The people behind the Coldcard hardware wallet exploit have begun moving stolen funds into privacy tools. According to blockchain security firm CertiK, cited by Cointelegraph on August 6, 2026, one set of attackers sent 64 Bitcoin through the Wasabi mixer on Tuesday and 200 Ether through Tornado Cash on Wednesday. At current prices that is roughly $4.17 million in BTC and about $380,000 in ETH, or close to $4.55 million combined.
That sum is small against the full scale of the breach. The Coldcard exploit has drained at least $100 million across three confirmed waves, hitting around 7,300 wallets, which ranks it as the third-largest crypto theft of 2026 so far. This week's laundering represents one actor cashing out a slice, not the whole haul clearing at once.
A copycat, not the lead attacker
CertiK's read is that the addresses now touching mixers do not belong to the original exploiter. "We think it might be a smaller exploiter," a CertiK spokesperson said. "There's likely a few copycats after the initial exploit." Investigators have tied at least 15 separate attackers to the same underlying flaw, which turned a single firmware bug into an open season once the method was understood.
The split between BTC and ETH laundering venues fits the pattern. Wasabi handles Bitcoin through CoinJoin-style batching, while Tornado Cash remains the default Ethereum mixer despite years of sanctions pressure in the United States. Splitting funds across two chains and two tools is a standard attempt to fragment the trail before converting to spendable fiat or stablecoins.
The 2021 bug that made keys guessable
The vulnerability traces to a firmware update from March 2021 that weakened how affected Coldcard devices generated seed randomness. Instead of a full 128 bits of entropy, some wallets were left with roughly 40 bits. That gap is the difference between a key that cannot be brute-forced in any human timescale and one that can be cracked without ever touching the device.
Dragonfly partner Haseeb Qureshi put the failure in blunt terms, estimating that about "$2 of AI hardening" could have caught the flaw, and noting that some AI models rediscovered the weakness in under 20 minutes when pointed at the code. The bug sat dormant for years before attackers weaponized it, which is why funds are only moving now.
Anyone who set up an affected Coldcard in that window and never rotated to a fresh seed on patched firmware is exposed regardless of how carefully they stored the physical device. This is not a phishing or malware story. The keys themselves were weak from generation.
The custody lesson behind the numbers
Coldcard's appeal was always self-custody done properly: an air-gapped device, keys that never leave your hands, no exchange or issuer able to freeze your balance. That model still avoids the counterparty risk that sank FTX and Wirecard, and it is the same principle behind cards that spend from your own wallet rather than a custodial float. Holding your own keys removes the middleman.
It does not remove implementation risk. A hardware wallet is only as strong as its firmware and its entropy source, and this breach shows what happens when one silent defect undercuts an otherwise sound design. Self-custody shifts responsibility to the user, and part of that responsibility is acting on security disclosures fast, not treating a device as permanently safe because it was safe on day one.
For anyone spending crypto day to day, the takeaway is separation of duties. Keep long-term holdings on cold storage you actively monitor for advisories, and route everyday spending through a smaller hot balance or a dedicated card account. Concentrating everything on a single device, however reputable, is the exposure this campaign punished.
Overview
Attackers exploiting a 2021 Coldcard firmware flaw pushed 64 BTC through Wasabi and 200 ETH through Tornado Cash this week, laundering about $4.55 million. CertiK believes the mover is a copycat rather than the lead exploiter, one of at least 15 actors abusing a bug that cut seed entropy from 128 bits to 40 bits. The full campaign has taken over $100 million from roughly 7,300 wallets. Self-custody still beats trusting a custodian, but it demands users track firmware advisories and rotate weak keys immediately.



