Stolen Funds from Coldcard Wave 3 Attack Move On-Chain for First Time
The cryptocurrency community is tracking a significant on-chain development. Alex Thorn, Head of Research at Galaxy Digital, indicated via social media that the wallet address associated with the Coldcard Wave 3 security incident has seen its first movement of funds since the attack occurred.
Fund Flow and Conversion Attempts
On-chain data reveals that the attacker did not simply transfer the funds to another custodial wallet. Instead, they attempted to convert a portion of the assets into Ethereum (ETH) using a decentralized cross-chain trading protocol. This move is a first among the Wave series of incidents, breaking the pattern of stolen funds remaining dormant in the original address.
The scale of this transfer remains limited. Currently, approximately 90% of the crypto assets stolen in the Wave 3 event are still held in the attacker's initial wallet, untouched.
Technical Hurdles in the Conversion Process
A deeper look at the chain activity shows the attacker's conversion attempts were not smooth. Multiple transaction records indicate issues, with some transactions being refunded by the protocol. This suggests the entity faced technical challenges during the cash-out process, or encountered insufficient cross-chain liquidity at specific times.
Despite these setbacks, monitoring shows the attacker has persisted, continuously submitting new transaction requests in an effort to convert the remaining funds. This pattern of trial and error provides security teams and exchanges with additional clues and a longer time window to trace the fund flow.
Context and Industry Implications
The Wave series of vulnerabilities affecting Coldcard had previously raised significant concern among hardware wallet users. The Wave 3 attacker's decision to move funds now may signal a new phase in their liquidation strategy. Security experts advise:
- Relevant exchanges should enhance monitoring of suspicious ETH inflows.
- Users holding affected assets should stay informed, though direct recovery remains unlikely.
- This event underscores the complexities decentralized cross-chain bridges face in anti-money laundering monitoring.
Industry observers suggest the timing of this move could be related to market conditions, cash-out channels, or the attacker's own risk assessment. Further fund movements will be under close surveillance.