At Bitcoin block 965,339, Bitquery counted 1,402.59 BTC still sitting in identified addresses โ fully traceable, mostly unmoved. Then the ledger began to breathe. [[1]]
For months, the approximate $114.7 million in Bitcoin drained from Coldcard hardware wallets sat inert, a frozen monument to a five-year-old firmware defect. The attacker who reconstructed private keys offline without ever touching a device had parked the loot and vanished. On September 2 and 3, 2026, that stillness broke. A tracked 20.5 BTC stash moved through 34 THORChain swaps into Ethereum, routing 20.15 BTC of it to a single fresh address. [[11]][[2]] The investigation shifted from static attribution to an active cross-chain trail โ and the friction points along that trail are more revealing than the destination itself.
This is not a story about a thief cashing out with surgical precision. It is a story about a decentralized protocol absorbing a hostile actor's first tentative steps, about refund trails that map intent, and about the uncomfortable symmetry between forensic capability and laundering agility.
The Friction That Precedes the Flight
Let us be precise about what happened. Bitquery's tracker recorded 34 swaps on September 2โ3, routing 20.45 BTC of traced value into Ethereum. The broader total was 20.69 BTC across 36 swaps, including two earlier August transactions worth 0.24 BTC. [[13]] Most of the value โ 20.15 BTC across 26 swaps โ was routed toward one Ethereum address: 0x160a7A4c067B084F03400c6980Ac29F73F6782f6. Another 0.30 BTC went through eight swaps to a second Ethereum address. [[1]]
But the mechanics matter more than the sums. Galaxy Research's Alex Thorn, who traced the funds, reported that the attacker encountered repeated THORChain refund errors while retrying swaps. [[14]] Multiple attempts to convert the assets did not go through as intended; swaps were refunded, prompting further attempts. [[12]] This detail โ the refund trail โ is where the forensic analyst's eyes should linger.
THORChain operates on a continuous liquidity pool (CLP) model, not the lock-and-mint architecture of delegated bridges like WBTC. Users deposit native BTC into node-controlled addresses, swap within the pool, and receive the target asset on the destination chain. The protocol uses threshold signature schemes (TSS), where multiple nodes collectively manage private keys, requiring a threshold quorum to sign any transaction. [[2]] There is no wrapped token, no centralized custodian, no reversal mechanism. Once value crosses the threshold, it is gone โ a property the attacker clearly understood.
Yet the refunds tell a different story. The attacker was not executing a rehearsed exit. They were testing the route, probing liquidity depth, and iterating through failures. This is the signature of a route-test rather than a full cash-out โ an assessment Thorn explicitly endorsed. [[14]] Over 90% of Wave 3 funds remain untouched. [[15]]
What the Numbers Actually Tell Us
Let us decompose the on-chain footprint, because the aggregate obscures the intent.
First, the concentration. Routing 20.15 BTC through 26 swaps into a single Ethereum address is not the behavior of an operator versed in chain hygiene. A sophisticated launderer would spread across multiple destinations, interleave through privacy pools, or at minimum stagger the timing. The attacker used two intermediate Bitcoin addresses โ basic opsec, nothing more. No Wasabi mixing, no CoinJoin coordination, no evident attempt to obscure the cross-chain junction. [[2]]
The Ethereum destination address held roughly 644.5 ETH at last check, with only a small outgoing transaction of about 5 ETH โ the first activity since the theft. [[2]][[11]] The attacker is holding, not dumping. That holding pattern, combined with the repeated THORChain refunds, suggests a cautious operator assessing exit liquidity before committing larger tranches.
Second, the scale. Approximately 1,396.33 BTC โ roughly $90 million at current prices โ has never moved from identified addresses. [[1]] The 20.5 BTC that did move represents a fraction of the third wave's holdings. This is not an exit; it is a reconnaissance patrol. The attacker is testing whether THORChain's liquidity pools can absorb a meaningful liquidation without catastrophic slippage before committing the bulk.
