Coldcard Attacker Moves 45% of Stolen BTC, Galaxy Reports
Galaxy reports that the attacker behind the Coldcard-linked Bitcoin theft has moved 45% of the stolen BTC, routing the funds through the cross-chain swap protocol THORChain and the...
Galaxy reports that the attacker behind the Coldcard-linked Bitcoin theft has moved 45% of the stolen BTC, routing the funds through the cross-chain swap protocol THORChain and the privacy technique CoinJoin.
TLDR KEYPOINTS
- Galaxy reports the attacker has moved 45% of the stolen Bitcoin.
- THORChain and CoinJoin are named as the fund-movement routes.
- The available context does not establish the theft mechanism or the total amount stolen.
Galaxy reports movement of 45% of stolen Bitcoin
The finding is attributed to Galaxy, which reports that roughly 45% of the stolen Bitcoin has been moved by the attacker. The share describes funds in motion, not a recovery or a seizure. For related coverage, see Coldcard Releases Firmware 5.6.1 After $100M Exploit Claim, Adds User Entropy for New Seeds.
What the reported 45% represents
The 45% is a reported share of the stolen Bitcoin that has been moved. The available context does not convert that share into a BTC quantity or a dollar figure, and no total stolen amount is established here. For related coverage, see Liquid Network Hack: WatcherGuru Reports 4,000 BTC Withdrawal.
The label “Coldcard attacker” reflects how the incident has been described in the reporting. It does not, on this evidence, indicate a device compromise, a hardware vulnerability, or manufacturer responsibility. Coinlive has separately tracked claims that the wider Coldcard exploit tops $100 million in stolen BTC and that a suspected fourth wave of attacks put 449 BTC at risk.
THORChain and CoinJoin are named as fund-movement routes
Galaxy names two routes for the reported movement: THORChain and CoinJoin. The 45% figure applies to the reported movement involving those routes together; it is not a split assigned to each route individually.
THORChain’s mention in the reported movement
THORChain, a cross-chain swap protocol, is cited as one route used in the reported transfers. The context provides no transaction records, no destination assets, and no wallet identifiers tied to that route.
CoinJoin’s mention in the reported movement
CoinJoin, a coin-mixing technique, is the second named route. Its mention describes how funds were reportedly moved and does not indicate that THORChain or CoinJoin operators participated in or endorsed the theft.
What the supplied information leaves unresolved
Moving funds does not, on this evidence alone, establish a sale, a cash-out, or a permanent loss of traceability. On-chain movement and successful laundering are not the same claim, and none of the underlying transactions are shown here. Readers can independently monitor Bitcoin network activity via Mempool.space.
The remaining 55% is not described here as stationary, recovered, frozen, or still under the attacker’s control; the available context simply does not say. Prior coverage of the incident set out what happened in the Coldcard exploit for additional background.
The total stolen amount, the timing of the theft and transfers, the theft mechanism, and transaction-level evidence are absent from the supplied context. Those are limits of the information at hand, not necessarily gaps in Galaxy’s underlying report.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Author
Akita Inu
Akita Inu covers fast-moving crypto market updates, exchange news, and token ecosystem developments for CoinLive, with a focus on concise source-led reporting.