Stolen Coldcard Funds: Attackers Move 64 BTC and 200 ETH Through Mixing Services

Stolen Coldcard Funds: Attackers Move 64 BTC and 200 ETH Through Mixing Services

Cybercriminals responsible for the Coldcard security breach have moved millions worth of cryptocurrency to mixing platforms, though the bulk of pilfered assets remain visible in wallets under attacker control.

Approximately 64 Bitcoin, valued at $4.17 million, along with 200 Ether, valued at $380,000, connected to the Coldcard security breach have been moved to cryptocurrency mixing services, blockchain security firm CertiK has reported.

According to blockchain data provided by CertiK, the Bitcoin movement originated from address bc1q0 and was directed to the Wasabi crypto mixing protocol on Tuesday.

"We think it might be a smaller exploiter. There's likely a few copycats after the initial exploit," a CertiK spokesperson told Cointelegraph. CertiK's X post indicates that the 200 Ether (ETH) transfer to Tornado Cash occurred on Wednesday.

Cryptocurrency mixing services like Tornado Cash generally combine and then obfuscate digital assets from various users, severing the publicly visible onchain connection between those sending and those receiving funds. Such obfuscation complicates the tracking of pilfered assets, thereby reducing the likelihood of recovering them.

Back in April, the individual responsible for the $293 million Kelp DAO security breach laundered approximately 75,700 Ether, valued at $175 million at that time, mostly through THORChain, which generated roughly $910,000 in fees for that protocol. That particular attacker also utilized the Umbra privacy protocol.

The Coldcard security breach has emerged as the third-largest hack targeting cryptocurrency in 2026 thus far. According to Galaxy Digital, the exploit drained no less than $100 million in Bitcoin through three confirmed waves of attacks affecting 7,300 victim wallets. Galaxy Digital has additionally identified what they believe to be a fourth wave of attacks that may push aggregate losses to approximately $130 million in BTC.

CertiK data showing cryptocurrency transfers
Source: CertiK

Most copycats haven't moved stolen funds

Blockchain tracking conducted by TRM Labs revealed that the greater portion of stolen victim assets remained consolidated in a limited number of addresses controlled by the attackers with minimal attempts at mixing, as stated in a report released on Thursday.

According to the blockchain intelligence firm, the "differences in transaction construction" observed across each wave of attacks suggest the involvement of multiple perpetrators behind the security breach.

This assessment aligns with earlier findings from Galaxy, which indicated that no fewer than 15 distinct attackers took advantage of the Coldcard security weakness.

According to TRM Labs, a firmware defect dating back to March 2021 compromised seed randomness on certain Coldcard wallets, reducing key strength from 128 bits down to 40 bits, rendering it "brute-forceable without physical access."

Haseeb Qureshi, managing partner at Dragonfly, noted that approximately "$2 of AI hardening" might have been sufficient to prevent the Coldcard breach, referencing social media accounts indicating that certain AI models independently rediscovered the security flaw that enabled the attack in under 20 minutes.

← Back to Blog