The operator tied to the third wave of the Coldcard hardware-wallet exploit has begun converting stolen Bitcoin into Ether, marking the first confirmed movement from the original attacker addresses linked to Waves 1, 2, or 3.
Galaxy Research head Alex Thorn reported late Wednesday that a Wave 3 cluster moved about 20.5 BTC through the THORChain cross-chain exchange, with payouts landing on Ethereum.
Thorn’s on-chain chart traces coins from victim addresses through a collection wallet, a pay-to-witness-script-hash vault, and several 2-of-2 hops before they reached THORChain inbound vaults. He said the transfers are the first funds from those three documented waves to leave the original hacker addresses.
A follow-up note added that about 90% of Wave 3 holdings remain unmoved and that several swap attempts were refunded before later retries.
The movement does not resolve the larger theft. Galaxy’s later public tallies have placed high-confidence losses near 1,789 BTC across more than 8,800 addresses, valued at about $115 million at the time of theft. Those figures sit in Galaxy research updates and are independent of the smaller Wave 3 cash-out seen on September 2.
First cash-out from the documented waves
Wave 3 stood apart from the earlier sweeps. Instead of a single collector, researchers mapped hundreds of separate vaults. Until September 2, those scripts were known only as hash-locked outputs. The first spend revealed a 2-of-2 multisignature construction, and subsequent hops used the same pattern with different key pairs.
Thorn said the cash-out wallet also differed from the software used in the July and August sweeps. The later transactions signaled replace-by-fee, set a recent locktime, and paid higher fees. THORChain deposits appeared to come from a third interface, carrying an OP_RETURN memo and an affiliate tag of “sto” at zero basis points. Those details describe wallet fingerprints already visible on-chain; they do not identify the operator.
Most of the stolen Wave 3 Bitcoin still sits in the original vaults. That pattern matches the earlier waves, which remained inert for weeks after the first thefts on July 30. The new swaps therefore matter less as a change in total losses than as a change in behavior: an operator who previously left coins untouched is now testing a cross-chain exit.
Read: Coldcard Hacker Went After Largest Bitcoin Wallets First: Chainalysis
Firmware flaw and remaining user risk
The thefts followed a seed-generation flaw that Coinkite disclosed in a security advisory on July 30. The company said some Coldcard firmware released from March 2021 onward produced seeds with weaker entropy than intended. Devices themselves were not remotely taken over. Attackers reconstructed keys offline and spent from funded addresses.
Coinkite later published a firmware update and repeated the same warning: installing new firmware does not repair a seed already created on affected software. Users must generate a new seed on fixed firmware and move funds. Co-founder Rodolfo Novak apologized publicly, said the firm shipped a hotfix that removes the software fallback path, and asked holders to migrate before reading further technical notes.
The manufacturer also said TAPSIGNER, OPENDIME, and SATSCARD use different code and were not covered by the same advisory. Seeds created with at least 50 independent private dice rolls were treated as an exception because the dice themselves supplied the required entropy.
The Wave 3 swaps do not change that guidance. Coins still sitting on Coldcard-generated single-signature addresses remain exposed if the seed was created on vulnerable firmware. Researchers have treated later opportunistic thefts as separate from the three large, patterned waves, but the practical advice is unchanged: move funds to a newly generated seed.
Also read: Ledger Hit With $500M Class Action Over $1.9M Wallet Theft
