How much stolen cryptocurrency flows into the mixer? [TAG
Cryptocurrencies linked to the recent Coldcard breach have begun to move through privacy protocols, making it harder to track and recover assets stolen from thousands of wallets. According to blockchain data reviewed by security researchers, on Tuesday, about 64 bitcoins (worth about $4.17 million) were transferred from an address starting with bc1q0 to the Wasabi coin-mixing protocol. Separately, on Wednesday, an attacker converted stolen bitcoins into about 200 Ethereum via THORChain and then sent the funds worth about $380,000 to Tornado Cash. These transfers account for only a small portion of the total loss related to the vulnerability. Security analysts believe the transfers could have been made by a smaller attacker or one of multiple imitators following the initial attack. The mixed-currency protocol mixes the assets of multiple users and obscures public transaction records between sending and receiving addresses. They don't make assets disappear, but make attribution more difficult and reduce the likelihood that exchanges or investigators will identify and freeze stolen funds. The separation between the 64 bitcoin hybrid cluster and the larger cluster of seven addresses holding approximately 1159 bitcoins supports the idea that more than one attacker may have exploited the vulnerability. Investigators also found differences in the way transactions were constructed in different attack waves.
Why did researchers suspect there were multiple attackers?
The Coldcard vulnerability stole at least $100 million in Bitcoin in three confirmed waves of attacks, involving approximately 7300 victim wallets. A suspected fourth wave of attacks could bring total losses to approximately $130 million, which would make this incident the third largest cryptocurrency hack recorded so far in 2026. Blockchain tracking shows that most stolen assets are still concentrated in addresses controlled by a small number of attackers. Only a relatively small portion is sent through the money mixer, which suggests that many suspected attackers have not yet attempted to cover up or cash out their positions. Researchers said differences in how transactions were constructed in different attack waves suggested that not all of the funds were stolen by a single operator using a single automated process. Early analysis identified at least 15 attackers who may have exploited the same vulnerability. This model makes the recovery process more difficult. An attacker may follow a consistent money-laundering route that investigators can trace on multiple blockchains. Multiple imitators may use different wallets, exchanges, bridging and privacy tools, forcing investigators to isolate dozens of transaction leads.
Investor Points
Funds transferred through Wasabi and Tornado Cash did not account for the majority of Coldcard's losses. The greater risk is that before exchanges, analytics companies and law enforcement can determine a reliable recovery route, other attackers will start moving concentrated bitcoins.
What caused the Coldcard wallet vulnerability?
The vulnerability is related to a firmware bug introduced in March 2021 that weakens the randomness used by certain Coldcard wallets to generate seed phrases. The flaw reportedly reduced the effective strength of the private key from 128 bits to 40 bits. At this level, it is possible for an attacker to recover affected keys through brute-force computing without having to physically access the wallet. This makes the vulnerability particularly damaging because users may believe that their funds are protected as long as their hardware devices and recovery phrases are stored securely. The incident shows that the security of hardware wallets does not just depend on physical devices. Weaknesses in random number generation, firmware updates, or seed creation can undermine protection, even if users follow standard hosting practices. Haseeb Qureshi, managing partner at Dragonfly, believes basic AI-assisted safety testing could have helped identify the flaw. He cited reports that some AI models rediscovered the vulnerability in less than 20 minutes and said the missing security measures were roughly equivalent to "$2 in AI hardening." This statement does not mean that automated testing can replace professional safety audits. It does suggest that wallet developers may increasingly use AI tools, combining traditional code review, fuzzification testing and cryptographic verification to spot weaknesses before attackers do.
Can the remaining funds be recovered?
Most stolen assets are concentrated in a few visible addresses, providing investigators with a window to track future movements. Exchanges and custodians can mark identified addresses, while blockchain analytics companies can track transactions as funds move through bridges or centralized trading platforms. When attackers use currency mixers, decentralized exchanges, or cross-chain protocols to divide funds into smaller amounts, the likelihood of recovery is reduced. In April, the people behind the $293 million Kelp DAO hack transferred approximately 75,700 Ethereum pieces through multiple services, including THORChain and Umbra privacy protocols. This case demonstrates how stolen funds can generate revenue from agreements used to transfer them. ThorChain reportedly earned approximately $910,000 in fees from transactions related to the attacker. For Coldcard users, the top priority is to determine whether their wallets were created using the affected firmware and move any remaining assets to new addresses randomly generated using security seeds. The next big test for investigators will be whether the attackers holding most of the stolen bitcoins keep their funds dormant or start following smaller transfers and entering privacy agreements.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH