Coldcard Loot Hits the Blender: 64 BTC and 200 ETH Whisked Into Mixers �
Roughly 64 BTC ($4.17 million) and 200 ETH ($380,000) connected to the Coldcard exploit were routed through cryptocurrency mixing protocols, according to blockchain security firm CertiK. The Bitcoin was sent from address bc1q0 to the Wasabi mixer on Tuesday, and the Ether followed to Tornado Cash on Wednesday, per CertiK's X post. "We think it might be a smaller exploiter. There's likely a few copycats after the initial exploit," a CertiK spokesperson told Cointelegraph.
Mixing protocols such as Tornado Cash pool funds from multiple users and scramble them, severing the publicly traceable onchain link between sender and recipient and complicating recovery efforts. The laundering pattern echoes an April incident in which the hacker behind a $293 million Kelp DAO exploit moved approximately 75,700 Ether, then worth $175 million, largely through THORChain, generating about $910,000 in fee revenue for that protocol, with additional use of the Umbra privacy protocol.
The Coldcard event has become the third-largest cryptocurrency hack of 2026, draining at least $100 million in BTC across three confirmed attack waves from 7,300 victim wallets, according to Galaxy Digital. The firm also identified a suspected fourth wave that could push total losses to roughly $130 million in BTC. Source: CertiK.
Onchain tracing from TRM Labs showed that most stolen funds remain clustered in a small set of attacker-controlled addresses with limited mixing activity, according to a Thursday report. The firm noted that "differences in transaction construction" across attack waves suggest multiple perpetrators, a finding consistent with Galaxy's prior identification of at least 15 distinct attackers exploiting the same vulnerability.
TRM Labs traced the root cause to a firmware bug from March 2021 that weakened seed randomness on certain Coldcard devices, reducing key strength from 128 bits to 40 bits and rendering the wallets "brute-forceable without physical access." Dragonfly managing partner Haseeb Qureshi added that roughly "$2 of AI hardening" could have prevented the incident, pointing to social media reports that some AI models independently rediscovered the flaw in under 20 minutes.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.