NewsCryptoColdcard Exploiters Move 64 BTC and 200 ETH to Crypto Mixers Amid Ongoing Investigation

Coldcard Exploiters Move 64 BTC and 200 ETH to Crypto Mixers Amid Ongoing Investigation

Author: Cointelegraph·

Key Takeaways

  • Approximately 64 Bitcoin worth $4.17 million and 200 Ether worth $380,000 linked to the Coldcard exploit have been transferred to cryptocurrency mixing protocols Wasabi and Tornado Cash.
  • The Coldcard exploit is the third-largest cryptocurrency hack of 2026, draining at least $100 million across three confirmed attack waves affecting 7,300 victim wallets.
  • TRM Labs identified at least 15 different attackers who exploited a March 2021 firmware bug that reduced wallet key strength from 128 bits to 40 bits, making wallets brute-forceable without physical access.
  • The majority of stolen funds remain in attacker-controlled addresses with limited mixing, leaving a narrow window for law enforcement to track and potentially freeze remaining assets.
  • Dragonfly managing partner Haseeb Qureshi stated that minimal AI security testing costing roughly two dollars could have prevented the exploit, as some AI models reportedly rediscovered the vulnerability in under 20 minutes.
Coldcard Exploiters Move 64 BTC and 200 ETH to Crypto Mixers Amid Ongoing Investigation

Approximately 64 Bitcoin, valued at $4.17 million, and 200 Ether, valued at $380,000, connected to the recent Coldcard exploit have been transferred to cryptocurrency mixing protocols, according to blockchain security platform CertiK.

The Bitcoin was moved from address bc1q0 to the Wasabi mixing protocol on Tuesday, based on blockchain data shared by CertiK. The 200 Ether (ETH) was sent to Tornado Cash on Wednesday, as reported in CertiK's X post.

"We think it might be a smaller exploiter. There's likely a few copycats after the initial exploit," a CertiK spokesperson told Cointelegraph.

Cryptocurrency mixing protocols such as Tornado Cash pool and scramble digital assets from multiple users, severing the publicly traceable onchain link between senders and recipients. This process significantly complicates efforts to trace stolen funds and reduces the likelihood of asset recovery.

The tactic echoes a similar laundering operation in April, when the hacker responsible for the $293 million Kelp DAO hack laundered roughly 75,700 Ether — then worth $175 million — primarily through THORChain, generating approximately $910,000 in fee revenue for the protocol. That attacker also utilized the Umbra privacy protocol.

The Coldcard exploit currently ranks as the third-largest cryptocurrency hack of 2026. It drained at least $100 million in Bitcoin across three confirmed attack waves affecting 7,300 victim wallets, according to Galaxy Digital. The firm also identified a suspected fourth wave that could raise total losses to approximately $130 million in BTC. Coldcard, manufactured by Toronto-based Coinkite, is widely used among Bitcoin self-custody advocates for its air-gapped design, making the exploit particularly damaging to trust in hardware wallet security.

Most Copycat Attackers Have Not Moved Stolen Funds

Onchain tracing conducted by TRM Labs revealed that the majority of victim funds remain pooled in a small number of attacker-controlled addresses with limited mixing attempts, according to a Thursday report. The relatively low volume of funds moved through mixers so far leaves open a narrow window for blockchain analysts and law enforcement to track and potentially freeze remaining assets before they are laundered.

The blockchain intelligence firm noted that "differences in transaction construction" across each attack wave suggest multiple attackers were responsible for the exploit. This aligns with Galaxy Digital's earlier findings, which identified at least 15 different attackers who exploited the Coldcard vulnerability.

TRM Labs determined that a firmware bug originating from March 2021 weakened seed randomness on certain Coldcard wallets, reducing key strength from 128 bits to 40 bits and making the wallets "brute-forceable without physical access." The vulnerability went undetected for roughly five years, a period during which affected wallets generated keys that were computationally feasible to crack.

Dragonfly managing partner Haseeb Qureshi wrote that roughly "$2 of AI hardening" could have prevented the Coldcard exploit, citing social media reports that some AI models rediscovered the underlying vulnerability in under 20 minutes.