EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard exploit transferred 64 BTC and 200 ETH into a currency mixer

2026-08-07 12:13:36
Bookmark

Blockchain security company CertiK monitors early money laundering after Coldcard hardware wallet attacks

Blockchain security company CertiK said it has observed early money laundering related to ongoing Coldcard hardware wallet exploits: About 64 bitcoins (worth approximately US$4.17 million) and 200 ether (approximately US$380,000) were sent to the cryptocurrency mix-in service after the theft began. According to CertiK's X platform update and the address-level data it provides, on-chain transfers include: on Tuesday, 64 bitcoins were transferred from the source address marked by CertiK to the Wasabi mixed currency agreement; on Wednesday, 200 ether were transferred to Tornado Cash.

Key Points

CertiK reported that 64 bitcoins and 200 ether coins associated with Coldcard exploits were routed through Wasabi and Tornado Cash, respectively. Hybrid services pool funds and obscure transaction associations, which reduces the possibility of stolen asset recovery. Analysis by TRM Labs shows that most victim funds are still concentrated in addresses controlled by a small number of attackers, and there are relatively few attempts to mix currencies. Galaxy Digital previously estimated that the Bitcoin losses caused by the Coldcard incident were at least US$100 million, and if subsequent attacks are confirmed, the amount of losses may be even greater.

Coldcard's money laundering signal after theft

According to blockchain security platform CertiK, some of the stolen funds have been processed through privacy tools designed to cut off traceability on the chain. On the bitcoin side, about 64 bitcoins were transferred to Wasabi, a well-known mixed-currency protocol that combines deposited funds and redistributes them, making matching between senders and recipients extremely difficult. Regarding Ethereum, CertiK said that 200 ether coins were transferred to Tornado Cash. Like other money mixers, Tornado Cash operates by integrating deposits and confusing the direct on-chain relationship between the address where the transaction was initiated and the final withdrawal address.

CertiK also pointed out that this behavior may not have been the work of a single attacker. A CertiK spokesperson told Cointelegraph: "We think this could be a smaller attacker. After the initial exploit, there are likely some copycats." This is consistent with broader case reports that describe multiple participants trying to profit from the same underlying vulnerability.

Impact of currency mixers on recovery

When stolen assets are transferred to currency mixers, investigators often lose clear "paper records" that usually help determine the flow of funds. Mixed currency agreements typically aggregate funds from multiple users and then reallocate them in a way that disrupts the open association between deposits and withdrawals. This structural design reduces the likelihood of timely asset recovery, especially if stolen funds are moved quickly and opportunities for intervention by authorities and compliance teams are limited. Even so, blockchain analysis is not useless-large-scale surveillance can still detect certain patterns, track high-level capital flows, and correlate time and source of funds, depending on how thoroughly an attacker uses the mixing steps. [TAG

The broader context also highlights the risks: Earlier this year, in the Kelp DAO hack, attackers laundered most of the estimated 75,700 ether coins (worth about $175 million at the time) through THORChain, using the Umbra privacy protocol in addition. This precedent shows that adversaries can quickly move stolen funds through multiple layers of privacy and liquidity.

Coldcard losses are still increasing, tracking wave by wave

Coldcard exploit has grown into one of the largest cryptocurrency hacking incidents reported in 2026. Galaxy Digital previously said the incident stole at least $100 million worth of bitcoins from approximately 7,300 victim wallets in three confirmed waves of attacks. Galaxy also identified a suspected fourth wave of attacks-if confirmed, Bitcoin losses are expected to rise to about $130 million. This "wave" framework is important to traders, holders and event responders because it implies that attacker activity may not be limited to a single point in time and that additional funds may be transferred even after the initial report.

At the same time, CertiK's observations on the use of currency mixers provide a practical indicator of the speed at which some stolen funds are processed. Although the amounts highlighted by CertiK are not the complete picture of the incident, they suggest that at least some attackers appear to prioritize trace obfuscation early in the theft life cycle.

TRM Labs: Most funding remains concentrated, indicating limited follow-up action

TRM Labs 'on-chain tracking provides further information. According to a report on Thursday, TRM Labs found that most victim funds are still concentrated in relatively few attacker-controlled addresses, and that currency mixing activity is currently limited. TRM Labs also said differences in transaction construction in each attack wave indicate that there are multiple attackers behind the exploit. This is consistent with Galaxy's earlier findings that at least 15 different attackers exploited the Coldcard vulnerability. TRM Labs blamed the root cause on a March 2021 firmware vulnerability that weakened the seed randomness of some Coldcard wallets. The company said the reduced key strength allows affected keys to be brute-force cracked without physical access, which explains why the actual impact of the vulnerability can be quickly replicated once it is known.

On the broader theme of prevention, Dragonfly managing partner Haseeb Qureshi said on social media that relatively small improvements could have reduced the risk. He used "$2 AI enhancements" as a shorthand for strengthening defenses and cited reports that some AI models rediscovered the vulnerabilities that led to the attack in less than 20 minutes.

What to focus on next

As the Coldcard case continues to evolve, the key variables are whether additional funds continue to flow into the mixer and whether the pattern of concentration of funds between the wallet and the attacker cluster changes. Investors and event trackers should pay attention to confirmation of subsequent waves of attacks and to whether money laundering exceeds the earlier cases highlighted by CertiK and the limited mixing observed by TRM Labs.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP