Coldcard hackers transfer 64 BTC and 200 ETH to cryptocurrency mixers

요약:About $4.55 million in cryptocurrency linked to the Coldcard exploit was moved to mixing protocols, according to CertiK. The transfers included 64 Bitcoin sent to Wasabi and 200 Ether to Tornado Cash, prompting speculation of a smaller exploiter or copycats. Mixers obscure the onchain trail, complicating recovery. The Coldcard hack is now the third-largest crypto theft of 2026, with at least $100 million drained across three attack waves and a suspected fourth raising potential losses to about $130 million. TRM Labs found most victim funds remain unmixed, and transaction differences suggest multiple attackers. The root cause was a 2021 firmware bug that weakened seed randomness, making wallets brute-forceable. Dragonfly's Haseeb Qureshi estimated that "$2 of AI hardening" could have prevented it.

About 64 Bitcoin, worth $4.17 million, and 200 Ether, worth $380,000, linked to the recent Coldcard exploit were sent to cryptocurrency mixing protocols, according to blockchain security platform CertiK.

The Bitcoin transfer was from address bc1q0 to crypto mixing protocol Wasabi on Tuesday, according to blockchain data shared by CertiK.

“We think it might be a smaller exploiter. There‘s likely a few copycats after the initial exploit,” a CertiK spokesperson told Cointelegraph. The 200 Ether (ETH) was transferred to Tornado Cash on Wednesday, according to CertiK’s X post.

Crypto mixing protocols such as Tornado Cash typically pool and then scramble the cryptocurrency from multiple users, breaking the publicly traceable onchain link between senders and recipients. This makes it difficult to trace the stolen funds, decreasing the chances of asset recovery.

In April, the hacker behind a $293 million Kelp DAO hack laundered about 75,700 Ether, then worth $175 million, primarily through THORChain, generating about $910,000 in fee revenue for the protocol. The attacker also used the Umbra privacy protocol.

The Coldcard exploit has now become the third-largest cryptocurrency hack so far in 2026. It drained at least $100 million in Bitcoin across three confirmed attack waves from 7,300 victim wallets, according to Galaxy Digital. The company also identified a suspected fourth wave that could bring total losses to about $130 million in BTC.

Source: CertiK

Most copycats havent moved stolen funds

Onchain tracing by TRM Labs showed that the majority of victim funds were still pooled in a small number of attacker-controlled addresses with limited mixing attempts, according to a Thursday report.

The blockchain intelligence company said that the “differences in transaction construction” during each attack wave hint at multiple attackers behind the exploit.

The analysis is in line with Galaxys previous findings that showed at least 15 different attackers who exploited the Coldcard vulnerability.

Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says

TRM Labs said that a firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, cutting key strength to 40 bits from 128 bits, making it “brute-forceable without physical access.”

Dragonfly managing partner Haseeb Qureshi wrote that roughly “$2 of AI hardening” could have prevented the Coldcard exploit, citing social media reports that some AI models rediscovered the vulnerability that led to the attack in less than 20 minutes.

Magazine: Does Botanix‘s failure prove Bitcoiners don’t care about DeFi?

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

은광주, 은 시세 반토막에도 80% 상승 전망…이유는?

다음

마이크로소프트 주가 전망…시티, 애저 실적에 목표가 $600 상향