For the first time since the third wave of the Coldcard hardware wallet attack campaign, funds have moved — and they are not sitting still. Roughly 4.2 Bitcoin (BTC) from the Wave 3 attacker's addresses has been converted into approximately 135 Ether (ETH) through THORChain, the permissionless cross-chain liquidity protocol. The movement marks a significant escalation in the post-exploit lifecycle of these stolen funds, signaling that whoever is behind the Wave 3 attack is now actively pursuing obfuscation — and that the cross-chain infrastructure meant to serve decentralized finance (DeFi) continues to function as a primary escape route for bad actors.
The mechanics here matter. THORChain is designed to enable native cross-chain swaps without wrapped tokens or custodial intermediaries, which is precisely what makes it attractive for legitimate users seeking trustless asset exchange — and equally attractive to those attempting to launder proceeds from theft. By routing stolen Bitcoin through THORChain and emerging on the other side as ETH, an attacker gains both asset-class diversification and an additional layer of chain-hopping complexity that complicates blockchain forensics. The attacker did not simply execute a single clean swap; they tested multiple routes through the protocol before completing the conversion, suggesting either a deliberate probing of the infrastructure's limits or an attempt to identify the path of least friction before committing larger sums.
A Pattern the Industry Has Seen Before
The playbook being deployed here is familiar. High-profile exploits targeting Coldcard hardware wallets — one of the most respected names in self-custody Bitcoin security — have previously resulted in dormant stolen funds that sit untouched for extended periods before attackers eventually decide conditions are right to move. The Wave 3 label implies this is the third distinct attack campaign in a sequence, which itself indicates an organized, methodical threat actor rather than an opportunistic one-off. The fact that Wave 3 funds remained static until now, only to emerge routed through a cross-chain protocol, follows a pattern well-documented in post-mortem analyses of prior large-scale crypto thefts.
THORChain finds itself in a familiar and uncomfortable position. The protocol has previously been exploited directly — suffering its own security incidents — and has repeatedly appeared in the transaction trails of high-profile hacks, including in the aftermath of the Bybit exchange breach. The protocol's developers and community have long grappled with the tension between censorship resistance as a design principle and the reputational and regulatory exposure that comes from being a documented conduit for stolen assets. Several of the Wave 3 attacker's swap attempts appear to have encountered friction before the successful 4.2 BTC-to-135 ETH conversion went through, though the protocol ultimately did not prevent the laundering activity from completing.
What 4.2 BTC Tells Us About Attacker Intent
The relatively modest size of the initial swap — 4.2 BTC — is worth examining carefully. In the context of a coordinated multi-wave attack campaign targeting hardware wallet users, 4.2 BTC is unlikely to represent the entirety of Wave 3 proceeds. More plausibly, it represents a test: a probe of on-chain monitoring response times, law enforcement reaction, and the protocol's behavior under scrutiny before larger tranches are moved. This is consistent with the attacker's behavior of testing multiple routes through THORChain rather than committing immediately to a single path. The 135 ETH received on the other end of that swap now sits in Ethereum address space, where it can be further fragmented, routed through mixers, or deposited into DeFi protocols to further complicate tracing.
The timing also raises questions. Moving funds years or months after an attack, when blockchain analytics capabilities have matured and investigative attention may have partially shifted elsewhere, is a calculated risk that some attackers are willing to take. On-chain intelligence firms that have been tracking Wave 3 attacker addresses will now face the more complex task of following assets across chains — a challenge that cross-chain forensics has improved at addressing, but that still introduces meaningful friction for investigators.
Hardware Wallet Trust and Infrastructure Accountability
Beyond the immediate forensics story, the Coldcard Wave 3 movement reopens broader questions about the attack campaign itself. Coldcard has maintained a strong security reputation within the Bitcoin self-custody community, and each wave of the attack series has chipped away at confidence in hardware wallet security more generally — not necessarily because of flaws in the devices themselves, but because the threat models surrounding seed phrase management, supply chain integrity, and physical security remain deeply underappreciated by users. When stolen funds from these attacks begin moving, it forces a renewed reckoning with both how the theft occurred and what the recovery of any funds realistically looks like.
For the DeFi infrastructure layer, and for THORChain specifically, the repeated appearance of the protocol in post-exploit laundering chains is becoming a regulatory flashpoint that the ecosystem cannot indefinitely deflect. Cross-chain bridges and liquidity protocols that operate without Know Your Customer (KYC) requirements will face mounting pressure from regulators in the United States, European Union, and elsewhere as evidence of their role in laundering stolen crypto assets accumulates in public blockchain data. The Wave 3 swap may be small in absolute terms, but it is another entry in a ledger that policymakers are actively reading.
What this development means in practice is straightforward: the Coldcard Wave 3 attacker is no longer dormant, they have demonstrated willingness to use cross-chain infrastructure to convert and obscure stolen Bitcoin, and the broader crypto security community should treat this initial 4.2 BTC swap as a precursor rather than an isolated event. The next moves will be watched closely — and they will come.
Written by the editorial team — independent journalism powered by Bitcoin News.