GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Marketing/Whale

News linked to both this project and an event.

In 4 Days, a Whale Spent 85.42 Million USDC to Cross-Chain Buy 1,075.6 BTC

Odaily reports, according to on-chain analyst Yu Jin's monitoring, a whale completed a cross-chain BTC purchase 2 hours ago. Over the past 4 days, this whale spent a total of 85.42 million USDC to buy 1,075.6 BTC, with an average cost of $79,412, including approximately $170,000 in swap fees paid to THORChain.

Spent 60.37 million USDC in two days, a whale bought 767.8 BTC through THORChain

According to on-chain analyst Yu Jin's monitoring, a whale continued to buy 544.5 BTC via cross-chain today, worth $42.43 million. Over the past two days, this whale has swapped 60.37 million USDC for 767.8 BTC through THORChain, at an average price of approximately $78,628.

A whale that once liquidated 50,000 ETH has returned after 8 months to buy 179.8 BTC

Odaily News: According to on-chain analyst Yu Jin's monitoring, a whale that cleared 50,600 ETH at an average price of $2,921 late last year, netting a profit of $19.02 million, has resumed buying Bitcoin after an 8-month hiatus. Over the past day, the whale swapped 14.2 million USDC for 179.8 BTC via THORChain at a price of $78,955 per BTC, and is still continuing to buy, with $74.32 million USDC still in hand.

Coldcard thief prioritizes emptying third wave of vaults, has moved 97.09 BTC worth approximately $7.7 million

according to Bitcoin News monitoring, the Coldcard thief is prioritizing emptying the largest portion of the third wave of vaults. Galaxy Research stated that these wallets have transferred out 97.09 BTC, worth approximately $7.7 million, accounting for about 45% of the assets in this batch. The attacker created 293 2/2 vaults themselves and previously moved some tokens via THORChain on September 2, followed by multiple rounds of CoinJoin over the weekend. The vulnerability stems from a 2021 firmware flaw that reduced seed entropy to a minimum of 40 bits. Of the tokens stolen in this exploit, approximately 82% remain unmoved.

Coldcard Wave 3 Attacker Has Transferred Approximately 45% of Stolen Bitcoin

According to Galaxy Research, in the Coldcard wallet attack incident, the Wave 3 attacker has transferred approximately 45% of the stolen Bitcoin, with the related funds routed to Ethereum via THORChain or entering CoinJoin transactions to increase tracking difficulty. Galaxy stated that the attacker previously created 293 2-of-2 multisig vaults to hold victim funds, draining them from largest to smallest amount, and the funds in the 11 largest vaults have now been fully transferred out.

Approximately 45% of stolen assets have entered coin mixing or cross-chain paths, Coldcard attacker continues to move funds

Odaily News: The attacker behind the Coldcard "Wave 3" exploit continues to move stolen funds. In this phase, the attacker created 293 separate 2-of-2 multisig vaults for each victim's assets. On September 2, the first batch of funds was bridged to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attacker is processing the largest holdings in descending order by stolen amount, having already transferred vaults ranked 1 through 11 in sequence. The next 10 vaults yet to be transferred collectively hold 30.81 BTC, while vaults ranked 61 through 293 collectively hold 33.77 BTC.To date, the attacker has moved approximately 45% of the assets stolen in this exploit, with funds either flowing to Ethereum or entering CoinJoin mixing transactions. This latest transfer activity has also revealed a previously unknown vault: 58 addresses jointly spent funds via a 2-of-2 multisig setup in the same format as Wave 3, with the Wave 3 attacker subsequently routing them to a jump address that funds CoinJoin transactions.This vault is currently marked with "cause = open," but it is highly likely to belong to Coldcard victims as well, which could bring the total number of vaults involved in Wave 3 to 294 and push the previously disclosed total stolen in the Coldcard exploit to approximately 1,806 BTC. At present, roughly 82% of the stolen BTC remains in addresses initially controlled by the attacker, while approximately 18% has been moved, with fund flows suggesting it may be undergoing laundering.

