Firmware vulnerability from 2021 enabled theft across 7,300 wallets

Hackers exploited a Coldcard firmware vulnerability to drain cryptocurrency from 7,300 victim wallets, transferring portions of the stolen funds to cryptocurrency mixing protocols Wasabi and Tornado Cash on Tuesday and Wednesday respectively, according to analysis by blockchain security firms.

On Tuesday, 64 Bitcoin worth $4.17 million was transferred from address bc1q0 to Wasabi. On Wednesday, 200 Ether valued at $380,000 moved to Tornado Cash. The transfers represent a fraction of total losses, with most stolen funds remaining pooled in attacker-controlled addresses that saw limited mixing attempts.

The exploit stems from a firmware bug introduced in March 2021 that weakened seed randomness on Coldcard wallets, reducing key strength to 40 bits from 128 bits. TRM Labs, a blockchain intelligence company, described the weakened randomness as “brute-forceable without physical access.”

Minimum confirmed losses across three attack waves total $100 million in Bitcoin. Estimated total losses including a suspected fourth wave reach $130 million, making this the third-largest cryptocurrency hack in 2026.

Multiple attackers identified in transaction analysis

Galaxy Digital, a cryptocurrency analysis firm, identified at least 15 different attackers based on transaction construction differences during each attack wave. However, a CertiK spokesperson offered a different assessment: “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit.”

Crypto mixing protocols pool and scramble cryptocurrency from multiple users, breaking the publicly traceable onchain link between senders and recipients. The limited mixing activity across most victim funds suggests attackers may have prioritized speed over laundering sophistication.

Prevention cost estimated at $2

Haseeb Qureshi, managing partner at Dragonfly, a cryptocurrency investment firm, criticized the exploit’s preventability. “Roughly $2 of AI hardening could have prevented the Coldcard exploit,” Qureshi said.

The breach draws parallels to prior mixing activity tied to major hacks. In April, attackers laundered 75,700 Ether worth $175 million through THORChain following the $293 million Kelp DAO hack. That laundering generated $910,000 in fee revenue for the THORChain protocol.