INSIGHTS

Coldcard Hacker Uses THORChain to Swap Stolen BTC

Share:

A Coldcard attacker has reportedly begun laundering the proceeds of a wallet theft, moving roughly 10% of the stolen Bitcoin through THORChain to swap it into other assets. The activity keeps a string of Coldcard-related thefts in focus for self-custody users tracking where stolen funds go next.

What happened in the Coldcard attack

The core claim is narrow but concrete: an attacker behind a Coldcard theft has started shifting the stolen Bitcoin, and about 10% of the funds has been routed through THORChain. The reporting frames this as a fund-movement development rather than a fresh breach.

The incident sits alongside a broader pattern of Coldcard losses. Separate reporting has documented cases where 1,596 BTC was allegedly stolen and where Coldcard users reported a 594 BTC theft, giving context for why any movement of stolen coins draws immediate attention.

Bitcoin holders are watching because the losses have been tied to hardware wallet issues. Coldcard’s maker previously warned against using certain seed functions on specific firmware versions, and the fallout has been linked to roughly $100 million in hacked funds.

How the stolen BTC moved through THORChain

THORChain is a cross-chain liquidity protocol that lets users swap native assets across networks without a centralized intermediary, which is why it recurs in stolen-fund tracing. In this case, the attacker used it to convert part of the stolen Bitcoin, swapping BTC into ETH according to the reporting.

The notable detail is that only about one-tenth of the haul has moved so far. That leaves the majority of the stolen Bitcoin still traceable on-chain, and it is inference rather than confirmed intent to read the partial movement as a test or a staggered cash-out.

Why this matters for Bitcoin security watchers

For wallet users and exchange compliance teams, cross-chain swaps of stolen coins are the point where recovery odds narrow, since assets change form and network. The Coldcard episode has already prompted a wider self-custody security overhaul conversation among industry figures.

Coldcard has responded on the product side, with a firmware update adding dice rolls and coin flips for seed generation after the underlying seed failure. Tracking whether the remaining stolen Bitcoin follows the same THORChain route will determine how much of it stays visible to investigators.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.