About 64 Bitcoin, value $4.17 million, and 200 Ether, value $380,000, linked to the current Coldcard exploit have been despatched to cryptocurrency mixing protocols, in keeping with blockchain safety platform CertiK.
The Bitcoin switch was from tackle bc1q0 to crypto mixing protocol Wasabi on Tuesday, in keeping with blockchain information shared by CertiK.
“We expect it is likely to be a smaller exploiter. There’s seemingly a number of copycats after the preliminary exploit,” a CertiK spokesperson advised Cointelegraph. The 200 Ether (ETH) was transferred to Twister Money on Wednesday, in keeping with CertiK’s X publish.
Crypto mixing protocols corresponding to Twister Money sometimes pool after which scramble the cryptocurrency from a number of customers, breaking the publicly traceable onchain hyperlink between senders and recipients. This makes it tough to hint the stolen funds, lowering the probabilities of asset restoration.
In April, the hacker behind a $293 million Kelp DAO hack laundered about 75,700 Ether, then value $175 million, primarily via THORChain, producing about $910,000 in charge income for the protocol. The attacker additionally used the Umbra privateness protocol.
The Coldcard exploit has now turn out to be the third-largest cryptocurrency hack up to now in 2026. It drained at the very least $100 million in Bitcoin throughout three confirmed assault waves from 7,300 sufferer wallets, in keeping with Galaxy Digital. The corporate additionally recognized a suspected fourth wave that would convey whole losses to about $130 million in BTC.

Supply: CertiK
Most copycats haven’t moved stolen funds
Onchain tracing by TRM Labs confirmed that almost all of sufferer funds have been nonetheless pooled in a small variety of attacker-controlled addresses with restricted mixing makes an attempt, in keeping with a Thursday report.
The blockchain intelligence firm stated that the “variations in transaction building” throughout every assault wave trace at a number of attackers behind the exploit.
The evaluation is in step with Galaxy’s earlier findings that confirmed at the very least 15 totally different attackers who exploited the Coldcard vulnerability.
Associated: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly accomplice says
TRM Labs stated {that a} firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, reducing key power to 40 bits from 128 bits, making it “brute-forceable with out bodily entry.”
Dragonfly managing accomplice Haseeb Qureshi wrote that roughly “$2 of AI hardening” might have prevented the Coldcard exploit, citing social media reviews that some AI fashions rediscovered the vulnerability that led to the assault in lower than 20 minutes.
Journal: Does Botanix’s failure show Bitcoiners don’t care about DeFi?


