Attackers linked to the Coldcard exploit transferred approximately 64 Bitcoin and 200 Ether to cryptocurrency mixing protocols. The movement of funds was detected between August 4 and August 5, 2026, as alert published by CertiK confirmed through onchain analysis.https://twitter.com/CertiKAlert/status/2084920866526114183
The total value of the transferred assets equals $4.17 million in BTC and $380,000 in ETH. The Bitcoin transfer was executed from a specific wallet address to the Wasabi privacy service on Tuesday, August 4, 2026.
Meanwhile, the attacker bitcoin wallet address beginning with the prefix bc1q0 recorded direct interactions with the monitored mixing protocols. CertiK confirmed that the transfer of 200 ETH to Tornado Cash was completed on Wednesday, August 5, 2026.
Spokespersons from CertiK stated that these movements likely represent secondary exploiters or copycats acting after the initial breach. Crypto mixing protocols combine transactions from multiple users to disrupt public traceability on public ledgers.
By scrambling transaction histories inside smart contracts or liquidity pools, mixers break the visible link between sender and receiver. This process significantly reduces the probability of recovering stolen assets through standard blockchain tracing.
Fund Routing and Hardware Vulnerability Details
Despite these recent transfers, blockchain intelligence firm TRM Labs reported on August 6, 2026, that most stolen capital remains consolidated. The vast majority of victim funds stay pooled within a small cluster of addresses controlled by the attackers.
TRM Labs highlighted distinct structural differences in transaction construction across each attack wave. This finding aligns with analysis from Galaxy Digital, which identified at least 15 separate attackers exploiting the underlying vulnerability.
The technical root cause stems from a cold storage wallet vulnerability introduced in a March 2021 firmware update. The flaw weakened seed phrase randomness on Mk2 and Mk3 hardware device models.
The compromised entropy reduced private key strength from 128 bits down to just 40 bits. This reduction allowed malicious actors to reconstruct private keys offline using brute-force methods without needing physical possession of the hardware device.
Galaxy Digital calculated that the overall losses surpassed $100 million in BTC. The funds were drained from 7,300 victim wallets across three confirmed attack waves beginning in late July 2026.
Furthermore, Galaxy researchers identified evidence of a suspected fourth attack wave. If confirmed, total cumulative losses would reach approximately $130 million in Bitcoin, positioning the exploit as the third-largest cryptocurrency breach of 2026.
Laundering Dynamics and Industry Comparisons
The laundering patterns in this incident contrast with methods used in other major security breaches. During the previous Kelp DAO exploit in April 2026, the attacker laundered 75,700 Ether primarily using THORChain and the Umbra privacy protocol.
That Kelp DAO incident generated roughly $910,000 in fee revenue for THORChain. In contrast, attackers in the Coldcard exploit have selectively utilized Wasabi for Bitcoin transactions and Tornado Cash for Ethereum assets.
Regarding protocol security, Dragonfly managing partner Haseeb Qureshi noted that basic code hardening could have mitigated the flaw. Artificial intelligence models successfully rediscovered the firmware vulnerability in under 20 minutes during testing simulations.
Onchain security firms continue active monitoring of all identified wallet addresses to detect further fund movements. Future transfers will determine whether the remaining funds remain dormant or enter additional mixing protocols over time.
This article is for informational purposes only and does not constitute financial advice.

