📰
Top StoriesBearish
66
BTCETH

Coldcard Hackers Launder $4.5M via Crypto Mixers

Hackers from the Coldcard wallet exploit have transferred 64 BTC and 200 ETH to mixers Wasabi and Tornado Cash, laundering $4.5 million. This follows the theft of over $100 million in Bitcoin from 7,300 wallets, now the third-largest crypto hack of 2026. On-chain analysis reveals most stolen funds remain unmoved.

CointelegraphCointelegraph by Zoltan Vardai

Quick Take

1

64 BTC ($4.17M) sent to Wasabi mixing protocol on Tuesday.

2

200 ETH ($380K) transferred to Tornado Cash on Wednesday.

3

Coldcard exploit drained $100M+ BTC, third-largest hack of 2026.

4

Most victim funds still pooled in attacker-controlled addresses unlaundered.

Market Impact Analysis

Bearish

The laundering of stolen funds from a major hack may reinforce negative security perceptions, but the market likely already priced in the hack; the incremental impact is limited.

Timeframeshort

Speculation Analysis

Factuality85/100
RumorsVerified
Speculation Trigger25/100
MinimalExtreme FOMO

Key Takeaways

  • 64 BTC ($4.17M) funneled to Wasabi mixer, and 200 ETH ($380K) to Tornado Cash, marking the first laundering moves from the Coldcard exploit.
  • The Coldcard hack is now 2026's third-largest, draining over $100 million in Bitcoin from 7,300 wallets due to a firmware bug.
  • Most stolen funds remain in attacker-controlled addresses with limited mixing, suggesting multiple attackers may be biding their time.
  • On-chain tracing firms warn that mixer use complicates recovery, though copycat attackers haven't moved funds yet.
Hack Total $100M+ drained from 7,300 wallets
BTC Laundered 64 BTC ($4.17M) via Wasabi on Tuesday
ETH Laundered 200 ETH ($380K) via Tornado Cash on Wednesday
Firmware Flaw Seed randomness weakened to 40 bits from standard 128 bits

What Happened

Hackers behind the Coldcard exploit have begun laundering stolen crypto, moving 64 BTC ($4.17M) to Wasabi mixer on Tuesday and 200 ETH ($380K) to Tornado Cash on Wednesday. The transfers mark the first significant movement of funds since the exploit drained over $100 million from 7,300 wallets. The Coldcard breach, now the third-largest crypto hack of 2026, stemmed from a firmware bug that reduced seed entropy to just 40 bits, making private keys brute-forceable. While these initial laundering attempts involve only a fraction of the total stolen funds, they signal active steps to obscure the trail.

The Numbers

The Coldcard exploit ranks as 2026's third-biggest crypto theft, with at least $100 million in Bitcoin siphoned across three attack waves. A suspected fourth wave could push losses to $130 million. The moved funds represent a small slice: 64 BTC ($4.17M) and 200 ETH ($380K) — less than 5% of the total haul. The firmware vulnerability, introduced in March 2021, slashed seed key strength from 128 bits to 40 bits, enabling brute-force attacks without physical access. On-chain data shows most stolen BTC remains pooled in attacker-controlled addresses.

Why It Happened

The laundering via mixers is a predictable next step after a major exploit. Attackers use Wasabi and Tornado Cash to break the link between original theft addresses and cash-out points, making funds harder to trace. The Coldcard bug, a critical firmware flaw that weakened random number generation, opened the door for mass theft. With multiple attackers identified — at least 15 exploiters — the slow movement suggests a coordinated or patient approach. The use of mixers underscores the ongoing challenge for blockchain security, as privacy tools continue to shield illicit flows despite regulatory pressure.

Broader Impact

The incident reignites debate over privacy tool regulation. Tornado Cash was sanctioned in 2022, yet remains in use. This laundering attempt may intensify calls for stricter controls on mixers, while also highlighting the dire consequences of hardware wallet vulnerabilities. For the industry, the Coldcard case underscores the need for rigorous firmware audits and user education. As AI advances, such bugs could be spotted pre-exploit — a missed opportunity that might have cost users over $100 million.

What to Watch Next

  • Watch for further mixing transactions from the main attacker addresses, as $100M+ remains largely unmoved.
  • Monitor regulatory responses, especially potential actions against Wasabi or renewed focus on Tornado Cash compliance.

Source: Cointelegraph

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Cointelegraph
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

📰
DeFiNeutral
52

Ten Weirdest Tokenized Assets: From Farts to Cows

From flatulence NFTs to tokenized cows as collateral, this listicle explores the most unusual real-world assets minted onchain. The article highlights how tokenization is expanding beyond traditional finance, with cases like digital racehorses, whiskey barrels, and even uranium, demonstrating blockchain's potential to fractionalize and trade almost anything.

85% confidence
Aug 6, 2026, 1:30 PM UTC · Cointelegraph
Coldcard Hackers Launder $4.5M via Wasabi, Tornado | Bytewit