TL;DR
- Hackers linked to the Coldcard exploit transferred 64 BTC ($4.17 million) and 200 ETH ($380,000) to crypto mixers.
- Many of the stolen funds stay in wallets managed by the hackers; makes an attempt to make use of mixers had been restricted, in keeping with TRM Labs.
- A firmware bug from March 2021 lowered key power from 128 to 40 bits, making them weak to brute drive assaults with out bodily entry.
The hackers behind the Coldcard exploit moved a portion of the stolen funds to crypto mixers, as confirmed by blockchain safety platform CertiK.
Particularly, 64 Bitcoin valued at $4.17 million had been despatched from handle bc1q0 to the Wasabi protocol, whereas 200 ETH price $380,000 had been transferred to Twister Money. Each transactions had been recorded on-chain and traced by CertiK, which printed its findings on its X account.
Our alert system detected two 200 ETH transactions despatched to Twister Money linked to the continued @COLDCARDwallet assault.
The funds had been bridged from BTC to ETH handle 0x41B7529a411EeA979a8d468bdEBd36b0ad703268 through THORChain earlier than being despatched to Twister Money. pic.twitter.com/JLazHWIEvo
— CertiK Alert (@CertiKAlert) August 5, 2026
A CertiK spokesperson famous that the transactions may correspond to secondary actors: “We consider it may very well be a minor hacker. There are most likely a number of copycats following the preliminary exploit.” This state of affairs is per findings from Galaxy Digital, which recognized no less than 15 distinct attackers concerned within the Coldcard breach.
The Hackers Left Traces on the Chain
The Coldcard exploit grew to become the third-largest cryptocurrency hack to this point in 2026. Based on Galaxy Digital, the assault triggered losses of no less than $100 million in Bitcoin from 7,300 wallets throughout three confirmed assault waves, with a fourth suspected wave that may convey whole losses to roughly $130 million in BTC.

Nonetheless, the vast majority of the stolen funds weren’t moved. A Thursday report from TRM Labs revealed that many of the stolen belongings stay concentrated in a small variety of addresses managed by the hackers, with mixing makes an attempt occurring however remaining restricted. The agency additionally detected variations in transaction building throughout assault waves, reinforcing the speculation of a number of actors behind the exploit.
$2 Would Have Been Sufficient to Stop the Exploit
The technical root of the issue is a firmware bug from March 2021 that lowered the randomness of seeds in some Coldcard wallets, reducing key power from 128 to 40 bits and making them weak to brute drive assaults with out requiring bodily entry, in keeping with TRM Labs.


Haseeb Qureshi, managing associate at Dragonfly, acknowledged that roughly “$2 price of AI hardening may have prevented the exploit”, citing social media experiences indicating that some synthetic intelligence fashions rediscovered the vulnerability in underneath 20 minutes.

