64.9 BTC were sent into Wasabi, and 200 ETH were sent into Tornado. Coldcard ended up among the stolen-funds pool—mixing at last has moved.
Key figures are shown in the cover and in the正文 配图.
【What the topic is about】
Blockchain security monitoring indicates that, among the funds related to the Coldcard hardware wallet vulnerability, about 64 to 64.9 BTC were transferred into the Wasabi mixing protocol, and about 200 ETH were transferred into Tornado Cash. In public accounts, this BTC mixing took place around August 5, while the ETH mixing fell within the August 4–5 window.
Based on rough prices at the time, this batch of BTC was on the order of a few million (around $4 million-plus), while the ETH was on the order of a few hundred thousand (around $300k-plus). Compared with the total cumulative loss in the hundreds of millions, this looks more like a probing shipment than a main-boot load clean-out.
【First, set the event’s foundation straight】
The attack began around July 30, 2026. Public post-mortems point to a firmware construction problem in Coinkite Coldcard around March 2021. Seed generation landed in an underpowered software pseudo-random number generator: the effective entropy fell from the designed 128 bits down to roughly the 40-bit range of older devices, making remote brute-force attacks feasible—without needing to touch your physical machine.
According to Galaxy Research and TRM Labs, repeated sweeps cumulatively hit about 1,816 BTC, totaling roughly $116 million, across more than 5,200 addresses. Other reporting puts the totals across three to four waves in the $100–130 million range. Transaction construction differs between rounds. Industry-side reporting suggests multiple people were involved, and even imitators; CertiK has also publicly mentioned the possibility of small-scale users and copycats.
【What mixing implies】
Mixing protocols pool users’ funds together, cutting the public on-chain linkage between sending addresses and receiving addresses. The difficulty of tracing and labeling increases.
TRM’s public description is especially striking. Most of the victim funds still concentrate in a small number of addresses controlled by the attackers; mixing attempts so far appear limited. The main named instance is the ~64.9 BTC sent into Wasabi, plus the 200 ETH sent into Tornado. CertiK interprets the related transfers as actions by smaller users. Whether the main attacker has already laundered on a large scale remains unsupported by the available public materials.
【How to read this for the market and users】
For market conditions: this mixed batch is small relative to BTC’s daily trading volume, more like noise from a security narrative. In the short term, don’t write it directly as the main cause of a sell-off.
For holders: updating firmware only protects seeds generated in the future. Seeds generated by old firmware can’t be covered by a patch. Public guidance is to generate brand-new seeds on the already-fixed firmware, then move funds. Multi-sig, sufficiently independent dice-entropy sources, and strong BIP-39 passphrases are discussed separately in the public post-mortems.
For the narrative: hardware wallets are not immune. Cold storage still depends on how the seed is generated—where the entropy comes from—and whether there is a second layer of protection.
【Observation checklist】
Watch three things. First, whether the main-archive addresses continue to batch-transfer into Wasabi or similar protocols. Second, whether downstream addresses show fast CEX deposit traces after mixing. Third, whether the vendor and subsequent chain security actions further tighten the scope of the victim-address list and the firmware impact surface.
Expiration reminder: don’t only focus on the 64.9 BTC mixing activity and ignore the fact that over a thousand BTC are still sitting on attacker addresses—otherwise you’ll underestimate the uncertainty around future sell pressure and the enforcement window.
Do you think this is a small crew’s trial run, or the prelude to a large-scale mixing wave?
Not investment advice.
Dragonfly Captain|A finance blogger who likes analyzing data and candlestick charts.
Welcome to follow, like, and save.
#Coldcard #混币协议 #链上安全 #hardware wallet