Coldcard Attackers Move 64.9 BTC and 200 ETH Through Mixers
Funds linked to the Coldcard hardware wallet exploit have entered Wasabi and Tornado Cash, marking the first identified mixer deposits tied to the theft campaign.
TRM Labs traced one 64.9 BTC deposit into Wasabi and 200 ETH deposited into Tornado Cash on August 4. The movements represent a small portion of the estimated 1,816 BTC, worth about $116 million, drained from more than 5,200 addresses across four waves.
Wasabi Receives 64.9 BTC as Tornado Cash Gets 200 ETH
TRM identified the Wasabi and Tornado Cash deposits in an August 5 assessment of the Coldcard incident. CertiK separately flagged the 200 ETH movement into Tornado Cash.
Mixers make transaction trails more difficult to follow by separating deposited assets from later withdrawals. The services can complicate efforts to trace where stolen funds move after they leave their initial receiving addresses.
Investigators have not attributed the deposits to a specific attacker. Differences in transaction construction across the four theft waves suggest that multiple operators may have exploited the same seed-generation weakness.
Most of the 1,816 BTC Remains in a Few Attacker Addresses
TRM said most victim funds remain pooled in a few attacker-controlled addresses. Apart from the two mixer deposits, onward activity has largely involved one additional consolidation step rather than extensive layering.
The current loss estimate remains preliminary because funds are still moving, and additional victims may report compromised wallets. A fourth wave was still moving through Bitcoin’s mempool when TRM completed its assessment.
TRM has not linked the campaign to a known hacking group and continues monitoring the stolen funds for further movement.
Coldcard Users Must Replace Seeds Created on Affected Firmware
The exploit traces to a March 2021 firmware error that caused affected devices to use a weak software random-number fallback during wallet-seed generation.
Coinkite says affected seeds include those generated on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, Mk4 and Mk5 releases before version 5.6.0, and Q firmware before version 1.5.0Q. Some older-model seeds contained about 40 bits of entropy instead of the intended 128 bits.
Installing fixed firmware protects newly generated wallets but cannot strengthen an existing vulnerable seed. Users must create a new seed on patched firmware, verify the wallet and receiving address, send a small test transaction and then migrate the remaining Bitcoin.