Bitcoin stolen in a major exploit involving Coldcard wallets has begun moving through mixing services, but the bulk of the cryptocurrency remains in attacker-controlled addresses, according to recent analysis by Galaxy Research and on-chain investigators.
Largest Attacker Retains Most Funds
The largest identified attacker continues to hold approximately 1,159 BTC across seven addresses. These addresses have not moved their funds since they were initially consolidated. Investigations into the incident indicate that the Bitcoin was stolen in just 41 minutes, suggesting a coordinated and efficient theft.
No transactions from these seven addresses have reached crypto exchanges, mixers, or other services that could potentially enable the attacker to cash out. Still, investigators are closely monitoring hundreds of associated wallets that may be tied to the wider Coldcard exploit.
Exchanges, law enforcement agencies, and blockchain analytics firms have reportedly flagged around 600 addresses connected to the larger theft, heightening scrutiny and potentially complicating any attempts by attackers to liquidate the stolen assets.
Although Bitcoin at the protocol level cannot be frozen or seized by flagging addresses, trying to launder such a significant sum without alerting authorities poses a challenge. Transferring funds to regulated exchanges could trigger anti-money-laundering controls and requests for transactional information.
Separate Mixing Activities Detected
Alongside the main stash, security analysts identified another attacker attempting to obscure approximately 64 BTC. The individual reportedly began by mixing roughly 10 BTC, then receiving 54 BTC back as change. Later, these funds were split into smaller amounts of around 7 BTC each to facilitate further mixing activity.
The movement of these coins reportedly involved Wasabi Wallet, a privacy-focused Bitcoin wallet that utilizes CoinJoin transactions. This method is designed to make it more challenging to trace specific Bitcoin inputs to their corresponding outputs.
Mini dictionary: CoinJoin, a privacy technique that combines multiple Bitcoin transactions into a single transaction, making it difficult to determine which input corresponds to which output and increasing the user’s anonymity.
Despite using mixers, analysts noted that blockchain traces—such as timing patterns, transaction sizes, subsequent consolidations, and eventual interactions with exchanges—can still provide investigative leads. The mixing activity appears separate from the main seven-address cluster, reinforcing suspicions that multiple attackers exploited the same vulnerability.
Vulnerability and Total Losses
Coldcard, developed by CoinKite, is a Bitcoin hardware wallet known for its advanced security features and focus on privacy. The vulnerability in question is linked to seed phrases generated by impacted devices, which used flawed random-number generation, weakening overall wallet security.
Galaxy Research previously estimated confirmed losses from the Coldcard vulnerability at around 1,596 BTC, with potential additional attacks bringing the estimated total up to 2,055 BTC. Other research teams have suggested total losses exceeding 1,800 BTC.
| Source | Estimated BTC Stolen |
|---|---|
| Galaxy Research (confirmed) | 1,596 BTC |
| Galaxy Research (potential) | 2,055 BTC |
| Other researchers | more than 1,800 BTC |
Updating the Coldcard firmware prevents the creation of new vulnerable wallets but does not restore security to any wallet already generated with the compromised seed mechanism. Affected users are required to establish a brand-new wallet and transfer their funds to new, secured addresses.
Mixers may complicate blockchain analysis, but they do not guarantee anonymity, as investigators can still gather significant clues from transaction patterns.





USDT
AAPL
