Coldcard Exploit Drains Over $130 Million in Bitcoin as Hackers Move Funds to Mixers

Binance


Set as Google Preferred SourceFollow on Google News

TLDR

  • A firmware flaw in Coldcard hardware wallets has led to losses of over $130 million in Bitcoin across multiple attack waves
  • Bitcoin active addresses hit 980,000 per day, the highest since December 2024, driven by security concerns not market optimism
  • At least 15 different attackers exploited the vulnerability, with a fourth wave suspected
  • Hackers sent 64 Bitcoin and 200 Ether to crypto mixing services Wasabi and Tornado Cash to obscure stolen funds
  • The Coldcard exploit is now the third-largest crypto hack of 2026

A firmware flaw in Coldcard hardware wallets has triggered one of the biggest Bitcoin security events of 2026, with losses now estimated at over $130 million.

The vulnerability dates back to March 2021, when a firmware bug weakened the randomness of seed generation on affected devices. This cut key strength from 128 bits to just 40 bits, making wallets brute-forceable without any physical access.

Galaxy Digital confirmed at least three waves of attacks, draining funds from 7,300 victim wallets. A suspected fourth wave could push total losses even higher.

Bitcoin On-Chain Activity Spikes

Blockchain analytics firm Glassnode reported that Bitcoin active addresses surged to around 980,000 per day following the exploit. That is the highest level since December 2024.

Glassnode was clear that the spike was not driven by market enthusiasm. The firm described it as “an operational security response, not a change in market conviction.”

Dormant Bitcoin worth nearly 200 times the value of the initially stolen funds moved across the network, suggesting many holders were moving assets out of caution.


Betpanda


The July 31 theft of 594 Bitcoin, worth around $38 million at the time, was the event that triggered the wider on-chain response. Galaxy Research later confirmed losses had exceeded 1,596 Bitcoin, worth more than $100 million.

Hackers Route Funds Through Mixers

Blockchain security firm CertiK tracked the movement of stolen funds. Around 64 Bitcoin, worth $4.17 million, was sent to Wasabi, a Bitcoin mixing protocol. Separately, 200 Ether worth around $380,000 was sent to Tornado Cash.

CertiK suggested some of these transfers may have come from copycat attackers. “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” a CertiK spokesperson said.

TRM Labs confirmed that most stolen funds are still sitting in a small number of attacker-controlled wallets. The differences in how each attack wave was constructed point to at least 15 separate attackers.

Dragonfly managing partner Haseeb Qureshi noted that some AI models reportedly rediscovered the underlying vulnerability in less than 20 minutes. He suggested roughly two dollars of AI-based hardening could have prevented the exploit.

Security experts say updating firmware alone is not enough for affected users. Anyone who created a wallet on a compromised device is advised to generate a new wallet and move their funds immediately.

The Coldcard exploit now ranks as the third-largest crypto hack of 2026 so far.





Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*