EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

CertiK: Coldcard vulnerability caused $4.17 million in Bitcoin to flow into Wasabi mixer

2026-08-07 00:33:02
Bookmark

CertiK: About US$4.17 million in bitcoins from the Coldcard vulnerability have been transferred to the Wasabi mixer

According to blockchain security company CertiK, about US$4.17 million in bitcoins (about 64 coins) and 200 Ethereum pieces worth US$380,000 have been transferred to the cryptocurrency mixing protocol recently related to the Coldcard vulnerability.

Stolen cryptocurrency is transferred via currency mixer

CertiK said that the stolen bitcoins originated from the address bc1q0 and were sent to the privacy mixer Wasabi on Tuesday. The company said that based on blockchain data, the bitcoin was transferred through a single transaction. The next day, CertiK detected that 200 Ethereum pieces had been transferred to Tornado Cash, another well-known mixed-currency protocol.

A CertiK spokesperson believes that the relevant addresses involved may belong to small participants or followers who imitate the original vulnerability. Cryptocurrency mixing protocols such as Tornado Cash aim to confuse transaction history and mix the digital assets of multiple users, making the source of funds extremely difficult to trace. This process significantly reduces the likelihood of successful recovery of stolen assets.

This Coldcard vulnerability incident has become one of the largest cryptocurrency security incidents in 2026, ranking the third largest hacking attack by value.

The scale and impact of the Coldcard vulnerability

According to digital asset company Galaxy Digital, the Coldcard attack stole a total of at least US$100 million in bitcoin, involving approximately 7300 victim wallets, and was carried out in three obvious attacks. Galaxy also pointed out that a suspected fourth wave of attacks could increase losses to US$130 million in Bitcoin.

According to TRM Labs 'on-chain analysis, most of the stolen digital assets remain at multiple addresses controlled by attackers. The blockchain intelligence company emphasized that the vast majority of funds have only undergone limited obfuscation attempts, and only a small amount has been transferred to mixed-currency services.

Attack waves Estimated losses Number of wallets victims Mixed currency activity Waves 1-3 (confirmed) US$100 million BTC7, 300 Limited Suspected Wave 4 Additional US$30 million in BTC Undisclosed Ongoing

TRM Labs observed that each wave of attacks presents unique transaction characteristics, indicating that multiple perpetrators may be involved. This assessment is consistent with Galaxy Digital's findings, which identified at least 15 independent attackers exploiting the same Coldcard vulnerability.

Coldcard, produced by Coinkite, is a hardware wallet used to protect Bitcoin and other cryptocurrencies. The wallet's security reputation was challenged by this incident, which originated from a vulnerability in its firmware.

Small Dictionary: Tornado Cash is a decentralized privacy tool on the Ethereum blockchain that allows users to deposit and withdraw ETH in a way that breaks any on-chain association between sender and recipient, thereby enhancing transaction privacy.

Technical details and countermeasures

TRM Labs attributed the root cause of the attack to a vulnerability in firmware since March 2021 that weakened the seed randomness of certain Coldcard wallets. The vulnerability reduces encryption key strength from 128 bits to 40 bits, allowing an attacker to extract private keys without physically touching the device.

Galaxy Digital noted that "differences in transaction structure" in each attack wave indicate that multiple attackers have gradually acquired knowledge of vulnerabilities over time. [TAG

Dragonfly managing partner Haseeb Qureshi commented that minimal safeguards, including a cost upgrade of about $2 per device, were required to prevent the exploit. He cited reports that certain artificial intelligence models successfully identified the vulnerability within 20 minutes.

Qureshi said a "$2 artificial intelligence hardening" may have alleviated the Coldcard incident, highlighting the potential value of AI-driven security audits.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP