A threat actor linked to the so-called third-wave Coldcard exploit has begun moving stolen funds, converting approximately 10% of pilfered Bitcoin into Ethereum through the decentralized cross-chain liquidity protocol THORChain. Blockchain researchers have already traced the swapped assets to a newly created Ethereum address, opening a fresh front in what is becoming a protracted cat-and-mouse investigation between on-chain forensics teams and a disciplined, patient attacker.

The choice of THORChain as the laundering vector is not incidental. The protocol enables native cross-chain swaps — moving Bitcoin directly into Ethereum without wrapping or centralized intermediaries — making it one of the few pieces of decentralized infrastructure capable of cleanly breaking an asset trail across two entirely separate blockchains. Unlike a centralized exchange, THORChain requires no Know Your Customer verification, no account registration, and leaves no custodial chokepoint where authorities might intervene. For an attacker trying to sever the forensic link between stolen Bitcoin and a fresh Ethereum stash, it is close to an ideal tool.

What makes this development particularly significant is the framing: this is described as the third-wave Coldcard exploiter, meaning researchers are tracking not a single incident but a patterned series of attacks on the hardware wallet ecosystem. Coldcard, manufactured by Coinkite, is widely regarded as one of the most security-hardened Bitcoin hardware wallets available, favored by high-net-worth holders and institutional custodians precisely because of its air-gapped design and open-source firmware. The existence of successive exploit waves targeting its users implies either a persistent, unfixed vulnerability in a specific configuration or workflow, or a social-engineering campaign sophisticated enough to survive multiple rounds of public exposure.

The decision to move only about 10% of the stolen funds at this stage is itself analytically telling. Experienced crypto thieves rarely liquidate everything at once. Partial movements serve multiple purposes: they test whether specific addresses or swap routes are being monitored, they probe whether forensics teams or law enforcement have flagged particular infrastructure nodes, and they allow the attacker to preserve optionality on the bulk of the haul while laundering a smaller, less conspicuous tranche. If THORChain's liquidity pools process the swap without triggering any intervention or asset freeze, the remaining 90% becomes easier to move through the same or similar channels.

THORChain itself occupies an uncomfortable position in this narrative. The protocol's developers and community have long grappled with its dual-use reality: the same permissionless architecture that makes it attractive to privacy-conscious legitimate users also makes it a recurring feature in post-hack forensic reports. The protocol has previously appeared in the aftermath of high-profile exploits across the industry, and calls for its governance layer to implement more robust transaction screening have consistently run into ideological resistance from a community philosophically opposed to on-chain censorship. That tension is unlikely to resolve easily, and incidents like this one add pressure on regulators in multiple jurisdictions who are already scrutinizing decentralized exchange infrastructure.

For Coldcard users and the broader Bitcoin self-custody community, the emergence of a third wave of targeted exploits warrants a sober reassessment of operational security practices. Hardware wallet security does not exist in isolation — it intersects with seed phrase storage, firmware update hygiene, physical security, and the handling of partially signed Bitcoin transactions. A device that is cryptographically impenetrable can still be defeated at the human layer. Whether this campaign is exploiting a technical flaw, a process failure, or a social engineering vector, the pattern of repeated waves suggests the attacker has identified a repeatable method that has not yet been fully neutralized.

What This Means for the Industry

The broader implication of this incident runs beyond one attacker and one wallet brand. Cross-chain infrastructure built on permissionless principles is now a standard feature of sophisticated theft operations. Forensic tracing has improved dramatically — researchers were able to follow the funds to a new Ethereum address in near real time — but tracing and recovery are two very different things. Identifying where stolen assets land is of limited comfort if the legal and technical mechanisms to freeze or recover those assets across chains remain immature. The gap between forensic visibility and enforcement action is where hackers continue to operate, and the third-wave Coldcard case is a precise illustration of how that gap is being exploited with deliberate, methodical patience. Until cross-chain compliance infrastructure matures to match cross-chain swap infrastructure, that gap will remain open for business.

Written by the editorial team — independent journalism powered by Bitcoin News.