The attacker involved in the Coldcard loot incident has officially started moving 20.45 BTC, valued at roughly $1.6 million, by routing the assets onto the Ethereum network. Through a series of 34 swaps executed between September 2 and September 3, the hacker effectively transitioned the previously 'parked' funds from Bitcoin to Ethereum. This cross-chain movement is a common tactic used to obscure the transaction trail and move assets into the DeFi ecosystem where privacy-preserving tools are more prevalent.
Bitquery, a blockchain data provider, traced the movement and noted that the primary destination wallet on the Ethereum side recently showed a decrease of approximately 5 ETH. This suggests the attacker is already beginning to disperse or liquidate portions of the stolen assets. The use of numerous small swaps is a classic obfuscation technique intended to bypass the automated flagging systems used by centralized exchanges and security monitors.
This development is significant for the U.S. crypto community as it highlights the persistent challenges of tracking sophisticated cross-chain money laundering. While Coldcard is a reputable hardware wallet manufacturer, incidents involving the theft of user funds—often through compromised seeds or phishing—serve as a stark reminder of the risks in self-custody. Furthermore, the shift to Ethereum often signals an intent to utilize protocols like Tornado Cash, which remains a high-priority target for U.S. regulators and the Office of Foreign Assets Control (OFAC).
For the broader market, the movement of stolen funds typically creates localized selling pressure and negatively impacts investor sentiment regarding security. Readers should watch for further activity in the identified Ethereum destination addresses, as large-scale liquidations can impact liquidity on decentralized exchanges. The ongoing monitoring by firms like Bitquery remains essential in the arms race between blockchain forensics and malicious actors seeking to exit the market with stolen capital.