en

Coldcard attacker holds 1,159 BTC as mixing starts

image
rubric logo Security
hodl like 2

Most of the Bitcoin stolen through the COLDCARD wallet flaw remains unmoved, but on-chain investigators have detected a separate attacker beginning to route smaller amounts through a mixer.

COLDCARD attacker leaves 1,159 $BTC untouched

Galaxy Research said the largest known theft connected to the COLDCARD vulnerability involved 1,159 $BTC. The funds remain spread across seven addresses associated with the attacker and have not moved since the initial sweep.

COLDCARD ATTACKER MOVES FUNDS 👺

The Coldcard RNG exploit cluster received 1,159.42 $BTC (~$72.71M) from 870 exploited addresses.

The attacker moved 0.06 $BTC (~$3.78K) to a new address, while 1,159.35 $BTC (~$72.70M) remains across the 8 original attacker addresses.

Fresh… pic.twitter.com/mPGHa9Vnat

— Onchain Lens (@OnchainLens) August 1, 2026

The Bitcoin was stolen within 41 minutes, according to the latest on-chain monitoring cited by Bitcoin News. Investigators have not detected transfers from the seven addresses to exchanges, mixers or other services commonly used to obscure stolen funds.

The assets are therefore better described as unmoved rather than technically frozen. Bitcoin transactions cannot be stopped at the protocol level merely because an address has been flagged.

However, the attacker could face difficulties converting the funds into fiat or other assets. Law enforcement agencies, cryptocurrency exchanges and blockchain analytics companies have reportedly flagged about 600 addresses connected with the wider theft.

Any transfer to a compliant exchange could trigger transaction monitoring controls and requests for information about the account receiving the Bitcoin.

Smaller attacker begins mixing stolen Bitcoin

Separate on-chain activity suggests another attacker has started attempting to obscure part of the stolen funds.

Analysts tracked 64 $BTC entering a transaction flow linked to a mixer. Approximately 10 $BTC was initially mixed, while about 54 $BTC returned as change. The remaining funds were subsequently divided into outputs of roughly 7 $BTC each for further mixing.

UPDATE COLDCARD:
THE THIEF IS NOW MIXING HIS 64 $BTC

1. The funds were sent to that address:
bc1pynd6vswmxkghw6k5463xwcj7el7u4tpl2t2pnh0s8llmc2wgzfqsdu7h92

2. It was mixed in that strange transaction:
– 64 $BTC input
– and a 54 $BTC output… https://t.co/717BUz0gxm pic.twitter.com/GMzSkE3xrA

— Marius Off🔗Chain (@mariusoffchain) August 5, 2026

Mixers combine or restructure transactions to make it harder to connect the original source of cryptocurrency with its eventual destination. However, they do not guarantee that funds will become untraceable.

Analysts said the relatively large and consistently sized outputs make this laundering attempt easier to follow. Investigators can continue monitoring the transactions as the Bitcoin passes through additional addresses.

The activity also appears separate from the seven-address cluster holding 1,159 $BTC. Previous reporting found that multiple attackers may have exploited the same wallet weakness, meaning movements from one cluster should not automatically be attributed to every COLDCARD theft.

Galaxy previously tracked 1,596 stolen $BTC

As previously reported by crypto.news, Galaxy Research confirmed that attackers stole 1,596 $BTC from approximately 7,300 addresses across three attack waves. It also identified 14 smaller incidents connected to the same seed-generation flaw.

A suspected fourth wave could raise the total to approximately 2,055 $BTC, although Galaxy had not confirmed those additional losses through sufficient victim reports.

The vulnerability resulted from a firmware error that weakened the randomness used to generate wallet seed phrases. Attackers could reproduce possible seeds offline, derive their Bitcoin addresses, and compare them with addresses visible on the blockchain.

They did not need physical access to the devices, their PINs, or the Bitcoin network itself. The underlying Bitcoin protocol was not compromised.

Coinkite has released corrected firmware, but an update cannot secure a seed phrase generated using a vulnerable version. Affected users must create an entirely new seed and transfer their Bitcoin to addresses derived from it.

The Coldcard hack is especially damaging to Canadian bitcoiners. Our analysis of attackers and victims finds that $BTC holders in Canada are bearing 25% of attributable losses.

With estimates ranging as high as $110M, according to Galaxy Research’s dataset, we analyzed the… pic.twitter.com/AyxfHCcOrY

— Chainalysis (@chainalysis) August 4, 2026

US investigators monitor flagged addresses

Galaxy previously said it shared confirmed attacker and victim addresses with US law enforcement agencies, exchanges and cyber-investigation groups. The expanding address list could help authorities identify stolen funds when attackers attempt to use regulated services.

Still, recovering the Bitcoin remains uncertain. An attacker may move funds through several addresses, mixers, decentralized platforms or services outside US jurisdiction before attempting to convert them.

The latest mixer activity gives investigators a new transaction trail to follow, while the 1,159 $BTC held by the largest known attacker remains exposed to continuous public monitoring.