Ukrainian authorities have disrupted a sophisticated cryptocurrency theft operation based in Kyiv that allegedly moved up to $1 million monthly. According to Decrypt, the criminal ring utilized fake investment advertisements distributed through Telegram channels to lure victims throughout the European Union. These advertisements directed users to a malicious lookalike exchange platform that emptied victims' wallets upon interaction.

The operation specifically targeted EU residents through social media outreach, establishing false credibility via investment promises before executing thefts. Crypto drainers—malicious scripts that deceive users into authorizing transactions that transfer assets to attacker-controlled addresses—have emerged as a prevalent vector for cryptocurrency theft. The reported monthly volume of $1 million indicates a substantial scale of criminal activity prior to law enforcement intervention.

In a separate security development, blockchain investigators have tracked the movement of funds stolen during the ongoing Coldcard hardware wallet exploits. According to Cointelegraph, the perpetrator behind the third wave of attacks has laundered approximately 10 percent of stolen assets through THORChain, a decentralized cross-chain liquidity protocol. The exploiter converted the stolen Bitcoin into Ethereum using the protocol, with researchers tracing the resulting funds to a new Ethereum address.

THORChain facilitates native asset exchanges across different blockchains without requiring centralized intermediaries or wrapped tokens, characteristics that can attract individuals seeking to obscure the origin of illicit funds. The conversion from Bitcoin to Ethereum represents a technique designed to complicate blockchain tracing efforts by shifting value across distinct ledger systems. The remaining portion of the stolen Coldcard funds has not been moved through this specific channel, suggesting the attacker may be utilizing alternative methods for the balance.

These concurrent incidents illustrate distinct challenges within cryptocurrency security, encompassing both social engineering campaigns targeting retail users and the subsequent laundering of assets through decentralized financial infrastructure. While Ukrainian law enforcement successfully apprehended the operators of the EU-targeting drainer scheme, the Coldcard case demonstrates the complexity investigators face when perpetrators leverage permissionless protocols to transfer stolen assets across blockchain networks.