Over the past 48 hours, a specific cluster of transactions has been quietly dissected by blockchain researchers. The third wave of attackers responsible for the Coldcard hardware wallet breach just moved approximately 10% of their stolen Bitcoin. But they didn't touch a centralized exchange. No KYC. No freeze risk. They routed it through THORChain, converting native BTC into ETH and landing it in a freshly identified Ethereum address.
This isn't just a blip on a tracking dashboard. It's a case study in how sophisticated actors view the current infrastructure landscape. Based on my years auditing cross-chain flows and tracking high-profile exploits, this specific move tells me more about the state of DeFi infrastructure than the hack itself.
Let's deconstruct what actually happened, why it matters, and where the blind spots are.

The Context: Why THORChain and Not a Mixer?
Coldcard, built by Canadian firm Coinkite, holds a reputation as one of the most secure hardware wallets on the market. It's the tool of choice for long-term holders who prioritize self-custody over convenience. A compromise here isn't just a theft; it's a breach of trust in the highest-assurance layer of the stack.
This "third wave" implies prior attempts or successful attacks, likely targeting different cohorts of users. Now, the attacker is sitting on a pile of native BTC. In 2022, the playbook was clear: route through Tornado Cash or a chain-hopping mixer. In 2025, the calculus has shifted.
THORChain offers something mixers and CEXs don't: native, non-custodial asset swaps. No wrapped tokens, no pegged assets. It's a continuous liquidity pool (CLP) settled in RUNE. For an attacker, this solves the two biggest problems: liquidity depth and settlement finality. They convert BTC to ETH without relying on a custodian, and more importantly, without triggering the red flags that a sudden influx of $5 million to a KYC'd exchange would.

The Core: Deconstructing the Attacker's Path
The technical path is clean: