Recent revelations have shed light on the Coldcard exploit, a major security incident in 2026, where approximately 64 Bitcoins worth $4.17 million and 200 Ether valued at $380,000 have been traced to cryptocurrency mixing services. CertiK, a renowned blockchain security firm, identified these transactions and reported that the stolen Bitcoin, originating from address bc1q0, was transferred to the Wasabi mixer, while the Ether made its way to Tornado Cash. These moves significantly complicate asset recovery due to the inherent anonymity provided by these mixers.
How Were the Stolen Assets Moved?
The transfer of stolen Bitcoin was executed in a single transaction, marking its shift to a more private domain through Wasabi. On the subsequent day, the 200 Ether found its way to Tornado Cash, a notorious asset-mixing protocol. These actions raise red flags about the potential involvement of minor cyber criminals or imitators of the original hack, exploiting cryptocurrency mixing protocols to obscure transaction histories and evade detection.
What Damage Did the Coldcard Exploit Cause?
The Coldcard incident is noteworthy, ranking as the third-largest cryptocurrency hack of the year. Total losses amount to at least $100 million in Bitcoin, impacting roughly 7,300 wallets. Blockchain intelligence firm TRM Labs noted that most of the stolen funds are still located in a few specific addresses controlled by attackers. Surprisingly, only minimal amounts have been processed through mixing services until now.
- The confirmed attack waves have already resulted in $100 million Bitcoin losses.
- There is suspicion of another wave that could increase losses by $30 million.
- Limited transaction obscuring activities have been detected by security analysts.
Each attack wave demonstrated unique transaction characteristics, implying the presence of various perpetrators, according to TRM Labs. Galaxy Digital corroborated these findings and identified the participation of roughly 15 different attackers exploiting Coldcard’s weakness.
Coldcard, developed by Coinkite, is a trusted hardware wallet for safeguarding Bitcoins. This incident, though, has highlighted a significant vulnerability in its firmware, damaging its credibility.
The exploit was linked to a firmware bug since March 2021 that disrupted the randomness of seed generation, reducing cryptographic key efficacy from 128 bits to merely 40 bits. This flaw made it possible for attackers to commandeer private keys without accessing the physical device.
Galaxy Digital highlighted that evolving transaction methodologies across attack stages point to multiple attackers gaining knowledge of the exploit over time.
Haseeb Qureshi from Dragonfly disclosed that a basic update, priced at around $2, could have provided sufficient protection against such breaches. Notably, AI models were reported to have detected the vulnerability in a brief 20-minute review.



