Coldcard Exploiters Move 64 BTC, 200 ETH Into Crypto Mixers

Blockonomics
Blockonomics


Blockchain security firm CertiK says it has observed early laundering behavior tied to the ongoing Coldcard hardware wallet exploit: about 64 Bitcoin (valued at roughly $4.17 million) and 200 Ether (about $380,000) were reportedly sent to crypto mixing services after the theft began.

CertiK-linked onchain movements include a transfer of the 64 BTC from a source address labeled by CertiK to the Wasabi mixing protocol on Tuesday, while the 200 ETH was reportedly moved to Tornado Cash on Wednesday, according to CertiK’s X updates and address-level data shared by the firm.

Key takeaways

  • CertiK reports 64 BTC and 200 ETH connected to the Coldcard exploit were routed through Wasabi and Tornado Cash, respectively.
  • Mixing services pool funds and obscure transaction linkages, which can reduce recovery odds for stolen assets.
  • TRM Labs’ analysis suggests most victim funds remain concentrated in a limited set of attacker-controlled addresses with relatively few mixing attempts so far.
  • Galaxy Digital previously estimated losses from the Coldcard incident are at least $100 million in BTC, with a possible larger figure if additional attack waves are confirmed.

Laundering signals after the Coldcard theft

According to blockchain security platform CertiK, a portion of the stolen funds has already been processed through privacy-focused tooling designed to break onchain traceability. The Bitcoin leg involved approximately 64 BTC moving to Wasabi, a well-known mixing protocol that pools deposits and then redistributes funds in ways that make sender-recipient matching significantly harder.

On the Ethereum side, CertiK said 200 ETH was transferred to Tornado Cash. As with other mixers, Tornado Cash works by combining deposits and obfuscating the direct onchain relationship between the address that initiated a transaction and the eventual withdrawal target.

Ledger

CertiK also suggested the behavior may not reflect only a single actor. “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” a CertiK spokesperson told Cointelegraph. That aligns with broader incident reporting that has described multiple parties attempting to monetize the same underlying vulnerability.

Why mixers matter for recovery efforts

When stolen assets are transferred into mixers, investigators often lose the clean “paper trail” that typically helps identify where funds end up. Mixing protocols generally work by aggregating multiple users’ funds and then redistributing in a way that disrupts public linkage between deposits and withdrawals.

That structural design can lower the probability of timely asset recovery, especially when stolen funds are quickly moved and there is limited opportunity for authorities and compliance teams to intervene. Even so, blockchain analysis is not rendered useless—large-scale monitoring can still sometimes detect patterns, track high-level flows, and correlate timing and fund sources, depending on how thoroughly attackers operationalize the mixing step.

The wider context also underscores the stakes: earlier this year, the Kelp DAO hack saw an attacker launder nearly all of roughly 75,700 ETH—then valued around $175 million—primarily through THORChain, with additional use of the Umbra privacy protocol. That precedent illustrates how quickly adversaries can shift stolen funds across multiple privacy and liquidity layers.

Coldcard losses still mounting, with wave-by-wave tracking

The Coldcard exploit has already grown into one of the largest crypto hacks reported for 2026. Galaxy Digital previously stated the incident drained at least $100 million worth of Bitcoin across three confirmed attack waves sourced from around 7,300 victim wallets.

Galaxy also identified a suspected fourth wave, which—if confirmed—could lift projected losses to approximately $130 million in BTC. This “wave” framing matters to traders, holders, and incident responders because it implies the attacker activity may not be confined to a single moment, and that additional funds could be moving even after initial reports.

In parallel, CertiK’s observations of mixer usage offer a practical marker of how quickly some stolen funds are being processed. While the amounts highlighted by CertiK are not the full scale of the event, they signal that at least some attackers appear to be prioritizing trace obfuscation early in the lifecycle of the theft.

TRM Labs: most funds remain concentrated, suggesting limited follow-through

Further insight comes from onchain tracing by TRM Labs, which—according to a Thursday report—found that the majority of victim funds were still pooled in a relatively small number of attacker-controlled addresses, with limited mixing activity so far.

TRM Labs also said that differences in transaction construction across each attack wave suggest multiple attackers behind the exploit. This is consistent with Galaxy’s earlier findings that at least 15 different attackers may have exploited the Coldcard vulnerability.

TRM Labs attributed the underlying issue to a firmware bug from March 2021 that weakened seed randomness on some Coldcard wallets. The company said that the reduced key strength made the affected keys brute-forceable without physical access, highlighting why the exploit could be rapidly replicated once the vulnerability’s practical impact became known.

On the broader theme of prevention, Dragonfly managing partner Haseeb Qureshi argued on social media that comparatively small improvements could have mitigated the risk. He referenced “$2 of AI hardening” as a shorthand for strengthening defenses, citing reports that some AI models rediscovered the vulnerability leading to the attack in less than 20 minutes.

What to watch next

As the Coldcard case continues to evolve, the key variable is whether additional funds keep flowing into mixers and whether concentration patterns change across wallets and attacker clusters. Investors and incident-trackers should watch for confirmation of further attack waves, and for whether laundering activity expands beyond the early examples highlighted by CertiK and the limited mixing behavior observed by TRM Labs.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure





Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*