What happened
Galaxy Digital published tracing Monday showing the attacker behind the Coldcard breach has cycled 45% of stolen Bitcoin through a mix of THORChain swaps and CoinJoin coordinators, according to a report from CryptoBriefing on September 7. THORChain lets users swap native BTC for other native assets without a centralized intermediary, breaking the on-chain trail. CoinJoin batches multiple users' inputs into a single transaction, obscuring which output belongs to which sender.
Galaxy's researchers say the attacker chained the two, first swapping into other assets and then routing back through CoinJoin coordinators to further fragment the flow. The remaining 55% sits in wallets that on-chain analysts are watching in real time. Neither Coldcard's parent company Coinkite nor Galaxy has published a precise dollar figure for the funds still at risk.
Why it matters
This is the second high-profile case in eighteen months where THORChain has surfaced as the laundering rail of choice after a major exploit. The pattern matters because THORChain's cross-chain swaps are non-custodial and permissionless. There is no exchange desk to freeze the funds and no compliance officer to serve a subpoena.
Recovery pressure has to be applied at the protocol governance layer, and the community's appetite for that intervention is uneven at best. Coldcard is a hardware wallet, marketed to self-custody users who explicitly opted out of exchange risk. An attacker walking away with wallet funds and then laundering them through decentralized rails cuts at the core sales pitch of the hardware-wallet category.
