Coldcard Hackers Begin Laundering Stolen Crypto as Investigators Track Remaining Funds

Hackers connected to the massive Coldcard wallet breach have started moving a portion of the stolen cryptocurrency through privacy tools, signaling the first major attempts to hide their trail. Despite the laundering activity, investigators say the bulk of the stolen funds are still sitting in wallets controlled by the attackers, making them easier to monitor.
Blockchain security company CertiK reported that approximately 64 Bitcoin, valued at around $4.17 million, was transferred into the Wasabi mixing service earlier this week. Separately, another 200 Ether, worth roughly $380,000, was sent through the Tornado Cash protocol.
The Bitcoin transaction originated from an address beginning with "bc1q0," according to blockchain records reviewed by CertiK. Security researchers believe these transfers may not be linked to the primary attacker behind the exploit.
"We suspect this could be a smaller participant or someone copying the original attack," a CertiK representative said, suggesting that multiple actors may now be taking advantage of the exposed vulnerability.
Cryptocurrency mixers are designed to improve transaction privacy by combining digital assets from many users before redistributing them to new addresses. While these services have legitimate privacy applications, they are frequently used by cybercriminals to make stolen funds harder to trace on public blockchains.
Although millions of dollars have now entered mixing services, investigators say only a small portion of the stolen cryptocurrency has been laundered so far.
According to blockchain intelligence firm TRM Labs, most of the assets taken during the Coldcard exploit remain consolidated across a limited number of wallets controlled by the attackers. The company noted that only minimal efforts have been made to obscure the majority of the stolen funds, allowing analysts to continue tracking their movements.
TRM Labs also found evidence suggesting the attacks were carried out by more than one group. Researchers observed noticeable differences in the way transactions were structured across separate attack waves, indicating that several independent attackers may have exploited the same weakness.
Those findings match earlier analysis from Galaxy Digital, which estimated that at least 15 different attackers participated in exploiting the Coldcard vulnerability after details of the flaw became known.
The Coldcard incident has grown into one of the largest cryptocurrency thefts of 2026. Galaxy Digital estimates that over $100 million worth of Bitcoin was stolen across three confirmed attack waves, affecting roughly 7,300 wallets. Investigators are also examining a possible fourth wave that could increase total losses to nearly $130 million.
Researchers traced the root cause of the breach to a firmware issue dating back to March 2021. According to TRM Labs, the software bug significantly reduced the randomness used when generating wallet seed phrases. Instead of providing the expected 128-bit level of security, the flaw reportedly reduced the effective strength to just 40 bits, making private keys vulnerable to brute-force attacks without requiring physical access to the wallet.
The weakness remained unnoticed for years before attackers began exploiting it on a large scale. As investigators continue monitoring blockchain activity, the fact that most stolen funds remain in identifiable wallets offers a small advantage for law enforcement and blockchain analytics firms. However, if more of those assets begin flowing through mixing protocols, tracing and recovering the cryptocurrency could become significantly more difficult.
