About 64 Bitcoin, worth $4.17 million, and 200 Ether, worth $380,000, linked to the recent Coldcard exploit were sent to cryptocurrency mixing protocols, according to blockchain security platform CertiK.
The Bitcoin transfer was from address bc1q0 to crypto mixing protocol Wasabi on Tuesday, according to blockchain data shared by CertiK.
“We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” a CertiK spokesperson told Cointelegraph. The 200 Ether (ETH) was transferred to Tornado Cash on Wednesday, according to CertiK’s X post.
Crypto mixing protocols such as Tornado Cash typically pool and then scramble the cryptocurrency from multiple users, breaking the publicly traceable onchain link between senders and recipients. This makes it difficult to trace the stolen funds, decreasing the chances of asset recovery.
In April, the hacker behind a $293 million Kelp DAO hack laundered about 75,700 Ether, then worth $175 million, primarily through THORChain, generating about $910,000 in fee revenue for the protocol. The attacker also used the Umbra privacy protocol.
The Coldcard exploit has now become the third-largest cryptocurrency hack so far in 2026. It drained at least $100 million in Bitcoin across three confirmed attack waves from 7,300 victim wallets, according to Galaxy Digital. The company also identified a suspected fourth wave that could bring total losses to about $130 million in BTC.

Source: CertiK
Most copycats haven’t moved stolen funds
Onchain tracing by TRM Labs showed that the majority of victim funds were still pooled in a small number of attacker-controlled addresses with limited mixing attempts, according to a Thursday report.
The blockchain intelligence company said that the “differences in transaction construction” during each attack wave hint at multiple attackers behind the exploit.
The analysis is in line with Galaxy’s previous findings that showed at least 15 different attackers who exploited the Coldcard vulnerability.
Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says
TRM Labs said that a firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, cutting key strength to 40 bits from 128 bits, making it “brute-forceable without physical access.”
Dragonfly managing partner Haseeb Qureshi wrote that roughly “$2 of AI hardening” could have prevented the Coldcard exploit, citing social media reports that some AI models rediscovered the vulnerability that led to the attack in less than 20 minutes.
Magazine: Does Botanix’s failure prove Bitcoiners don’t care about DeFi?
