TL;DR
- Hackers linked to the Coldcard exploit transferred 64 BTC ($4.17 million) and 200 ETH ($380,000) to crypto mixers.
- Most of the stolen funds remain in wallets controlled by the hackers; attempts to use mixers were limited, according to TRM Labs.
- A firmware bug from March 2021 reduced key strength from 128 to 40 bits, making them vulnerable to brute force attacks without physical access.
The hackers behind the Coldcard exploit moved a portion of the stolen funds to crypto mixers, as confirmed by blockchain security platform CertiK.
Specifically, 64 Bitcoin valued at $4.17 million were sent from address bc1q0 to the Wasabi protocol, while 200 ETH worth $380,000 were transferred to Tornado Cash. Both transactions were recorded on-chain and traced by CertiK, which published its findings on its X account.
#CertiKInsight 🚨
Our alert system detected two 200 ETH transactions sent to Tornado Cash linked to the ongoing @COLDCARDwallet attack.
The funds were bridged from BTC to ETH address 0x41B7529a411EeA979a8d468bdEBd36b0ad703268 via THORChain before being sent to Tornado Cash. pic.twitter.com/JLazHWIEvo
— CertiK Alert (@CertiKAlert) August 5, 2026
A CertiK spokesperson noted that the transactions could correspond to secondary actors: “We believe it could be a minor hacker. There are probably several copycats following the initial exploit.” This scenario is consistent with findings from Galaxy Digital, which identified at least 15 distinct attackers involved in the Coldcard breach.
The Hackers Left Traces on the Chain
The Coldcard exploit became the third-largest cryptocurrency hack so far in 2026. According to Galaxy Digital, the attack caused losses of at least $100 million in Bitcoin from 7,300 wallets across three confirmed attack waves, with a fourth suspected wave that would bring total losses to approximately $130 million in BTC.
However, the majority of the stolen funds were not moved. A Thursday report from TRM Labs revealed that most of the stolen assets remain concentrated in a small number of addresses controlled by the hackers, with mixing attempts occurring but remaining limited. The firm also detected differences in transaction construction across attack waves, reinforcing the hypothesis of multiple actors behind the exploit.
$2 Would Have Been Enough to Prevent the Exploit
The technical root of the problem is a firmware bug from March 2021 that reduced the randomness of seeds in some Coldcard wallets, cutting key strength from 128 to 40 bits and making them vulnerable to brute force attacks without requiring physical access, according to TRM Labs.
Haseeb Qureshi, managing partner at Dragonfly, stated that roughly “$2 worth of AI hardening could have prevented the exploit”, citing social media reports indicating that some artificial intelligence models rediscovered the vulnerability in under 20 minutes.






