Security · Update
After Weeks of Stillness, 20.5 Bitcoin Tested the Exit
For five weeks the addresses holding 1,789 stolen bitcoin did nothing at all. Then about 20.5 of them went into THORChain, came back, and went in again. The retries are the interesting part.
The most striking fact about the Coldcard theft has never been the size of it. It has been the stillness. Since late July, when an attacker began draining bitcoin from wallets whose seeds were generated by a flawed 2021 firmware build, the money has sat where it landed and done nothing. Galaxy Research put the total at 1,789.28 BTC — roughly $114.7 million at the time it was taken — spread across 8,865 addresses, and reported in late August that the overwhelming majority of it had not moved an inch.
On September 2, some of it moved. Alex Thorn, who runs research at Galaxy and has been tracking the wallet clusters since the theft began, posted that the attacker behind the third wave had swapped roughly 10% of their holdings into ether through THORChain, the cross-chain decentralised exchange. The Crypto Times put the figure at about 20.5 BTC. Over 90% of that wave's holdings stayed put.
It is not a large transaction. It is the first one, which is a different kind of significant. As TFTC noted in its write-up, this was the first confirmed movement out of the original attacker addresses across any of the three documented waves.
The swap kept coming back
Here is the detail that got buried under the headline number, and it is the one worth sitting with. The swaps did not work cleanly. Thorn's description, quoted by crypto.news, is almost comic in its plainness:
"The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying."
THORChain refunds are not an error condition in the usual sense. They are a documented, designed behaviour, and the design explains a great deal about why someone holding a very large amount of stolen bitcoin would struggle to convert it. When a swapper submits an order, they set a price limit — a minimum acceptable output. THORChain's developer documentation is explicit that if the swap cannot achieve that limit, the inbound amount is refunded, in whole or in part.
The protocol offers a tool for exactly this problem, called streaming swaps: a large order is chopped into a series of smaller sub-swaps executed at intervals, so the trade absorbs less slippage than it would in one shot. It works like a TWAP order, and it is capped — the documentation sets a maximum stream length of 14,400 blocks, about 24 hours. But a streaming swap is not magic. If the sub-swaps still cannot meet the price limit, the user gets a partial fill and a partial refund.
Neither Thorn nor any outlet covering this has confirmed which constraint bit — liquidity depth, the price limit the attacker chose, or a protocol safeguard. crypto.news said so directly, and this desk is not going to improve on that by guessing. What can be said without guessing is structural: THORChain's pools are finite, a swap large enough to move them meaningfully will breach a tight limit, and refunds are what the protocol does about it rather than a sign that anyone intervened.
The ledger, as of Sep 6
| Figure | Value | Source |
|---|---|---|
| Total stolen, all three waves | 1,789.28 BTC (~$114.7M at theft) | Galaxy Research |
| Addresses affected | 8,865 | Galaxy Research |
| Direct victim reports | 221, covering 790.72 BTC | Galaxy Research |
| Moved through THORChain, Sep 2 | ~20.5 BTC (~10% of wave 3) | The Crypto Times, Galaxy |
| Wave 3 still unmoved | Over 90% | Galaxy Research |
| Dollar value of the swap | Disputed | See note below |
One number needs flagging rather than repeating. Coin-turk headlined the swap at $11 million; no other outlet in this cycle carried that figure, and it does not survive arithmetic. Galaxy's own valuation implies roughly $64,000 per coin at the time of the theft, which would put 20.5 BTC nearer $1.3 million than $11 million. That is the desk's arithmetic against Galaxy's numbers, not a reported figure, and we offer it only to explain why we are not printing the larger one.
Why ether, and why now
Converting stolen bitcoin into ether is not a portfolio decision. Thorn's explanation, as summarised by TFTC, is that a cross-chain swap breaks "the transaction graph that blockchain forensics tools use to flag stolen UTXO sets". Bitcoin's model makes tainted coins unusually easy to follow: every output carries its history, and exchanges maintain lists of outputs they will not touch. Crossing to an account-based chain does not erase that history, but it does force the tracing firms to re-establish the link on the other side rather than read it off the ledger.
They re-established it here. Galaxy identified the receiving Ethereum address and, per every outlet covering this, shared it with law enforcement and with crypto companies in a position to freeze or flag deposits. Whatever the swap was meant to accomplish, anonymity was not among the things it achieved.
Which is what makes the size of the move readable. Twenty bitcoin out of a pile of roughly two hundred, moved through a route that immediately failed and had to be retried, is not a cash-out. It is a probe: an attempt to learn whether a particular exit works, at a scale where finding out that it does not costs very little. The refunds turned that probe into a fairly public one.
The part that never stopped
Two other threads in this story deserve to stay attached to it, because both complicate the picture of a thief sitting patiently on a hoard.
First, some funds were moving all along, just not from the three headline clusters. The Crypto Basic reports that in August, 64 BTC and 200 ETH were sent to mixers including Tornado Cash. That is a different behaviour from the wave-3 wallets, and it suggests either more than one actor or more than one strategy.
Second — and this is the line that should worry anyone still running an affected device — the harvesting has not stopped. The same report notes that a researcher's deliberately weakened test wallet was swept on August 28. That wallet was bait. Something took it. Nearly a month after the theft became public knowledge, whoever holds the key-derivation capability is still scanning for vulnerable seeds and still emptying what it finds.
The underlying flaw remains what it was: a firmware build from March 2021 that generated seeds with insufficient entropy on several Coldcard models, leaving them derivable by anyone who worked out the weakness. It only reaches single-signature wallets. A multisig arrangement using devices from more than one manufacturer was never exposed to it, which is the single most useful sentence in this entire episode and the one least likely to be acted on.
The Take
Ninety percent of a stolen pile sitting still is not restraint and it is not conscience. It is a liquidity problem, and this week the thief tried to measure it and got the answer sent back to him. That is genuinely good news, and it is worth naming why: the friction is doing real work here, and the friction exists because tracing firms, exchange compliance desks and a public ledger make large stolen sums genuinely hard to spend. None of that recovers a single coin for the 8,865 addresses on the list. But it does mean the number to watch is not the balance — it is the retry count. When the swaps stop bouncing, someone has found a route that clears, and the rest of the pile will follow much faster than five weeks. For anyone still holding bitcoin on a single-signature Coldcard from that firmware era: the bait wallet swept on August 28 is the whole answer to whether the risk has passed. Move the coins.