Approximately 64 Bitcoin valued at $4.17 million and 200 Ether worth $380,000, linked to the recent Coldcard exploit, have been transferred to cryptocurrency mixing protocols, according to blockchain security firm CertiK.
Stolen crypto routed through mixers
CertiK reported that the stolen Bitcoin originated from address bc1q0 and was sent to privacy-focused mixer Wasabi on Tuesday. The firm stated that, based on blockchain data, the Bitcoin was moved in a single transaction. The following day, certiK detected a transfer of 200 Ether to Tornado Cash, another well-known mixing protocol.
A spokesperson for CertiK suggested that the addresses involved may belong to smaller actors or copycats imitating the original exploit. Cryptocurrency mixing protocols like Tornado Cash are designed to obscure transaction history, blending digital assets from multiple users so that the origin of funds becomes extremely difficult to trace. This process significantly lowers the chances of successfully recovering stolen assets.
The Coldcard exploit has now become one of the largest crypto security incidents of 2026, ranking as the third-largest hack by value.
Scale and impact of Coldcard exploit
The Coldcard attack totaled at least $100 million stolen in Bitcoin, targeting some 7,300 victim wallets over three distinct attack waves, according to digital asset company Galaxy Digital. Galaxy also pointed to a suspected fourth attack wave, potentially pushing losses to $130 million in Bitcoin.
Most of the stolen digital assets remain within several addresses still under the control of attackers, as recently confirmed by TRM Labs’ onchain analysis. The blockchain intelligence company highlighted that the majority of funds have experienced limited attempts at obfuscation, with only a small portion moved to mixing services so far.
| Attack Wave | Estimated Losses | Victim Wallets | Mixing Activity |
|---|---|---|---|
| Waves 1-3 (Confirmed) | $100 million BTC | 7,300 | Limited |
| Suspected 4th Wave | Additional $30 million BTC | Not disclosed | Ongoing |
TRM Labs observed that each attack wave featured distinct transaction characteristics, indicating the probable involvement of multiple perpetrators. This assessment aligns with Galaxy Digital’s findings, which identified at least 15 separate attackers exploiting the same Coldcard vulnerability.
Coldcard, produced by Coinkite, is a hardware wallet used for securing Bitcoin and other cryptocurrencies. The wallet’s reputation for security was challenged by this incident, which exploited a flaw in its firmware.
Mini dictionary: Tornado Cash, a decentralized privacy tool for the Ethereum blockchain, allows users to deposit and withdraw ETH in a manner that breaks any onchain link between the sender and receiver, thereby increasing transactional privacy.
Technical details and response
TRM Labs attributed the root cause of the attack to a firmware bug present since March 2021, which weakened the seed randomness in certain Coldcard wallets. The bug reduced the cryptographic key strength from 128 bits to 40 bits, making it feasible for attackers to extract private keys without needing physical device access.
Galaxy Digital noted that “differences in transaction construction” across the attack waves suggest several attackers gained knowledge of the vulnerability over time.
Haseeb Qureshi, managing partner at Dragonfly, remarked that only minimal protection—including upgrades costing about $2 per device—could have prevented the exploit. He cited reports indicating that some artificial intelligence models successfully identified the flaw within 20 minutes.
Qureshi commented that “$2 of AI hardening” might have mitigated the Coldcard incident, highlighting the potential benefits of AI-driven security audits.





USDT
AAPL