CertiK:与 Coldcard Wallet 攻击相关资金经 THORChain 跨链后转入 Tornado Cash

CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。

hinkal will fully compensate user funds, confirming approximately 797,000 USDC was extracted by an attacker and swapped for 454 ETH

decentralized privacy protocol hinkal has released an update on a security incident, confirming that an attacker extracted approximately 797,000 USDC from its Ethereum contract through a series of transactions and exchanged it for about 454 ETH. Of this, roughly 410 ETH was subsequently transferred to Tornado Cash, while the remaining approximately 44.67 ETH was bridged to the Bitcoin network via THORChain. hinkal is currently collaborating with an external security team to trace the flow of funds.hinkal stated that the impact of this security incident is limited to the relevant fund pools on the Ethereum chain, and contracts on other chains remain unaffected. However, all contracts have been temporarily suspended for fixes and security verification. All affected users will be fully compensated at a 1:1 ratio, with specific compensation procedures and timelines to be announced in a subsequent update.

Specter:THORChain shutdown over a month raises questions, with almost no transactions on the entire chain

on-chain security researcher Specter posted on X, stating that THORChain has not resumed normal operations for over a month after suspending all transactions due to a security vulnerability incident. The protocol previously did not choose to suspend transactions during other security incidents or suspicious fund flows; it even continued operating simple ETH-BTC paths. However, after becoming the affected party this time, it completely halted cross-chain transactions, sparking community discussion about the consistency of its risk management. Currently, THORChain on-chain trading remains completely stagnant, with almost no transactions on the entire chain. The recovery timeline remains unclear, and Specter reminds community users to "stay alert."

Chainalysis Tracks THORChain Attack Source: Proficient Money Laundering Skills, Cross-Chain Fund Transfer Weeks Before Attack

Odaily Chainalysis posted on X platform, stating that prior to the THORChain theft, wallets suspected to be linked to the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several consecutive weeks. As early as late April, the attacker-associated wallets deposited funds into Hyperliquid positions via Hyperliquid and the Monero privacy bridge. These funds were subsequently converted to USDC and transferred to Arbitrum, then bridged to Ethereum. Some of the ETH was then moved to THORChain to stake as RUNE for a newly joined node, which is believed to be the source of the attack.Subsequently, the attacker bridged a portion of the RUNE back to Ethereum and split it into four chains. One chain went directly to the attacker, passing through intermediate wallets before transferring 8 ETH to the wallet that would ultimately receive the stolen funds, just 43 minutes before the attack. The funds from the other three chains flowed in reverse. Between May 14 and 15, these wallets bridged the ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero via the same privacy bridge, with the final transaction occurring less than 5 hours before the attack commenced. As of Friday afternoon, the stolen funds remain untouched, but the attacker has demonstrated sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.

THORChain: Asgard Vault Breach Results in Approximately $10.7 Million Loss; User Cross-Chain Transactions Unaffected for Now

According to Odaily, THORChain has issued an emergency announcement stating that after discovering a suspected breach of an Asgard vault, the network has suspended trading operations to respond to the security incident. Preliminary information indicates that user funds remain unaffected, with losses primarily concentrated on the protocol's own capital.The official statement noted that the system automatically detected anomalous behavior and halted signing operations, thereby alerting the community and preventing further asset outflow. The investigation is currently ongoing to determine the root cause of the vulnerability and the full scope of the impact.Known information indicates that this incident involves one of the six Asgard vaults, with estimated losses of approximately $10.7 million. Meanwhile, staked RUNE on the affected nodes has been slashed due to a penalty mechanism triggered by unauthorized outgoing transactions. The network has paused churn operations and delayed the launch of new chains and related features until system stability is restored.THORChain stated that no user cross-chain transactions have been affected so far and has requested node operators to thoroughly inspect their infrastructure, secure key management, and anomalous behavior, and to submit relevant logs to assist the investigation.

PeckShield: THORChain Suffers Attack, Losing Approximately $10 Million in Cryptocurrency Assets

According to on-chain analyst PeckShield (@PeckShieldAlert), THORChain has been hacked, resulting in losses of approximately $10 million in crypto assets, including 36.75 BTC (around $3 million) and roughly $7 million in assets from BNB Chain, Ethereum, and Base.

TrustedVolumes: Attacker Has Laundered Approximately $278,000 in Stolen Funds

According to on-chain analyst PeckShield (@PeckShieldAlert), the TrustedVolumes attacker has laundered approximately $278,000 of stolen funds to date, including depositing 10.2 ETH (approx. $23,600) into Tornado Cash and swapping 110 ETH (approx. $250,000) for BTC via THORChain. Additionally, the attacker attempted to deposit 0.5 ETH into Railgun but subsequently withdrew it. TrustedVolumes was attacked on May 7, resulting in losses of approximately $6.7 million.

