Coldcard Hacker's Bitcoin Vanishes Into Ethereum—Here's How
Sarah Taylor ·
Listen to this article~3 min

The Coldcard hacker just swapped a chunk of stolen Bitcoin for Ethereum via THORChain. Here's what that means for crypto security and how investigators are tracking the funds.
So, the Coldcard hacker is back in the news, and this time they're not just sitting on stolen Bitcoin. They're moving it. And not in a small way either. According to researchers, the third-wave Coldcard exploiter shuffled about 10% of the stolen funds through THORChain, eventually landing in a brand-new Ethereum address. If you're into crypto security—or just love a good blockchain mystery—this one's worth watching.
### What Exactly Happened?
Let's break it down. Coldcard is a popular hardware wallet known for its strong security. But like any tool, it's only as safe as how you use it. The "third-wave" exploiter refers to a specific set of attacks targeting users who likely fell for phishing or mishandled their seed phrases. The hacker managed to sweep a chunk of Bitcoin into their own control.
Now, instead of just holding that Bitcoin, they decided to swap roughly 10% of it for Ethereum. How? Through THORChain, a decentralized liquidity protocol that lets you swap assets across different blockchains without a centralized exchange. That's a big deal because it makes tracking harder—but not impossible.
### Why THORChain Matters
THORChain isn't your average swap service. It's non-custodial, meaning no single entity holds your coins during the trade. That's great for privacy, but it also gives hackers a way to obfuscate their trail. By moving from Bitcoin to Ethereum, the exploiter breaks the direct link between the original theft and the new funds.
But researchers are clever. They followed the money. After the swap, the stolen ETH landed in a fresh Ethereum address. That address is now under scrutiny. And while the hacker might think they're clever, the blockchain never forgets.
> "The moment you move stolen funds across chains, you're not hiding—you're just leaving a longer trail." — Anonymous blockchain researcher
### What This Means for You
If you hold crypto, especially on a hardware wallet like Coldcard, this is a wake-up call. Here are a few takeaways:
- **Double-check your seed phrase storage.** Never store it digitally. Ever.
- **Beware of phishing sites.** The third-wave attacks often start with a fake login page.
- **Use multiple wallets.** Don't keep all your assets in one place.
- **Stay updated.** Coldcard has released patches, but you need to apply them.
And if you're trading or swapping, remember that services like THORChain are powerful but not anonymous. Law enforcement and analytics firms have gotten very good at tracing cross-chain movements.
### The Bigger Picture
This isn't just about one hacker. It's about the cat-and-mouse game between exploiters and investigators. As DeFi tools get more sophisticated, so do the methods to track them. The Coldcard case shows that even when stolen Bitcoin turns into Ethereum, the paper trail doesn't disappear.
For now, the hacker's new Ethereum address is being watched. Will they try to cash out? Will they move again? Only time will tell. But one thing's for sure: in crypto, privacy is a myth if you're not careful.
So, keep your guard up, keep learning, and maybe don't trust that random Discord DM offering a "free Coldcard update." Stay safe out there.