Medasit

The Coldcard Move: 20.5 BTC Just Crossed THORChain, and the Bear Market Just Got a New Bellwether

Credtoshi
Scams

At Bitcoin block 965,339, the tracker counted 1,402.59 BTC still sitting in identified addresses โ€” fully traceable, entirely dormant. Then, on September 2, 20.49703196 BTC left a previously flagged address associated with what Bitquery calls "Wave 3" of the Coldcard incident. The number itself is unremarkable. The method is everything.

That 20.5 BTC โ€” roughly $1.6 million at current prices โ€” crossed into Ethereum through 34 consecutive THORChain swaps over two days. One Ethereum address received most of it and now holds approximately 644.5 ETH. A small outgoing transaction of about 5 ETH followed, the first activity since the theft. Galaxy Research's Alex Thorn shared the new address with law enforcement, crypto companies, and monitoring organizations. The controller remains unidentified. The funds are live.

Code does not lie, but it often omits the context. The context here is worth unpacking.

The Vulnerability That Made This Moment Inevitable

Let me be precise about the root cause, because the industry has a habit of conflating events. This is not a phishing story. This is not a malware story. This is a firmware story.

In March 2021, Coinkite shipped firmware version 4.0.1 for the Coldcard Mk2 and Mk3 hardware wallets. A single commit changed the seed-generation call from ckcc.rng_bytes โ€” which correctly routed to the STM32 hardware random number generator โ€” to ngu.random.bytes, which passed through the libngu MicroPython library. The production configuration defined MICROPY_HW_ENABLE_RNG as zero because Coinkite supplies its own hardware RNG wrapper. The libngu library checked whether the macro existed rather than whether it was enabled. The build silently bound to MicroPython's Yasmarang fallback.

A deterministic software PRNG replaced a hardware TRNG. Effective entropy dropped from 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4, Mk5, and Q models. For five years, nobody noticed.

When the first sweep hit on July 30, 2026, the attacker drained roughly 594 BTC from about 500 addresses in 25 minutes. Subsequent waves expanded the damage. Galaxy Research's current confirmed estimate sits at 1,789.28 BTC across 8,865 addresses โ€” approximately $114.7 million at the time. The figure may exceed 2,000 BTC if a suspected fourth wave verifies.

Every drained address shared the same root cause: a seed with far less randomness behind it than anyone assumed. The attacker brute-forced the weak seeds in 41 minutes during the first wave.

Why THORChain, and Why It Matters

THORChain is not a bridge in the conventional sense. It does not lock assets on one chain and mint wrapped tokens on another. It operates a continuous liquidity pool (CLP) model: users deposit native BTC into vaults controlled by a threshold signature scheme (TSS) node network, the swap executes within the pool using RUNE as the intermediate accounting unit, and native ETH releases on the destination chain. No wrapping. No pegging. No centralized third party that can freeze or reverse a transaction.

The CLP model runs on the Cosmos SDK with a CometBFT consensus engine and GG20 Threshold Signature Scheme. Node operators must bond more than 1.5x the value of the vault they secure. The economic security model aims to keep total bonded RUNE at approximately twice the value of all non-RUNE assets in the pools. This makes attacks expensive โ€” but it also makes the protocol indifferent to who initiates a swap.

That indifference is precisely why the attacker chose this route. Let me be direct about what this means: once BTC crosses into THORChain and exits as ETH, no single institution can claw it back. The cross-chain swap is permissionless, irreversible, and โ€” critically for the attacker โ€” it converts Bitcoin, which has no DeFi ecosystem, into Ethereum, which has DEX aggregators, stablecoin pairs, and privacy tools in abundance.

Bitquery's live tracker recorded 34 swaps on September 2 and 3. The THORChain deposits carried an OP_RETURN memo and an affiliate tag of "sto" set at zero basis points. Two intermediate Bitcoin addresses routed the funds before the swaps. The origin address sits in Bitquery's "reported" tier โ€” one step below its "confirmed" list. That distinction matters in ways most observers overlook.

The Attribution Problem Nobody Wants to Discuss

Here is the contrarian angle. The entire industry narrative around this event assumes the chain of custody is knowable. It is not.

Bitquery classifies the origin address as "reported" rather than "confirmed." That is not a cosmetic label. It reflects an epistemic boundary: the analytics provider can demonstrate that funds flowed through a specific address, but it cannot prove who controls that address. The controller remains unidentified. Links between the broader drain waves โ€” Wave 1 through Wave 4 โ€” remain unresolved. Galaxy Research explicitly stated it cannot definitively associate the footprints across all waves.

Now consider what this means for law enforcement. The new Ethereum address has been shared with authorities. But an Ethereum address is not a person. It is not even a wallet. It is a point in a graph. If the attacker routes through a DEX aggregator or a mixer, the graph branches. If they choose a centralized exchange, KYC becomes the key breakthrough โ€” but the attacker has already demonstrated operational awareness by avoiding the obvious move of direct CEX deposits.

The Wave 3 operator also appears to be struggling with the mechanics. Thorn reported that the attacker's THORChain swap attempts repeatedly resulted in refunds, followed by retries. This is not the behavior of a sophisticated laundering operation. It is the behavior of someone โ€” or some group โ€” that has operational capital but limited technical fluency. They understand enough to route through a decentralized cross-chain protocol. They do not understand enough to execute the swaps cleanly on the first pass.

