Coldcard Wave 3 Funds Move Through THORChain Into Ethereum
Bitcoin linked to this year's Coldcard hardware-wallet theft is moving for the first time in weeks. On September 2, 20.497 BTC left an address that blockchain data provider Bitquery classifies as "reported," attacker-controlled, and tied to the third wave of the theft, passing through two fresh intermediate addresses that were both later emptied.
Bitquery's live tracker recorded 34 THORChain swaps on September 2–3 routing about 20.45 BTC of traced value into Ethereum — part of a broader 20.69 BTC total that includes two smaller swaps on August 2. Most of the routed value, 20.15 BTC across 26 swaps, landed at a principal Ethereum address that held a rounded 649.5 ETH; by early evening on September 3, roughly 5 ETH had left it, per Blockscout data.
The controller remains unidentified, and links between the wider theft waves remain unresolved. Most of the identified hoard is still parked: Bitquery counted 1,402.59 BTC sitting in identified, fully traceable addresses, including 1,396.33 BTC that has never moved.
Blockaid Details $1.1M Drain via Outdated Rain Card Contract
Blockchain security firm Blockaid disclosed this week that an August 28 exploit of an outdated Rain Solana card contract drained approximately $1.1 million from multiple stablecoin card programs — a reminder that shared card infrastructure concentrates risk across many brands at once.
Two affected crypto neobanks disclosed their own tallies: Avici reported $500,859 drained from 1,685 users, and Tria identified $431,945 affecting 636 customers — a combined $932,800-plus, with other Rain-supported programs bringing the estimated total to roughly $1.1 million. Proceeds later entered Tornado Cash on Ethereum, Blockaid said.
Blockaid identified four deployments carrying the same opcode hash as the vulnerable contract; the attacker drained at least two, while the other two held the same flaw but showed no confirmed losses. The exploit targeted collateral contracts holding users' card funding balances — not self-custodial wallets — and a reused signature bypassed the outdated contract's withdrawal controls. Rain said every program still running the affected version was upgraded after the August attack, though it has not published a complete technical report naming every affected deployment.
DOJ and CrowdStrike Dismantle Sality, an Eight-Year Crypto-Stealing Botnet
The DOJ, working with CrowdStrike and partners across four countries, has dismantled the Sality botnet, isolating more than 15,000 infected machines in a takedown that ended a malware operation blamed for eight years of stealing Bitcoin and Ethereum from infected systems. The operation marks one of the larger infrastructure seizures against a consumer-grade crypto stealer, though authorities have not yet published a consolidated loss figure or arrest tally.
FBI Seizes $560K in Crypto Tied to Alleged Hamas Fundraising
The FBI seized approximately $560,000 in cryptocurrency and took over the domains and servers of fundraising sites allegedly used by Hamas' military wing to collect donations and recruit supporters. The seizure, disclosed in court filings this week, relies on allegations that remain subject to proceedings — but adds to a growing tally of crypto seized from designated organizations by U.S. authorities this year.
TrustGrade tracks the security posture of DeFi protocols, exchanges, and chain infrastructure. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.