A whale swapped 40 BTC for 1,384.6 ETH and transferred the funds via Tornado Cash.

According to on-chain analyst Onchain Lens (@OnchainLens), a whale address swapped 40 BTC (approximately $3.23 million) for 1,384.6 ETH via THORChain, then transferred the funds into Tornado Cash for coin mixing.

Balancer attacker-linked address transferred 5,609 ETH worth $13 million to THORChain over the past 9 hours

according to on-chain analyst Ai Yi's monitoring, an address linked to the Balancer attacker has transferred 5,609 ETH, worth $13 million, to THORChain over the past 9 hours. In November 2025, Balancer was hacked for over $116 million, a incident with the same suspected culprit as the Aave attack, both pointing to the North Korean hacker group Lazarus Group. Both entities have recently been frequently using Tornado Cash for money laundering.

The Balancer hacker has currently converted 14,300 ETH into 419.3 BTC.

According to on-chain analyst Yujin (@EmberCN), the hacker who stole approximately $98 million worth of assets from Balancer last November has been continuously swapping ETH for BTC via THORChain. To date, the hacker has swapped a total of 14,300 ETH for 419.3 BTC (approximately $32.51 million). The hacker currently holds 7,700 ETH on the Ethereum chain and 419.3 BTC on the Bitcoin chain, with a combined value of approximately $50.4 million. Since the price of ETH has fallen significantly from around $3,600 at the time of the theft, the value of the hacker’s holdings has shrunk by nearly half—from the original $98 million.

Balancer hacker has swapped 7,000 ETH for 204.7 BTC, worth approximately $15.88 million

According to on-chain analyst Yujin (@EmberCN), the hacker who stole approximately $98 million in assets from Balancer last November is today exchanging ETH for BTC via THORChain. So far, 7,000 ETH have been swapped for 204.7 BTC—valued at roughly $15.88 million—and the process continues. Additionally, it has been disclosed that this address currently holds 15,000 ETH on Ethereum, valued at approximately $34.65 million, and 204.7 BTC on Bitcoin.

KelpDAO hacker converted nearly all 75,700 ETH into BTC within 36 hours

According to on-chain analyst Yujin (@EmberCN), the KelpDAO hacker, over a period of approximately one and a half days, has converted nearly all 75,700 ETH (valued at roughly $175 million) on Ethereum into BTC—primarily via the cross-chain protocol THORChain. This money-laundering activity generated approximately $800 million in trading volume and $910,000 in platform fees for THORChain.

KelpDAO Hacker Has Cross-Chained Most ETH to BTC via THORChain

According to on-chain analyst Yu Jin, the KelpDAO hacker began laundering and transferring ETH yesterday afternoon, and by now should have laundered 34,500 ETH (worth $80 million).Most of this ETH was cross-chain swapped into BTC via THORChain, which consequently earned a significant amount in "toll fees":1. THORChain's trading volume surged to $360 million over the past 24 hours, compared to an average daily volume of only $20 million previously.2. THORChain's platform fee revenue reached $420,000 over the past 24 hours, whereas its daily fee income was only $5,000 before.

KelpDAO’s stolen funds have entered the laundering phase: part of the funds has been bridged across chains to the Bitcoin network via THORChain, and over 400 addresses have already been utilized.

According to on-chain analyst Specter (@SpecterAnalyst), the North Korean hacking group TraderTraitor began laundering stolen funds from KelpDAO at approximately 3 a.m. Beijing time today—just three hours after the Arbitrum Council froze 30.7 ETH (approximately $71 million). The attackers split the remaining funds across three wallets, holding roughly 25,000 ETH (~$57.6 million), 25,700 ETH (~$59.2 million), and 25,000 ETH (~$57.9 million), respectively. The third wallet immediately initiated laundering operations and now holds only about 3,800 ETH (~$8 million). The majority of the funds were bridged to the Bitcoin network via THORChain, with approximately 99% flowing through this protocol. As a result, THORChain’s daily trading volume surged to $211 million—more than ten times its 30-day average—and generated roughly $189,000 in fees. During this laundering process, the illicit proceeds were also commingled with funds stolen in the BTC Turk (2025) and Bybit (2025) hacks. To date, approximately 442 BTC (~$33 million) linked to these incidents have been traced on the Bitcoin network, and over 400 addresses have been utilized throughout the entire laundering operation.