Hackers tied to the Coldcard exploit have started using cryptocurrency mixers to hide the flow of stolen assets. Mixing services like Wasabi and Tornado Cash accept funds from multiple users. They then randomly distribute them. This process effectively severs the direct link between senders and receivers on the blockchain. This greatly complicates the ability of investigators to follow the stolen coins back to the original hackers.
CertiK reported that the Bitcoin came from a wallet labeled bc1q0. It was sent to the Wasabi mixer on Tuesday. Meanwhile, 200 ETH was routed through Tornado Cash the next day. Although these transactions aim to anonymize the stolen funds, most of the assets are still sitting in addresses controlled by the attackers. There is little sign of further laundering activity.
Multiple Attackers May Be Involved
A spokesperson from CertiK told Cointelegraph that these movements suggest a possible group of attackers, with some likely copying the actions of the original exploit. Galaxy Digital had earlier identified at least 15 separate individuals who took advantage of the same flaw in Coldcard wallets.
TRM Labs' analysis confirmed that each wave of attacks had slightly different transaction patterns, which supports the idea that more than one group was involved. The Coldcard breach has now become the third most significant cryptocurrency theft of 2026, with at least $100 million in Bitcoin taken from over 7,300 victim wallets. Galaxy Digital warns that total losses could reach $130 million if a rumored fourth attack wave occurs.
According to TRM Labs, the security issue traces back to a firmware flaw. It made the randomness of seed phrases weaker in some Coldcard devices. Instead of the standard 128-bit encryption, the key strength was cut to just 40 bits. This made it possible for attackers to guess the keys through brute-force techniques. This happened without needing to physically access the wallets.
Haseeb Qureshi, managing partner at Dragonfly, noted that AI improvements costing as little as $2 could have made the Coldcard wallets more secure. He referenced reports indicating that certain AI models were able to detect the vulnerability within 20 minutes. This suggests stronger AI-based defenses could have thwarted the attack before it happened.

