Skip to main content

Coldcard Hackers Send 64 BTC and 200 ETH to Crypto Mixers



Stolen funds tied to the Coldcard hardware wallet exploit are showing early signs of laundering, but blockchain security researchers say most potential copycats have not yet moved large amounts of the victimed crypto. According to CertiK, about 64 Bitcoin (worth roughly $4.17 million) and 200 Ether (worth about $380,000) linked to the attack were routed into well-known mixing services—Wasabi for BTC and Tornado Cash for ETH.



The Coldcard incident has quickly become one of the largest crypto hacks of the year. Galaxy Digital previously put confirmed losses at least at $100 million in Bitcoin across three waves, and it also flagged a possible fourth wave that could raise total losses to around $130 million.



Key takeaways



  • CertiK says roughly 64 BTC linked to the Coldcard exploit were sent to Wasabi, and 200 ETH were moved to Tornado Cash.

  • Mixing services typically pool funds and obscure onchain linkages, reducing the odds of recovery for victims.

  • TRM Labs’ tracing suggests most victim balances remain concentrated in a small set of attacker-controlled addresses with limited mixing activity.

  • Analysis of transaction patterns across attack waves indicates the exploit may involve more than one actor.



Mixing services enter the Coldcard laundering picture


CertiK’s blockchain monitoring connected specific transfer activity to the Coldcard exploit and mapped part of the flow into privacy and obfuscation tooling. In its reporting, CertiK indicated that the Bitcoin transfer—sourced from address bc1q0—was sent to the Wasabi mixing protocol on Tuesday, using CertiK’s address data shared with Cointelegraph.



On the Ethereum side, CertiK stated that 200 ETH were sent to Tornado Cash on Wednesday, pointing to an X post from its account as the basis for the observation.



Crypto mixers like Tornado Cash operate by pooling deposits from multiple users and then releasing funds in a way that breaks straightforward onchain tracking from original sender to final recipient. That feature is precisely what makes tracing more difficult and asset recovery less likely—especially when attackers move quickly and fragment funds across multiple addresses and services.



Why this matters: laundering momentum vs. copycat behavior


CertiK’s spokesperson told Cointelegraph that the activity could be linked to a smaller exploiter, adding that “there’s likely a few copycats after the initial exploit.” The implication is straightforward: if additional parties used the same weakness, their onchain movement could help or hinder investigators depending on whether they follow up with laundering at scale.



That’s where TRM Labs’ findings become important. In a Thursday report titled “The largest hardware wallet exploit of 2026: inside the $116 million Coldcard hack”, TRM Labs said its onchain tracing indicates most victim funds were still pooled in a limited number of attacker-controlled addresses and that mixing attempts appeared restrained.



TRM Labs also highlighted that “differences in transaction construction” between each wave suggest multiple attackers. In other words, even if the underlying vulnerability was shared, the operational playbook may not be identical—an asymmetry that can be useful for investigators trying to separate participant identities, funding sources, and laundering pathways.



Coldcard hack scale and the “waves” pattern


Galaxy Digital previously characterized the Coldcard exploit as the third-largest cryptocurrency hack of 2026 so far, based on confirmed activity. In its assessment, Galaxy put drained losses at at least $100 million in Bitcoin across three verified attack waves involving 7,300 victim wallets. Galaxy also pointed to a suspected fourth wave that could lift total losses to roughly $130 million in BTC, according to earlier coverage from Cointelegraph.



Those wave-based findings matter for how analysts interpret laundering. If attackers are not distributing funds aggressively—or if only one portion of the stolen assets has been moved into mixers—then the time dimension becomes critical: investigators may still be waiting for broader follow-through as additional actors or additional batches of stolen funds begin to move.



Galaxy’s earlier analysis, also cited by Cointelegraph, suggested at least 15 different attackers exploited the vulnerability. This lines up with TRM Labs’ point about differences in transaction construction between waves, reinforcing the idea that what may look like a single incident could actually be a coordinated (or at least parallel) operation with distinct participants.



The technical weakness behind the exploit


TRM Labs’ report attributed part of the vulnerability to a firmware bug from March 2021 that weakened seed randomness on some Coldcard wallets. According to TRM Labs, the bug effectively reduced key strength to 40 bits from 128 bits, making it “brute-forceable without physical access.”



Other commentary around the fix has emphasized the low cost of better security hygiene. Dragonfly managing partner Haseeb Qureshi wrote that approximately “$2 of AI hardening” could have prevented the Coldcard exploit, referencing social media reports that some AI models rediscovered the vulnerability quickly—though those claims are framed as commentary rather than formal technical findings.



For investors and builders, the core takeaway is less about any single price tag and more about how quickly weaknesses can be weaponized once public knowledge spreads. When a vulnerability can be exploited remotely and at scale, incident response needs to account for both immediate attackers and longer-tail copycats.



Going forward, readers should watch whether additional attacker-controlled addresses begin pushing larger portions of stolen balances into mixing services, and whether the “suspected” fourth wave confirmed by Galaxy develops further. As more funds move—or fail to move—onchain, investigators will gain clearer signals about how many actors are involved and how successfully they’re managing to break traceability.



https://www.cryptobreaking.com/coldcard-hackers-send-64-btc/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Coldcard%20Hackers%20Send%2064%20BTC%20and%20200%20ETH%20to%20Crypto%20Mixers%20

Comments

Popular posts from this blog

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...