The Coldcard hackers are cashing out. One week after the biggest hardware wallet exploit in crypto history, the stolen coins have started moving. Roughly 64 BTC, worth $4.17 million, and 200 ETH, worth around $380,000, flowed into cryptocurrency mixing protocols this week, according to blockchain security firm CertiK.
We covered the initial breach in our Coldcard wallet hack breakdown, back when the damage looked like $38 million. That number aged badly. Fast. Today, the estimated losses sit closer to $130 million, and the laundering phase has officially begun.
Let’s follow the money.
Coldcard Hackers Turn to Wasabi and Tornado Cash
On Tuesday, one attacker address pushed 64 BTC into the mixing protocol Wasabi. A day later, 200 ETH landed in Tornado Cash. For beginners: mixers pool coins from thousands of users, scramble them, and spit them out with no visible link between sender and receiver. Once funds pass through, recovery odds drop close to zero.
Here’s the darkly ironic part. Wasabi is also the software many Coldcard victims use to watch their Bitcoin balances. The same tool that showed people their life savings vanishing is now helping the thieves wash the proceeds.
Interestingly, CertiK believes this particular launderer is one of the smaller players. A spokesperson told Cointelegraph the firm suspects several copycats piled in after the initial exploit. In other words, this wasn’t one genius hacker. It was a feeding frenzy.
Most of the Stolen Bitcoin Hasn’t Moved
Surprisingly, the bulk of the loot is still sitting in plain sight. Blockchain intelligence firm TRM Labs reported Thursday that most victim funds remain pooled in a handful of attacker-controlled addresses, with only limited mixing attempts so far.
Their analysis also confirmed something unsettling. Differences in how the transactions were constructed across each attack wave point to multiple attackers, which lines up with Galaxy Digital’s earlier finding of at least 15 separate exploiters.
The scoreboard so far:
- At least $100 million in Bitcoin drained across three confirmed attack waves, from roughly 7,300 victim wallets
- A suspected fourth wave that could push total losses to about $130 million
- The third-largest crypto hack of 2026, and it’s still growing
Every one of those 7,300 wallets belonged to someone who did what the industry told them to do. Which brings us to the hardest part of this story.
One Victim’s Story: $1.6 Million Gone in Seven Minutes
Jonathan Goodman, a well-known fitness entrepreneur, shared his experience on X. His post is worth reading in full, because it captures exactly why this hack cuts so deep.
Goodman held 18.25 BTC, worth just over $1.6 million CAD. His Coldcard never touched the internet. His seed phrase never left his possession. The device itself sat in a safety deposit box at a bank. By every rule the crypto community preaches, his setup was bulletproof.
Then he heard about the hack while relaxing at his cottage. His first thought: no way this affects me. He opened his watch-only wallet to check anyway. Red withdrawal transactions filled the screen. Between 9:36pm and 9:43pm on July 29, every single wallet he owned was emptied. Seven minutes, and a fortune built over years was gone.
He’s filing a police report and a complaint with the Ontario Securities Commission, though he admits he doesn’t expect to see the coins again. Still, his closing line stuck with me: “Mark my damn words. I’ll recover.”
That’s the brutal reality of this exploit. The victims weren’t careless. A firmware flaw from 2021 quietly undermined everything they did right.
Two Dollars of AI Could Have Prevented It
Quick recap for anyone catching up. TRM Labs confirmed that a firmware bug from March 2021 weakened seed generation on some Coldcard devices, cutting key strength from 128 bits down to 40 bits. That made the seeds brute-forceable without ever touching the physical device.
Now for the twist of the knife. Dragonfly managing partner Haseeb Qureshi wrote that roughly “$2 of AI hardening” could have prevented the entire exploit, pointing to reports that some AI models rediscovered the vulnerability in under 20 minutes.
Twenty minutes. A bug that hid from human reviewers for five years, and a machine finds it before your coffee gets cold. We flagged this exact dynamic in our first article: AI is now auditing every piece of open-source crypto code ever written, and not everyone running those audits wears a white hat.
Support Our Work
If you found this helpful, consider signing up on OKX or Bybit using our referral links. Your support keeps this content free and flowing.
My Take: Why I Point Newcomers to Exchanges Now
Recently, I’ve been giving newcomers advice that would have gotten me laughed out of the room a few years ago: leave your crypto on a trusted centralized exchange instead of rushing into self-custody. This hack shows exactly why. Self-custody carries hidden risks that no amount of personal discipline can fix. You can guard your seed phrase perfectly and still lose everything to one flawed line of firmware code written years before you bought the device.
To be clear, self-custody still has its place, and we weighed both sides honestly in our self-custody versus exchange guide. For experienced holders with passphrases, multisig, and fresh seeds, cold storage remains powerful. However, the “not your keys, not your coins” mantra was always sold as risk-free, and it never was.
On a personal note, Goodman’s story genuinely hurts to read. I’ve done exactly what he did. Plenty of times over the years, I kept a hardware wallet locked in a bank safe, deliberately out of my own reach. Partly to protect the coins from me and my own impulsive trading fingers, partly as protection against wrench attacks. Some of those wallets sat untouched for years. I can’t imagine opening a watch wallet on a quiet evening and seeing all of it drained. The safe protected the device perfectly. Nobody told us the device itself could be the flaw.
If you’re wondering how the other big manufacturer stacks up after all this, we dug into that question in our Ledger safety review.
Final Words
The Coldcard hackers have moved from stealing to laundering, and the window for recovery is closing with every mixer deposit. Meanwhile, the victim count keeps climbing, the attacker count sits at fifteen or more, and a suspected fourth wave hangs over the whole mess.
The lesson isn’t that hardware wallets are dead. The lesson is that “unhackable” was always marketing. Spread your risk across setups, add a passphrase, consider multisig, and stop treating any single device, seed, or platform as untouchable. The people who lost millions last week followed the rules perfectly. Respect that, learn from it, and build your storage strategy like the rules can fail.
See you next time!
As always, don’t forget to claim your bonus on OKX below. See you next time!
FAQ
How much did the Coldcard hackers send to mixers?
About 64 BTC (roughly $4.17 million) went to Wasabi, and 200 ETH (around $380,000) went to Tornado Cash, according to CertiK. Most stolen funds remain in attacker-controlled wallets for now.
How big are the total Coldcard hack losses?
Galaxy Digital confirmed at least $100 million drained across three attack waves from about 7,300 wallets. A suspected fourth wave could push the total near $130 million.
How many attackers exploited the Coldcard vulnerability?
At least 15 different attackers, according to Galaxy Digital. TRM Labs backed this up, noting the transaction construction differed between attack waves.
Can victims recover their stolen Bitcoin?
Recovery looks unlikely. Funds that pass through mixers like Wasabi or Tornado Cash become extremely difficult to trace. Victims like Jonathan Goodman are filing police and regulatory reports, but expectations remain low.
Should I move my crypto to an exchange after this hack?
It depends on your experience level. Newcomers may find a trusted major exchange safer than DIY cold storage. Experienced holders should use fresh seeds, passphrases, and multisig, and never rely on a single point of failure.
Morten Christensen
Crypto class of ’13, airdrop farmer since 2016. Avid trader and DeFi veteran. His market commentary has been featured by Bloomberg, The Wall Street Journal, The New York Times, Forbes, and CNN.
Credit: Source link



















