
Coldcard Theft Attackers Move More Funds Through THORChain

Coldcard Theft Attackers Move More Funds Through THORChain
WEEX View
- The main near-term variable is whether more of the remaining attacker-controlled BTC begins moving into cross-chain routes and mixers, which would make tracing and recovery harder.
- Galaxy’s update suggests the attackers are processing wallets in order of the amount stolen, so observers will likely focus on whether larger vaults continue to be drained first.
- The discovery of 58 more addresses using the same 2-of-2 spending pattern means the final scale of victim exposure may still rise as attribution work continues.
For the broader market, the key signal is not price action but how quickly forensic tracking can identify linked addresses before additional funds are obfuscated.
Galaxy Research said attackers tied to the “third wave” of the Coldcard hardware wallet theft are still moving stolen funds, with about 45% of the coins in that cluster already transferred out and additional newly identified addresses potentially lifting the estimated total theft to about 1,806 BTC.
According to Galaxy Research, the attackers created 293 separate 2-of-2 multi-signature vaults for victims in the third wave. The firm said the first batch of funds was transferred to Ethereum through THORChain on September 2 and has since entered the mixing process.
Galaxy said the attackers appear to be processing funds based on the amount stolen from each victim. It reported that the top 11 vaults have already been transferred. By contrast, the last 10 untouched vaults still hold a combined 30.81 BTC, while vaults ranked from 61 to 293 hold another 33.77 BTC.
Based on that tracking, Galaxy estimated that about 45% of the stolen coins from the third wave have been moved. It also said roughly 82% of the stolen BTC overall remains in addresses controlled by the attackers, while about 18% has been transferred.
The report also identified 58 new addresses that spend in the same 2-of-2 multi-signature format. Galaxy said those addresses may also belong to Coldcard victims, which would raise the estimated total amount stolen to about 1,806 BTC. Details on the affected users and any potential recovery effort were not disclosed in the update.
Why It Matters
This update extends the Coldcard theft from a static loss event into an active laundering story. Once stolen BTC moves through cross-chain infrastructure and mixers, the practical challenge for investigators, exchanges, and compliance teams becomes much harder, especially if attribution is still expanding.
The report also underscores how on-chain forensic estimates can change as more linked addresses are uncovered. For hardware wallet users and the wider crypto industry, that keeps attention on both operational wallet security and the limits of post-theft asset tracing once attackers begin staging funds across multiple formats and networks.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreUK FCA Weighs Softer Stance on Retail Prediction Markets
The UK Financial Conduct Authority is discussing a possible easing of retail restrictions on financial prediction markets, while its public position still supports the 2019 ban that treats such contracts as binary options.
Attack on Saudi Aramco’s Jizan Facility Lifts Oil Prices
Saudi Aramco said its Jizan oil facility was attacked on September 7, with damage still under assessment. Crude prices moved higher immediately as traders weighed the risk of renewed disruption to Saudi energy infrastructure.
Router Protocol Says It Will Shut Down and Burn ROUTE Tokens
Router Protocol said it will halt operations after more than four years of development and burn 30% of the ROUTE token supply, while token holders on exchanges were told to follow delisting instructions and withdraw before the deadline.
DBS and Citi Test Weekend USD Payments on Swift Ledger
DBS Bank and Citibank said they completed a cross-border U.S. dollar payment between Singapore and the U.S. using tokenized deposits on Swift’s digital ledger, reducing settlement time from about two business days to minutes.