That distinction provides a genuine investigative lead that most coverage has missed.

The Silent Two Billion Dollars

Let me return to the number that matters more than the 20.5 BTC that moved.

At Bitcoin block 965,339, Bitquery counted 1,402.59 BTC still sitting in identified addresses and fully traceable โ€” including 1,396.33 BTC that has never moved. That is roughly $90 million in stolen value parked in plain sight. The 20.5 BTC that crossed THORChain represents about 1.5% of the identified stash. The attacker is testing the pipeline, not executing a full exit.

The August 28 decoy sweep is evidence that the operators remain active. A deliberately weakened researcher wallet was swept shortly after being deployed โ€” proof that automated scanning for vulnerable private keys is still running roughly a month after the first large thefts. The group is not sitting on funds and waiting. They are probing for additional exposure.

This asymmetry โ€” $90 million dormant versus $1.6 million actively routed โ€” should reframe how the market evaluates the risk. The public narrative treats this as a $1.6 million laundering event. The technical reality is that it is a stress test of infrastructure designed to move $90 million.

The Compliance Reckoning That THORChain Cannot Avoid

THORChain's design philosophy is explicit: permissionless, censorship-resistant, no KYC. That philosophy now sits in direct tension with the Fatwa-level regulatory scrutiny that events like this invite. FATF guidance on virtual asset service providers already flags decentralized protocols as a gap. This event is a case study.

The regulatory blind spot is not that THORChain facilitates illegal transfers. That is a design feature, not a bug. The blind spot is that the protocol generates fee revenue โ€” RUNE holders capture value from every swap, including these 34 โ€” while having no legal personality that can be compelled to act. Regulators cannot sanction a protocol. They can only sanction the people who operate it, which means node operators, liquidity providers, and the RUNE token itself become the pressure points.

History provides the template. THORChain paused lending services in February 2025 amid a $200 million debt crisis. It has survived multiple security incidents since 2021. It keeps operating because the CLP model is genuinely useful. But every high-profile illicit use case narrows the window for institutional integration. The protocol is becoming a compliance liability at the exact moment it needs legitimacy to grow.

What to Watch Over the Next 90 Days

The Ethereum address at 0x160a7A4c067B084F03400c6980Ac29F73F6782f6 is now the most watched address in this investigation. Its current balance of approximately 644.5 ETH after a 5 ETH outgoing transaction suggests the attacker is testing liquidity depth. The critical question is whether the next move is a DEX swap into stablecoins or a CEX deposit. The former preserves anonymity at the cost of slippage. The latter simplifies capture.

The remaining 1,402.59 BTC is the real risk driver. If even a fraction of that moves through similar channels, the market impact becomes measurable. At current prices, a full liquidation would be a meaningful event for ETH ecosystem liquidity, even if the absolute scale remains small relative to daily volume.

I have spent the past decade auditing cross-chain infrastructure, and I can tell you this much: the Coldcard theft is not primarily a story about a hardware wallet failure. It is a story about the quiet collision between entropy math and protocol design. A single build flag destroyed the security assumptions of 8,865 addresses. A permissionless swap protocol then became the liquidation channel for the proceeds. Both facts are traceable on-chain. Neither fact is actionable without the other.

One last observation: the attacker chose THORChain over a centralized exchange even though CEXs offer deeper liquidity and faster settlement. That choice reveals their threat model. They fear identity exposure more than slippage. That fear is the one asymmetry investigators can exploit.

The forward-looking question is not whether this stolen value will move. It is whether the next wave does so with the same operational clumsiness โ€” or with the operational discipline this Wave 3 operator has not yet shown.

Market Prices

BTC Bitcoin
$76,066 -3.07%
ETH Ethereum
$2,428.82 -3.01%
SOL Solana
$99.63 -1.93%
BNB BNB Chain
$717.4 -0.54%
XRP XRP Ledger
$1.4 -0.14%
DOGE Dogecoin
$0.0822 -2.10%
ADA Cardano
$0.2032 -2.73%
AVAX Avalanche
$7.43 -0.38%
DOT Polkadot
$0.9825 -3.12%
LINK Chainlink
$11.27 -1.08%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{ๅนดไปฝ}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All โ†’
# Coin Price
1
Bitcoin BTC
$76,066
1
Ethereum ETH
$2,428.82
1
Solana SOL
$99.63
1
BNB Chain BNB
$717.4
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0822
1
Cardano ADA
$0.2032
1
Avalanche AVAX
$7.43
1
Polkadot DOT
$0.9825
1
Chainlink LINK
$11.27

๐Ÿ‹ Whale Tracker

๐ŸŸข
0x514b...629c
5m ago
In
1,442 ETH
๐ŸŸข
0xa42f...2901
3h ago
In
2,515,190 DOGE
๐Ÿ”ด
0x35cf...5283
6h ago
Out
34,321 SOL

๐Ÿ’ก Smart Money

0x5ee6...e5cd
Experienced On-chain Trader
-$3.4M
87%
0xdd35...f1a7
Market Maker
+$3.6M
95%
0x7be6...8cf3
Top DeFi Miner
+$0.9M
76%

Tools

All โ†’