- Attackers moved 64 BTC ($4.17M) and 200 ETH ($380K) from the Coldcard exploit to mixing protocols Wasabi and Tornado Cash.
- The exploit is the third-largest crypto hack of 2026, draining at least $100M in Bitcoin from 7,300 wallets across multiple attack waves.
- Onchain analysis reveals at least 15 attackers exploited a firmware bug that weakened seed randomness from 128 bits to 40 bits.
Attackers behind the record-breaking Coldcard exploit moved approximately $4.55 million in stolen cryptocurrency to mixing protocols this week, according to blockchain security platform CertiK. About 64 Bitcoin worth $4.17 million was sent to protocol Wasabi on Tuesday, while 200 Ether valued at $380,000 was transferred to Tornado Cash on Wednesday, blockchain data shows.
A CertiK spokesperson told Cointelegraph the transfers likely came from a smaller exploiter, with copycats emerging after the initial attack. Mixing protocols like Tornado Cash pool and scramble funds to break the publicly traceable onchain link between senders and recipients, according to CertiK‘s X post.
The Coldcard exploit has become the third-largest cryptocurrency hack of 2026, draining at least $100 million in Bitcoin from 7,300 victim wallets across three confirmed attack waves, according to Galaxy Digital. The firm also identified a suspected fourth wave that could push total losses to roughly $130 million in BTC.
Onchain analysis by TRM Labs shows most victim funds remain pooled in a small number of attacker-controlled addresses with limited mixing attempts, according to a Thursday report. Differences in transaction construction across attack waves suggest multiple attackers, aligning with Galaxy Digital‘s finding of at least 15 distinct exploiters.
TRM Labs attributed the vulnerability to a firmware bug from March 2021 that weakened seed randomness on some Coldcard wallets, cutting key strength to 40 bits from 128 bits. Dragonfly managing partner Haseeb Qureshi wrote that roughly $2 of AI hardening could have prevented the exploit, citing reports that some AI models rediscovered the vulnerability in under 20 minutes.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
