Coldcard attackers route 64 BTC, 200 ETH into mixers
Funds from the Coldcard exploit — 64 BTC (~$4.17M) and 200 ETH (~$380K) — were sent to Wasabi and Tornado Cash, CertiK reported.
Blockchain data analyzed by CertiK shows that funds tied to the Coldcard exploit — 64 Bitcoin, about $4.17 million, and 200 Ether, about $380,000 — were moved into crypto mixing services this week. The Bitcoin left an address labeled bc1q0 and was deposited into Wasabi on Tuesday; the Ether was sent to Tornado Cash on Wednesday.
Mixing services pool cryptocurrency from many users and then redistribute it, breaking direct onchain links between original senders and eventual recipients. That process makes tracing stolen funds and recovering assets more difficult.
Blockchain intelligence firm TRM Labs found most victim funds remain concentrated in a small number of attacker-controlled addresses and that few mixing attempts have been made so far. TRM noted differences in how transactions were constructed across attack waves, which suggest multiple actors exploited the same vulnerability.
CertiK published transaction details and a spokesperson commented that the pattern points to a smaller exploiter with likely copycats following the initial breach. Galaxy Digital identified at least three confirmed waves that together stripped at least $100 million in Bitcoin from about 7,300 wallets and flagged a suspected fourth wave that could push Bitcoin losses to roughly $130 million.
Investigators traced the root cause to a Coldcard firmware bug from March 2021 that weakened seed randomness on affected devices. TRM Labs reported the flaw reduced key strength from an expected 128 bits to about 40 bits, a level that can be brute-forced without physical access to the hardware.
Dragonfly managing partner Haseeb Qureshi noted that simple automated checks using AI models reportedly rediscovered the vulnerability in minutes and that minimal additional hardening could have prevented the exploit.
In April, an attacker laundering funds from a separate breach routed roughly 75,700 Ether mainly through THORChain and also used the Umbra privacy protocol; that effort generated about $910,000 in protocol fees for the intermediary.
Security firms including CertiK and TRM Labs continue to trace onchain flows and publish watchlists of addresses linked to the campaign while law enforcement and affected parties pursue recovery and enforcement options.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








