Based on findings from Galaxy Research, the malicious actor responsible for the third wave of the Coldcard wallet breach has transferred nearly 45% of their acquired Bitcoin (BTC) by channeling the assets via THORChain or utilizing CoinJoin transactions.
In a post on Monday, Galaxy noted that the perpetrator initiated the transfer of assets to Ethereum via THORChain on Sept. 2. These recent transfers directed the Bitcoin into CoinJoin sessions, which merge various user payments into one collective transaction to obscure the origin of the funds.
Galaxy reported that the third-wave hacker established 293 two-of-two multisig vaults to secure the assets of victims, and is currently transferring capital from the primary vaults starting with the largest balances. Assets housed within the 11 biggest vaults have already been relocated.
These activities enabled Galaxy to uncover an undiscovered vault that they believe likely contains capital belonging to another Coldcard victim, though the root cause of that specific loss is still unverified.
According to Galaxy, looking at every phase of the Coldcard incident, about 82% of the pilfered Bitcoin stays inside the addresses originally set up by the hacker, whereas 18% has been shifted, presumably to obfuscate the trail.
As stated by DefiLlama, the Originally published at https://cointelegraph.com/news/coldcard-third-wave-attacker-moves-bitcoin-stolen?utm_source=rss_feed&utm_medium=rss&utm_campaign=rss_partner_inbound.