How is the Coldcard hacker using THORChain to launder stolen Bitcoin into Ethereum?

The Coldcard exploiter is utilizing the decentralized cross-chain protocol THORChain to convert approximately 10% of their stolen Bitcoin into Ethereum to obscure the transaction trail. This shift to a new Ethereum address complicates recovery efforts and highlights the ongoing use of cross-chain bridges in sophisticated crypto laundering schemes.
How is the Coldcard hacker using THORChain to launder stolen Bitcoin into Ethereum?

The exploiter behind the recent Coldcard-related thefts is currently moving stolen Bitcoin (BTC) through the THORChain protocol to exchange it for Ethereum (ETH). According to blockchain researchers, the 'third-wave' hacker has successfully moved about 10% of the illicitly obtained funds, bridging them from the Bitcoin network to a fresh Ethereum address. By using a decentralized cross-chain liquidity protocol like THORChain, the attacker avoids centralized exchanges that require KYC (Know Your Customer) documentation, effectively breaking the direct link between the stolen BTC and the resulting ETH assets.

This specific incident involves a 'third-wave' actor, suggesting a series of coordinated or recurring attacks targeting users of the Coldcard hardware wallet ecosystem, likely through sophisticated phishing or supply chain exploits. Blockchain forensic analysts tracked the assets as they moved through THORChain’s liquidity pools, which allow for native asset swaps across different blockchains. The move to Ethereum suggests the hacker may be preparing to further obfuscate the funds through privacy mixers or decentralized finance (DeFi) protocols on the EVM-compatible chain.

For US-based crypto investors, this event underscores the persistent risks associated with hardware wallet security and the importance of verifying every transaction signature. While Coldcard itself is a highly regarded hardware wallet provider, hackers often exploit human error or 'middleman' vulnerabilities to gain access to private keys. This laundering activity also puts THORChain back in the regulatory spotlight, as US authorities like the Treasury Department continue to monitor decentralized protocols that can be leveraged for money laundering and sanctions evasion.

Market participants should watch for the movement of the remaining 90% of the stolen Bitcoin, which remains under the attacker's control. If the hacker continues to dump large amounts of BTC for ETH, it could create localized selling pressure, though the primary impact is on market sentiment regarding self-custody safety. Investors are urged to double-check their security protocols and remain vigilant against social engineering tactics that target cold storage users.