Coldcard's Wave-Three Attacker Moves Coins for the First Time

Coins from the third wave of the Coldcard thefts moved for the first time this week. Alex Thorn, who heads research at Galaxy, reported on Thursday that the wave-three attacker had pushed bitcoin through THORChain, a protocol that swaps assets across chains without a central exchange, and taken ether out at a fresh address. About a tenth of that attacker's holdings went, and more than 90% of it has not moved at all. This is the first departure of funds from the original attacker addresses in any of the three waves. Researchers passed the new Ethereum address to authorities and to crypto firms.
The swap kept bouncing
The route did not run cleanly.
"The hacker appears to be having some issues swapping all the funds through THORChain β they keep getting refunded and he keeps retrying," Thorn wrote, in the account Cointelegraph carried on Thursday.
The Crypto Basic describes the same report in looser terms, saying attempts repeatedly ended in refunds and were tried again. On the size of the transfer, The Crypto Times and Coin Insider both put about 20.5 BTC into THORChain's inbound vaults. Coin Insider alone adds that roughly 17.7 BTC came back as refunds and about 90.26 ETH reached the linked Ethereum address; no other account reviewed for this piece carries those two figures. Every outlet frames the movement as roughly 10% of wave three, and none publishes wave three's own total, so the share and the bitcoin figure cannot be checked against each other. The dates do not line up either. Four accounts put the transfer on 3 September, and The Crypto Times dates it a day earlier.
What the whole theft now counts as
Galaxy's running tally has climbed. Cointelegraph, crypto.news, TFTC and The Crypto Basic all give at least 1,789 BTC taken from 8,865 addresses, worth about $114.7 million when it went. Coin Insider states the same analysis more loosely, as more than 1,700 BTC worth over $110 million, which is a rounding of one count and not a rival to it. This desk published Galaxy's earlier figure of 1,719 BTC a month ago, and the gap between the two numbers is the tracing done since. crypto.news is alone in breaking the work down, to 221 victim reports covering 790.72 BTC, with further addresses found on-chain.
The flaw is still in circulation
The cause has not changed since July. A Coldcard firmware build from March 2021 shipped a broken random number generator, so seed phrases came out with too little randomness and private keys could be worked out without touching the device. Coinkite has shipped corrected firmware, and its guidance is that the fix does not reach backwards: installing new firmware does not repair a seed already created on affected software, the company said in a line The Crypto Times quotes. Anyone whose seed was made on a bad build has to generate a new one and move the coins across. The company told users to migrate in August, as the sweeps continued. The Crypto Times extends the affected window to 2023 and treats users who supplied 50 or more dice rolls at setup as unaffected; TFTC names the Mk3, Mk4, Mk5 and Q as the models at risk. Each of those details rests on one account.
Where the trail goes from here
What the attacker does next is not on the record. The coins could sit, move again for cover, or reach an exchange, and no account read here predicts which. Mixing has already featured in the wider file. CertiK reported in August that 64 BTC and 200 ETH linked to the exploit went to mixers including Tornado Cash, a service that pools deposits to break the link between sender and receiver. The attackers were still working late that month, when they swept a deliberately weakened wallet a researcher had planted to test their key-finding. Nothing in the on-chain record says why this week was the week, and nobody has claimed the addresses. The number to watch is the 90% that stayed where it was put.
Read also: The Coldcard Flaw Traces to One Disabled Build Flag