CASABLANCA, September 3, 2026
A Coldcard Wave 3 operator moved about 20.5 Bitcoin into Ether through THORChain after weeks of inactivity, the first spend from the original attacker addresses across the three documented attack waves as Bitcoin traded above $81,000.
The Sept. 2 movement is a material follow-up to the wallet theft rather than a new drain. It shows one operator beginning to route previously stolen assets across blockchains, while most of that operator’s holdings and most of Galaxy Research’s broader high-confidence total remained parked.
Bitcoin traded near $81,539 late Thursday, up about 5.7% over 24 hours and 27.1% over the prior month, according to CoinGecko market data. Its market value was about $1.637 trillion and 24-hour volume was roughly $35.8 billion, making the moved 20.5 BTC worth about $1.67 million at the review price.
Galaxy Research head Alex Thorn said in his public on-chain update that the operator appeared to have trouble swapping all the funds because THORChain kept refunding attempts and the operator kept retrying. Thorn said roughly 10% moved, about 90% remained, and analysts traced the output to a new Ethereum address that he shared with authorities and crypto companies.
The dedicated loss-impact review found no credible evidence that the transfer increased the number of victims or the amount originally stolen as of 8 p.m. UTC on Sept. 3. Galaxy’s later high-confidence tally attributed 1,789.28 BTC from 8,865 addresses to the incident, worth about $114.7 million when stolen; the new event changes the location and form of part of the proceeds, not that loss total.
Bitcoin
BTCColdcard Wave 3 Funds Reach THORChain
The operator moved the coins through a chain of Bitcoin transactions and a two-of-two multisignature vault before sending them to THORChain inbound addresses, according to the updated Coldcard money map. Native Ether was then paid to a new Ethereum address.
THORChain’s official swap documentation explains that a BTC-to-ETH trade enters a Bitcoin vault, passes through BTC:RUNE and RUNE:ETH liquidity pools internally, and releases native ETH on Ethereum. The user does not need a centralized exchange account or a wrapped Bitcoin token.
That permissionless route changes the tracing problem. The Bitcoin deposits and Ethereum payouts remain public, but the asset and destination chain change, so investigators must carry attribution across separate ledgers rather than wait for the original BTC to reach a conventional exchange deposit address.
The movement also needs a precise qualifier. Thorn described it as the first funds from the original addresses in Waves 1, 2 or 3 to move on-chain. Smaller Coldcard-linked footprints had already reached services, and TRM Labs previously reported a 64.9 BTC Wasabi deposit and 200 ETH entering Tornado Cash, so this was not the first laundering activity anywhere in the wider case.
Daily Crypto Briefs’ earlier fourth-wave report described roughly 1,816 BTC traced by TRM Labs across four waves. Galaxy’s 1,789.28 BTC and TRM’s roughly 1,816 BTC are separate, time-bound estimates with different address and attribution methods; they should not be added together.
The 20.5 BTC Swap Does Not Add to Losses
The 20.5 BTC figure represents stolen property changing hands and chains, not another 20.5 BTC of victim losses. At Thursday’s market price it was worth about $1.67 million, but the economic damage was recorded when those coins first left victim wallets.
Galaxy valued its high-confidence 1,789.28 BTC tally at $114.7 million at the time of theft. The same amount would be worth about $145.9 million at $81,539 per Bitcoin, but that mark-to-market comparison does not establish a larger recoverable claim, a new theft or proceeds actually converted into cash.
The incident began with a random-number-generation weakness in Coldcard firmware. Daily Crypto Briefs’ initial Coldcard seed warning explains the affected model and firmware paths, while Coinkite’s security advisory says updated firmware can improve future seed creation but cannot repair an affected seed already generated.
That distinction separates this case from a breach of the Bitcoin or THORChain consensus systems. The attacker did not need to reverse Bitcoin transactions or break THORChain to use its liquidity; the underlying Coldcard weakness made some wallet keys searchable, and the swap protocol then processed transactions signed by whoever controlled those keys.
The new destination does not prove the attacker has cashed out. A swap from BTC into ETH establishes control and movement, while realization into bank deposits, goods or another off-chain asset would require additional evidence that has not been disclosed.
Investigators Track the New Ethereum Address
Thorn said the Ethereum destination was sent to relevant authorities and crypto companies. That can help compliance teams watch for later deposits, but no agency, exchange or analytics firm had announced a freeze, seizure, recovery or identified suspect at the review time.
Repeated refunds may indicate a routing or liquidity constraint, but the public evidence does not establish the operator’s intent. The restrained conclusion is that one Wave 3 cluster tested and completed a cross-chain route while leaving about 90% of its holdings in the original addresses.
The broader investigation also remains open. Galaxy’s tally covers 8,865 addresses, not necessarily 8,865 people, and public reporting has not produced a final reconciled victim list, one agreed four-wave total or evidence that every stolen coin is controlled by a single actor.
The Crypto Fear and Greed Index read 65, or Greed, on Sept. 3, compared with 63 one day earlier. The Bitcoin-focused sentiment gauge does not measure recovery odds, but it places the first attacker spend against a sharply rising market that increased the dollar value of the still-unmoved BTC.
Fear & Greed Index
September 3, 2026The next material checkpoints are further movements from the Wave 3 vaults, any transfer from the new Ethereum address into an identifiable service, and a public recovery or enforcement announcement. For affected Coldcard holders, the unchanged priority is Coinkite’s migration guidance: old vulnerable seeds remain vulnerable even after a firmware update.
Stay up to date
Get the latest crypto insights delivered to your inbox
Primary sources and further reading
| Source | Title |
|---|---|
| | Alex Thorn: Coldcard Wave 3 fund-movement update |
| | Coldcard money map and on-chain tally |
| | Coinkite: Coldcard Mk3 Seed Generation Warning |
| | THORChain: Native Cross-chain Swaps |
| | CoinGecko: Bitcoin market data |
| | Alternative.me: Crypto Fear and Greed Index |
Fact-checked by: Daily Crypto Briefs Fact-Check Desk
Related Articles
Frequently Asked Questions
How much stolen Coldcard Bitcoin moved through THORChain?
On-chain reporting put the transfer at about 20.5 BTC, roughly 10% of the Wave 3 operator's holdings. Galaxy Research's Alex Thorn said about 90% of that operator's funds remained at the original addresses after the movement.
Was this the first movement of stolen Coldcard funds?
It was the first spend from the original attacker addresses associated with the three named Coldcard attack waves, according to Thorn. Other smaller Coldcard-linked clusters had previously sent assets to exchanges or mixers, so it was not the first movement anywhere in the broader investigation.
How much was lost in the Coldcard exploit?
Galaxy's later high-confidence tally attributed 1,789.28 BTC from 8,865 addresses to the exploit, worth about $114.7 million when stolen. TRM Labs separately traced roughly 1,816 BTC from more than 5,200 addresses across four waves using a different methodology.
Can authorities recover Bitcoin swapped through THORChain?
A cross-chain swap does not itself return stolen funds or identify an attacker. Thorn said the destination Ethereum address was shared with authorities and crypto companies, but no seizure, recovery or public attribution had been announced at the review time.



