Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

Coldcard attacker holds 1,159 BTC as mixing starts

August 5, 2026

Aug. 8 for U.S. users

August 5, 2026

White House Now Reviewing Crypto Clarity Act

August 5, 2026
Facebook X (Twitter) Instagram
Wednesday, August 5 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

Coldcard attacker holds 1,159 BTC as mixing starts

August 5, 2026Updated:August 5, 2026No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Coldcard attacker holds 1,159 BTC as mixing starts
Share
Facebook Twitter LinkedIn Pinterest Email
ad

A lot of the Bitcoin stolen via the COLDCARD pockets flaw stays unmoved, however on-chain investigators have detected a separate attacker starting to route smaller quantities via a mixer.

Abstract

  • The most important recognized COLDCARD attacker controls 1,159 BTC throughout seven addresses.
  • Not one of the 1,159 BTC has entered mixers or been transferred to an identifiable cash-out service.
  • A separate attacker despatched 64 BTC towards a mixer, initially mixing about 10 BTC.
  • Investigators have distributed roughly 600 flagged addresses to regulation enforcement, exchanges, and analytics corporations.

COLDCARD attacker leaves 1,159 BTC untouched

Galaxy Analysis mentioned the most important recognized theft linked to the COLDCARD vulnerability concerned 1,159 BTC. The funds stay unfold throughout seven addresses related to the attacker and haven’t moved because the preliminary sweep.

COLDCARD ATTACKER MOVES FUNDS

The Coldcard RNG exploit cluster acquired 1,159.42 BTC (~$72.71M) from 870 exploited addresses.

The attacker moved 0.06 BTC (~$3.78K) to a brand new tackle, whereas 1,159.35 BTC (~$72.70M) stays throughout the 8 unique attacker addresses.

Recent… pic.twitter.com/mPGHa9Vnat

— Onchain Lens (@OnchainLens) August 1, 2026

The Bitcoin was stolen inside 41 minutes, in accordance with the most recent on-chain monitoring cited by Bitcoin Information. Investigators haven’t detected transfers from the seven addresses to exchanges, mixers or different providers generally used to obscure stolen funds.

The property are due to this fact higher described as unmoved slightly than technically frozen. Bitcoin transactions can’t be stopped on the protocol degree merely as a result of an tackle has been flagged.

Nonetheless, the attacker may face difficulties changing the funds into fiat or different property. Regulation enforcement companies, cryptocurrency exchanges and blockchain analytics corporations have reportedly flagged about 600 addresses linked with the broader theft.

Any switch to a compliant alternate may set off transaction monitoring controls and requests for details about the account receiving the Bitcoin.

Smaller attacker begins mixing stolen Bitcoin

Separate on-chain exercise suggests one other attacker has began making an attempt to obscure a part of the stolen funds.

Analysts tracked 64 BTC getting into a transaction circulate linked to a mixer. Roughly 10 BTC was initially blended, whereas about 54 BTC returned as change. The remaining funds have been subsequently divided into outputs of roughly 7 BTC every for additional mixing.

UPDATE COLDCARD:
THE THIEF IS NOW MIXING HIS 64 BTC

1. The funds have been despatched to that tackle:
bc1pynd6vswmxkghw6k5463xwcj7el7u4tpl2t2pnh0s8llmc2wgzfqsdu7h92

2. It was blended in that unusual transaction:
– 64 BTC enter
– and a 54 BTC output… https://t.co/717BUz0gxm pic.twitter.com/GMzSkE3xrA

— Marius OffChain (@mariusoffchain) August 5, 2026

Mixers mix or restructure transactions to make it more durable to attach the unique supply of cryptocurrency with its eventual vacation spot. Nonetheless, they don’t assure that funds will turn out to be untraceable.

Analysts mentioned the comparatively giant and constantly sized outputs make this laundering try simpler to comply with. Investigators can proceed monitoring the transactions because the Bitcoin passes via further addresses.

The exercise additionally seems separate from the seven-address cluster holding 1,159 BTC. Earlier reporting discovered that a number of attackers might have exploited the identical pockets weak spot, that means actions from one cluster mustn’t routinely be attributed to each COLDCARD theft.

Galaxy beforehand tracked 1,596 stolen BTC

As beforehand reported by crypto.information, Galaxy Analysis confirmed that attackers stole 1,596 BTC from roughly 7,300 addresses throughout three assault waves. It additionally recognized 14 smaller incidents linked to the identical seed-generation flaw.

A suspected fourth wave may elevate the overall to roughly 2,055 BTC, though Galaxy had not confirmed these further losses via ample sufferer reviews.

The vulnerability resulted from a firmware error that weakened the randomness used to generate pockets seed phrases. Attackers may reproduce potential seeds offline, derive their Bitcoin addresses, and examine them with addresses seen on the blockchain.

They didn’t want bodily entry to the gadgets, their PINs, or the Bitcoin community itself. The underlying Bitcoin protocol was not compromised.

Coinkite has launched corrected firmware, however an replace can not safe a seed phrase generated utilizing a weak model. Affected customers should create a completely new seed and switch their Bitcoin to addresses derived from it.

The Coldcard hack is particularly damaging to Canadian bitcoiners. Our evaluation of attackers and victims finds that BTC holders in Canada are bearing 25% of attributable losses.

With estimates ranging as excessive as $110M, in accordance with Galaxy Analysis’s dataset, we analyzed the… pic.twitter.com/AyxfHCcOrY

— Chainalysis (@chainalysis) August 4, 2026

US investigators monitor flagged addresses

Galaxy beforehand mentioned it shared confirmed attacker and sufferer addresses with US regulation enforcement companies, exchanges and cyber-investigation teams. The increasing tackle listing may assist authorities establish stolen funds when attackers try to make use of regulated providers.

Nonetheless, recovering the Bitcoin stays unsure. An attacker might transfer funds via a number of addresses, mixers, decentralized platforms or providers exterior US jurisdiction earlier than making an attempt to transform them.

The newest mixer exercise offers investigators a brand new transaction path to comply with, whereas the 1,159 BTC held by the most important recognized attacker stays uncovered to steady public monitoring.

ad
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

White House Now Reviewing Crypto Clarity Act

August 5, 2026

Solana ETF flows stayed at zero for five sessions

August 5, 2026

Senator Lummis Still Pushing for CLARITY Vote Before August Recess

August 5, 2026

CLARITY Act misses cloture as bipartisan talks drag on

August 5, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
Coldcard attacker holds 1,159 BTC as mixing starts
August 5, 2026
Aug. 8 for U.S. users
August 5, 2026
White House Now Reviewing Crypto Clarity Act
August 5, 2026
Solana ETF flows stayed at zero for five sessions
August 5, 2026
Senator Lummis Still Pushing for CLARITY Vote Before August Recess
August 5, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.