through onchain analysis.
CNA reported the exploit reaching as much as US$130 million (AU$181 million) in early August, before Galaxy narrowed its confirmed tally. Those coins had sat untouched for about five weeks before this week’s transfers, and funds from the first two waves have not moved at all.
Read more: Bitcoin Treasury Titans Reload: Strive and Strategy Add $513M in BTC
Bitcoin,Hackers,THORChain#Coldcard #Hacker #Starts #Swapping #Stolen #Bitcoin #Ether1788509712
