security
Coldcard Exploiter Converts Stolen Bitcoin to ETH via THORChain
A hacker responsible for exploiting Coldcard vulnerabilities has transferred approximately 10% of the stolen Bitcoin to Ethereum through THORChain. Researchers have traced these assets to a new Ethereum address, highlighting ongoing activity in the aftermath of the breach.
AS1 NewsSource: cointelegraph.com
The third-wave Coldcard exploit has seen the attacker move a portion of the stolen Bitcoin—about 10%—through the decentralized liquidity protocol THORChain. This movement indicates an attempt to convert the stolen funds into Ethereum, possibly to obfuscate the assets or facilitate further transactions.
Security researchers have traced the transferred assets to a new Ethereum address, suggesting ongoing activity and potential laundering efforts by the attacker. The exploit involved vulnerabilities in Coldcard, a popular hardware wallet, raising concerns about hardware security and protocol resilience.
THORChain, known for enabling cross-chain swaps without intermediaries, has been used in this case to facilitate the asset transfer from Bitcoin to Ethereum. This highlights the protocol's role in cross-chain asset movement, especially in illicit activities.
The incident underscores the importance of security in hardware wallets and the need for continuous vigilance in cross-chain protocols. While the attacker has moved a fraction of the stolen funds, the activity demonstrates the persistent threat posed by exploits in the crypto ecosystem.
The event highlights ongoing security vulnerabilities and the use of cross-chain protocols in illicit asset movement, emphasizing the need for enhanced security measures.