
Coldcard Hacker Uses THORChain to Convert Stolen Bitcoin to Ether
Vexoda Newsroom
A hacker involved in a series of Coldcard hardware wallet thefts has begun converting a portion of stolen Bitcoin into Ether using the THORChain decentralized exchange protocol, with analysts tracking
A hacker linked to a significant series of Coldcard hardware wallet security breaches has reportedly begun the process of liquidating a portion of the stolen digital assets. Specifically, the individual has started swapping Bitcoin (BTC) for Ether (ETH) using the THORChain decentralized exchange protocol. This marks the first on-chain movement of funds originating from the hacker's primary addresses associated with these thefts, indicating a potential shift in the attacker's strategy from hoarding to monetization. Analysts are closely monitoring these transactions to understand the full scope of the hacker's actions.
The key figures involved include the perpetrator of the Coldcard exploits and cryptocurrency security researchers like Alex Thorn from Galaxy Research. Thorn reported that approximately 10% of the total stolen funds have been moved. He noted that the hacker encountered difficulties in completing the swaps via THORChain, experiencing repeated transaction failures and refunds, suggesting potential limitations or challenges with the protocol's liquidity for such large-scale exchanges. The majority of the stolen assets, about 90%, remain untouched in the hacker's wallets.
This incident is part of a larger pattern of exploits targeting Coldcard hardware wallets, a popular device for self-custody of cryptocurrencies. Previous reports from Galaxy Research indicated that at least 1,789 Bitcoin, valued at approximately $114.7 million at the time of theft, were stolen from over 8,800 different addresses. In August, blockchain security firm CertiK also noted that some perpetrators had already utilized cryptocurrency mixers like Tornado Cash to obscure the trail of a smaller portion of stolen funds, totaling 64 Bitcoin and 200 Ether.
Following the reported swaps, the stolen Bitcoin was traced through THORChain to a newly created Ethereum address. This development was shared with relevant law enforcement agencies and industry participants. The specific strategy employed by the hacker, attempting to use THORChain, is a method often utilized to move assets between different blockchain networks without relying on centralized exchanges, which typically require user identification. However, the reported issues suggest that even decentralized solutions can present hurdles for large or potentially flagged transactions.
The implications of these transactions are significant for both the security of hardware wallets and the broader cryptocurrency market. The ability of attackers to move and convert such large sums, even with difficulties, highlights the ongoing challenges in tracing and recovering stolen digital assets. The use of THORChain demonstrates a sophisticated approach by the hacker to bypass traditional financial systems. This event underscores the importance of continuous security research and development within the crypto space to protect users from evolving threats and ensure the integrity of digital asset transfers.
Traders and market observers should pay close attention to several factors moving forward. Firstly, the hacker's success or failure in converting the remaining 90% of stolen Bitcoin will be crucial. Monitoring whether the attacker attempts alternative methods or exchanges to liquidate the bulk of the assets is key. Secondly, the actions taken by authorities and security firms in response to the traced Ethereum address could provide insights into potential recovery efforts or future security measures. Finally, any further exploitation attempts or successful defense mechanisms against such attacks will influence trust and security perceptions around hardware wallets.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.