Coldcard hackers transfer 64 BTC and 200 ETH to cryptocurrency mixers
Hackers behind the Coldcard exploit transferred millions in digital assets to cryptocurrency mixers, while most stolen funds remained traceable in attacker-controlled wallets.
Hackers exploited the Coldcard vulnerability, moving over $4.17 million in Bitcoin and $380,000 in Ether to cryptocurrency mixing platforms, according to blockchain security firm CertiK. CertiK's sources suggest the exploit may have been carried out by a smaller group, with additional copycats potentially emerging. The stolen Bitcoin was sent to the Wasabi mixing protocol, while the Ether was moved to Tornado Cash.
Mixing protocols, like Tornado Cash, obscure the link between senders and recipients, making it challenging to trace the funds and recover them. In April, a hacker behind a $293 million Kelp DAO hack laundered approximately 75,700 Ether, earning around $910,000 in protocol fees. The Coldcard exploit ranks as the third-largest cryptocurrency hack in 2026, with the attacker siphoning at least $100 million in Bitcoin across three waves from 7,300 wallets, with a possible fourth wave adding $130 million in potential losses.
TRM Labs' onchain analysis indicates that most victim funds are still concentrated in a few attacker-controlled addresses with limited mixing attempts, hinting at multiple attackers behind the exploit. This situation aligns with Galaxy Digital's earlier findings, which suggest at least 15 distinct attackers had taken advantage of the Coldcard vulnerability.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.