Third, the timing. The swaps clustered across September 2โ3, a narrow window. Bitcoin-side confirmation typically requires one to three blocks for THORChain swaps, introducing a settlement latency that is both a security feature and an investigative opportunity. The attacker accepted that latency rather than using a faster but more centralized channel. That choice is itself a data point: the operator prefers permissionless rails over KYC friction, even at the cost of speed.
The Uncomfortable Symmetry
Here is the contrarian observation that the headline coverage misses: the same properties that make THORChain valuable for legitimate cross-chain settlement are precisely the properties that make it attractive for hostile actors. The ledger does not lie, only the narrative does.
THORChain's "anti-censorship" positioning โ no accounts, no KYC, native asset swaps without wrapped intermediates โ is a feature for a Ukrainian developer moving value across borders, and equally a feature for an attacker converting stolen Bitcoin into Ethereum. [[6]] The protocol does not discriminate. It cannot. Its TSS node network and CLP model are engineered to be indifferent to the identity of the swapper. That indifference is both its moat and its liability.
Consider what the attacker's choice reveals about competitive dynamics. The operator did not use WBTC, the custody-based bridge that dominates Bitcoin-to-Ethereum movement. They did not route through a centralized exchange with AML screening. They chose the only major protocol that offers native BTC-to-ETH settlement without an intermediary holding the collateral. [[18]] This is a demand signal for permissionless infrasture that regulators will not ignore.
The investigation now spans two separate public ledgers. Correlating Bitcoin outflows with THORChain swap memos and then following the resulting Ethereum addresses multiplies the analytic surface area. [[18]] Bitquery classified the funding source as "reported" rather than "confirmed" โ a distinction with legal weight. [[2]] The identity of the fund controller remains unverified. Galaxy Research has explicitly stated it cannot fully link every wave of the theft to a single operator. [[16]] The blockchain alone cannot confirm whether one group controls all four waves. [[16]]
The Regulatory Friction That Follows
Tracing the silent friction in the block height, what emerges is a structural irony. The attacker's refund errors โ the very failures that delayed the transfer โ may ultimately be the most damaging evidence. Each retry, each failed swap, each memo string, is a data point that analysts and, eventually, law enforcement can triangulate.
The operational takeaway is this: the 5 ETH outflow from the principal Ethereum address is the signal to watch. If the operator begins converting to stablecoins via DEX aggregation, expect fragmentation across multiple liquidity venues to mitigate slippage. If the operator attempts to move through a centralized exchange, the KYC layer becomes the enforcement lever. If the operator instead embraces privacy tooling โ Tornado Cash-style mixing or a privacy protocol โ the tracking window closes rapidly. [[20]]
For THORChain itself, the exposure is a double-edged sword. Each hostile transaction generates fees for liquidity providers โ a cynical form of "dirty revenue" โ while simultaneously reinforcing the regulatory narrative that permissionless cross-chain rails are laundering vectors. FATF has already flagged decentralized protocols as an emerging money-laundering channel. Events like this accelerate that scrutiny.
The Machine's Verdict
We map the chaos; we do not predict it. But we can read the signals embedded in this ledger with reasonable confidence.
The attacker is patient, technically competent at the infrastructure level, but not yet demonstrating sophisticated laundering technique. The concentration to a single ETH address, the absence of mixing, the repeated refund retries โ all point to an operator still developing their exit strategy. Over 90% of the third wave's funds remain parked, and 1,402.59 BTC across the broader theft is still traceable and unmoved. [[13]][[1]]
The next 30 days will determine whether this becomes a textbook recovery case or another cautionary tale about cross-chain anonymity. The questions that matter are not about price โ the market impact of $1.6 million in movement is negligible. The questions are structural: Can the industry's forensic tools keep pace with a determined operator's migration across chains? And can permissionless infrastructure sustain its legitimacy when its most active users are criminals?
Based on my audit experience across cross-border payment rails, the uncomfortable answer is that both sides of this arms race are improving simultaneously. The tracking tools are faster, the analytical coverage is broader, and the attribution techniques are more sophisticated than anything available in 2020. But the protocols themselves are also more capable, more liquid, and more indifferent to the intent of their users.
The ledger has broken its silence. What it reveals next will tell us which side of that race is winning.