BTC $78,683.45 -0.49%
ETH $2,492.71 +0.17%
BNB $755.33 +2.13%
XRP $1.42 +1.87%
SOL $103.67 -0.05%
TRX $0.3390 +1.34%
DOGE $0.0907 -0.14%
ADA $0.2204 -0.11%
BCH $259.31 -0.43%
LINK $12.54 -1.61%
HYPE $85.50 +0.72%
AAVE $129.18 -2.31%
SUI $0.8219 +0.37%
XLM $0.1883 -2.43%
ZEC $1,185.05 +4.03%
BTC $78,683.45 -0.49%
ETH $2,492.71 +0.17%
BNB $755.33 +2.13%
XRP $1.42 +1.87%
SOL $103.67 -0.05%
TRX $0.3390 +1.34%
DOGE $0.0907 -0.14%
ADA $0.2204 -0.11%
BCH $259.31 -0.43%
LINK $12.54 -1.61%
HYPE $85.50 +0.72%
AAVE $129.18 -2.31%
SUI $0.8219 +0.37%
XLM $0.1883 -2.43%
ZEC $1,185.05 +4.03%

ross

All
Article
Flash

Galaxy Research: Coldcard attackers continue to transfer funds, approximately 45% of the stolen assets have entered mixing or cross-chain pathways

Galaxy Research published that the attackers in the Coldcard "Wave 3" attack are still continuously transferring the stolen funds. During this phase, the attackers created 293 2-of-2 multi-signature wallets for each victim's assets. The first batch of funds was transferred across chains to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attackers are processing the largest amounts of stolen funds in order of the stolen amount, having sequentially transferred the funds from wallets ranked 1 to 11. The next 10 wallets that have not yet been transferred hold a total of 30.81 BTC, while wallets ranked 61 to 293 hold a total of 33.77 BTC. So far, the attackers have transferred about 45% of the stolen assets from this exploit, with funds flowing to Ethereum (via THORChain) or entering CoinJoin mixing transactions. Additionally, this fund transfer has revealed a previously unknown wallet: 58 addresses jointly spent in a 2-of-2 multi-signature format identical to that of Wave 3, and these were further transferred by the Wave 3 attackers to a jump address that funds CoinJoin.The on-chain analysis team currently marks this wallet as "cause = open," but believes it likely also belongs to Coldcard victims, which means the number of wallets involved in Wave 3 may increase to 294, raising the previously reported total amount stolen from the Coldcard vulnerability to approximately 1806 BTC. Currently, about 82% of the stolen BTC remains in addresses initially controlled by the attackers, while about 18% has been transferred, with the flow of funds indicating that it may be undergoing laundering processes.

first_img Cross-chain infrastructure Router Protocol announced its closure and will destroy 303 million ROUTE tokens

Router Protocol, a cross-chain infrastructure project supported by Coinbase Ventures, announced that it will cease all operations by September 30 and plans to permanently destroy 303,333,198 ROUTE tokens held in its treasury, accounting for about 30% of the total supply of nearly 1 billion tokens. The team released a statement on X, stating that over the past year, they attempted commercialization, licensing, and acquisition negotiations, but failed to achieve sustainable operational results.Router identified the flow of funds from the cryptocurrency sector to artificial intelligence and the decline in cross-chain asset transfer fees as core challenges facing its operations. As activities concentrated on fewer networks and standardized infrastructure, the demand for its services has decreased. The team noted that bridging economic profits are thin, fees have been compressed, and costs have never stopped. As part of the closure, Router will negotiate with centralized exchanges to stop supporting ROUTE tokens, and the delisting arrangements and withdrawal processes may vary across exchanges.Router raised $4.1 million from investors including Coinbase Ventures and Polygon in 2021 and launched the proof-of-stake Layer 1 blockchain Router Chain in July 2024, but it was shut down in September 2025 due to infrastructure costs, validator expansion, and security risks. The team also disclosed two security incidents in 2025: in February, approximately 80% of the value was recovered through negotiations after a vulnerability incident, while losses from a chain-level vulnerability in July could not be recovered.
app_icon
ChainCatcher Building the Web3 world with innovations.