Latest News

Coldcard Exploit Funds Worth $4.5 Million Sent Through…

How Much Stolen Crypto Has Reached Mixers?

Cryptocurrency linked to the recent Coldcard exploit has begun moving through privacy protocols, complicating efforts to trace and recover assets taken from thousands of wallets.

About 64 Bitcoin, worth roughly $4.17 million, was transferred from an address beginning with bc1q0 to the Wasabi mixing protocol on Tuesday, according to blockchain data reviewed by security researchers. Separately, an attacker converted stolen Bitcoin into about 200 Ether through THORChain before sending the funds, valued at roughly $380,000, to Tornado Cash on Wednesday.

The transfers represent only a small share of the total losses associated with the exploit. Security analysts believe the movements may have been made by a smaller attacker or one of several copycats that followed the initial attack.

Mixing protocols combine assets from multiple users and obscure the public transaction trail between sending and receiving addresses. They do not make assets disappear, but they can make attribution more difficult and reduce the likelihood that exchanges or investigators can identify and freeze the stolen funds.

The separation between the 64 Bitcoin mixing cluster and the larger seven-address cluster holding about 1,159 Bitcoin supports the view that more than one attacker may have taken advantage of the vulnerability. Investigators have also found differences in how transactions were constructed across the attack waves.

Why Do Researchers Suspect Multiple Attackers?

The Coldcard exploit drained at least $100 million in Bitcoin across three confirmed attack waves involving about 7,300 victim wallets. A suspected fourth wave could raise the total loss to approximately $130 million, which would make the incident the third-largest cryptocurrency hack recorded so far in 2026.

Blockchain tracing showed that most of the stolen assets remain concentrated in a limited number of attacker-controlled addresses. Only a relatively small portion has been sent through mixers, indicating that many of the suspected attackers have not yet tried to obscure or liquidate their holdings.

Researchers said differences in transaction construction across the attack waves suggest that the funds were not all taken by a single operator using one automated process. Earlier analysis identified at least 15 attackers that may have exploited the same weakness.

That pattern creates a more difficult recovery process. A single attacker may follow a consistent laundering route that investigators can map across several blockchains. Multiple copycats can instead use different wallets, exchanges, bridges and privacy tools, forcing investigators to separate dozens of transaction trails.

Investor Takeaway

The movement of funds through Wasabi and Tornado Cash does not account for most of the Coldcard losses. The larger risk is that additional attackers begin moving pooled Bitcoin before exchanges, analytics companies and law enforcement can identify reliable recovery routes.

What Caused The Coldcard Wallet Vulnerability?

The exploit was linked to a firmware bug introduced in March 2021 that weakened the randomness used to generate seed phrases on some Coldcard wallets. The flaw reportedly reduced the effective strength of private keys from 128 bits to 40 bits.

At that level, attackers could potentially recover affected keys through brute-force computing without obtaining physical access to the wallet. That made the vulnerability especially damaging because users may have believed their funds remained protected as long as their hardware devices and recovery phrases were stored securely.

The incident shows that hardware wallet security depends on more than the physical device. Weaknesses in random-number generation, firmware updates or seed creation can undermine protections even when users follow standard custody practices.

Dragonfly managing partner Haseeb Qureshi argued that basic artificial intelligence-assisted security testing could have helped identify the flaw. He cited reports that some AI models rediscovered the vulnerability in less than 20 minutes, describing the missing safeguard as roughly “$2 of AI hardening.”

The claim does not mean automated testing can replace professional security audits. It does suggest that wallet developers may increasingly use AI tools alongside traditional code review, fuzz testing and cryptographic verification to find weaknesses before attackers do.

Can The Remaining Funds Still Be Recovered?

The concentration of most stolen assets in a small group of visible addresses gives investigators a window to track future movements. Exchanges and custodians can flag identified addresses, while blockchain analytics companies can follow transactions as funds move through bridges or centralized trading platforms.

Recovery becomes less likely when attackers use mixers, decentralized exchanges or cross-chain protocols that split funds into smaller amounts. In April, the attacker behind the $293 million Kelp DAO hack moved about 75,700 Ether through several services, including THORChain and the Umbra privacy protocol.

That case showed how stolen funds can generate revenue for the protocols used to move them. THORChain reportedly earned about $910,000 in fees from transactions linked to the attacker.

For Coldcard users, the priority is identifying whether their wallets were created with affected firmware and moving any remaining assets to newly generated addresses using secure seed randomness. For investigators, the next major test will be whether the attackers holding most of the stolen Bitcoin keep the funds dormant or begin following the smaller transfers into privacy protocols.

You may also like