Blockchain security company CertiK monitors early money laundering after Coldcard hardware wallet attacks
Blockchain security company CertiK said it has observed early money laundering related to ongoing Coldcard hardware wallet exploits: About 64 bitcoins (worth approximately US$4.17 million) and 200 ether (approximately US$380,000) were sent to the cryptocurrency mix-in service after the theft began. According to CertiK's X platform update and the address-level data it provides, on-chain transfers include: on Tuesday, 64 bitcoins were transferred from the source address marked by CertiK to the Wasabi mixed currency agreement; on Wednesday, 200 ether were transferred to Tornado Cash.
Key Points
CertiK reported that 64 bitcoins and 200 ether coins associated with Coldcard exploits were routed through Wasabi and Tornado Cash, respectively. Hybrid services pool funds and obscure transaction associations, which reduces the possibility of stolen asset recovery. Analysis by TRM Labs shows that most victim funds are still concentrated in addresses controlled by a small number of attackers, and there are relatively few attempts to mix currencies. Galaxy Digital previously estimated that the Bitcoin losses caused by the Coldcard incident were at least US$100 million, and if subsequent attacks are confirmed, the amount of losses may be even greater.
Coldcard's money laundering signal after theft
According to blockchain security platform CertiK, some of the stolen funds have been processed through privacy tools designed to cut off traceability on the chain. On the bitcoin side, about 64 bitcoins were transferred to Wasabi, a well-known mixed-currency protocol that combines deposited funds and redistributes them, making matching between senders and recipients extremely difficult. Regarding Ethereum, CertiK said that 200 ether coins were transferred to Tornado Cash. Like other money mixers, Tornado Cash operates by integrating deposits and confusing the direct on-chain relationship between the address where the transaction was initiated and the final withdrawal address.
CertiK also pointed out that this behavior may not have been the work of a single attacker. A CertiK spokesperson told Cointelegraph: "We think this could be a smaller attacker. After the initial exploit, there are likely some copycats." This is consistent with broader case reports that describe multiple participants trying to profit from the same underlying vulnerability.
Impact of currency mixers on recovery
When stolen assets are transferred to currency mixers, investigators often lose clear "paper records" that usually help determine the flow of funds. Mixed currency agreements typically aggregate funds from multiple users and then reallocate them in a way that disrupts the open association between deposits and withdrawals. This structural design reduces the likelihood of timely asset recovery, especially if stolen funds are moved quickly and opportunities for intervention by authorities and compliance teams are limited. Even so, blockchain analysis is not useless-large-scale surveillance can still detect certain patterns, track high-level capital flows, and correlate time and source of funds, depending on how thoroughly an attacker uses the mixing steps. [TAG
The broader context also highlights the risks: Earlier this year, in the Kelp DAO hack, attackers laundered most of the estimated 75,700 ether coins (worth about $175 million at the time) through THORChain, using the Umbra privacy protocol in addition. This precedent shows that adversaries can quickly move stolen funds through multiple layers of privacy and liquidity.
Coldcard losses are still increasing, tracking wave by wave
Coldcard exploit has grown into one of the largest cryptocurrency hacking incidents reported in 2026. Galaxy Digital previously said the incident stole at least $100 million worth of bitcoins from approximately 7,300 victim wallets in three confirmed waves of attacks. Galaxy also identified a suspected fourth wave of attacks-if confirmed, Bitcoin losses are expected to rise to about $130 million. This "wave" framework is important to traders, holders and event responders because it implies that attacker activity may not be limited to a single point in time and that additional funds may be transferred even after the initial report.
At the same time, CertiK's observations on the use of currency mixers provide a practical indicator of the speed at which some stolen funds are processed. Although the amounts highlighted by CertiK are not the complete picture of the incident, they suggest that at least some attackers appear to prioritize trace obfuscation early in the theft life cycle.
TRM Labs: Most funding remains concentrated, indicating limited follow-up action
TRM Labs 'on-chain tracking provides further information. According to a report on Thursday, TRM Labs found that most victim funds are still concentrated in relatively few attacker-controlled addresses, and that currency mixing activity is currently limited. TRM Labs also said differences in transaction construction in each attack wave indicate that there are multiple attackers behind the exploit. This is consistent with Galaxy's earlier findings that at least 15 different attackers exploited the Coldcard vulnerability. TRM Labs blamed the root cause on a March 2021 firmware vulnerability that weakened the seed randomness of some Coldcard wallets. The company said the reduced key strength allows affected keys to be brute-force cracked without physical access, which explains why the actual impact of the vulnerability can be quickly replicated once it is known.
On the broader theme of prevention, Dragonfly managing partner Haseeb Qureshi said on social media that relatively small improvements could have reduced the risk. He used "$2 AI enhancements" as a shorthand for strengthening defenses and cited reports that some AI models rediscovered the vulnerabilities that led to the attack in less than 20 minutes.
What to focus on next
As the Coldcard case continues to evolve, the key variables are whether additional funds continue to flow into the mixer and whether the pattern of concentration of funds between the wallet and the attacker cluster changes. Investors and event trackers should pay attention to confirmation of subsequent waves of attacks and to whether money laundering exceeds the earlier cases highlighted by CertiK and the limited mixing observed by TRM Labs.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH