The Coldcard Hack Drained $116M. Here's Where It's Hiding.

By Alexandr Kerya · · 5 min read

TL;DR - Coinkite's Coldcard hack drained $116 million from over 5,200 Bitcoin addresses, and most of the stolen coins are still sitting untouched, waiting for wallet screening to catch them the moment they move.

Moving stolen bitcoin through Tornado Cash doesn't make it clean. It adds a mixer flag on top of a hack flag, and both stick to the coins wherever they land next.

Most coverage of the Coldcard hack stops at the firmware bug. This one covers what happens to the $116 million after the headlines fade, and what that means for anyone who ends up holding bitcoin that passed anywhere near it.

What happened in the $116 million Coldcard hack?

On July 30, 2026, attackers began draining bitcoin from Coinkite Coldcard hardware wallets. The first wave pulled roughly 594 BTC, worth about $38 million, from close to 500 addresses in 25 minutes. Three more waves followed over the next five days, and by August 4 the total reached 1,816 BTC, worth about $116 million, taken from more than 5,200 addresses.

No phishing link. No signed transaction. Just weak math.

Blockchain analytics firm TRM Labs called it the third-largest crypto hack of 2026, pushing the year's stolen total past $1.2 billion across 276 incidents.

Timeline of the Coldcard hack: July 30, 2026 first wave drains 594 BTC (about $38 million) from roughly 500 addresses in 25 minutes; by August 4, 2026 the total reaches 1,816 BTC (about $116 million) from over 5,200 addresses.
Four waves in five days took the running total from $38 million to $116 million.

Why did a five-year-old firmware bug make bitcoin keys brute-forceable?

Coinkite shipped firmware version 4.0.1 in March 2021 with a build configuration error. Seed generation was routed to a software pseudorandom number generator instead of the device's STM32 hardware RNG. Effective key strength dropped from 128 bits to as little as 40 bits, weak enough to brute-force without ever touching the physical device.

The device was offline. The randomness wasn't.

Patching the firmware today does not fix a wallet whose seed was already generated under the flawed build between March 2021 and the fix. That wallet's private key is still guessable. Only a fresh seed on a patched device closes the hole.

Where did the stolen bitcoin go?

Mostly nowhere, so far. TRM Labs found the funds pooled at a small number of attacker-controlled addresses with little onward movement. As of August 4, 2026, one deposit of 64.9 BTC had gone into Wasabi Wallet's CoinJoin mixer, and around 200 ETH, converted from part of the haul, had moved through Tornado Cash. That's under 4 percent of the 1,816 BTC total.

TRM declined to name a specific group behind the attack. Differences in how the transactions were built suggest more than one actor, and the laundering pattern doesn't match the playbook North Korea's TraderTraitor group usually runs.

Bar chart showing disposition of the 1,816 BTC stolen in the Coldcard hack as of August 4, 2026: about 96 percent still sits at attacker-controlled consolidation addresses, while 64.9 BTC, about 3.6 percent, has moved into the Wasabi CoinJoin mixer.
As of August 4, 2026, roughly 96 percent of the stolen bitcoin was still sitting untouched.

Does moving stolen bitcoin through a mixer make it untraceable?

No. A CoinJoin round or a Tornado Cash pool breaks the accounting trail for a casual observer, not for a screening tool built to expect exactly that move. Coins that emerge from Wasabi or Tornado Cash carry mixer exposure the moment they land in the next address, on top of whatever hack-exploit tag the originating funds already had.

That double tag is the whole point of our Tornado Cash residue breakdown: a mixer hop doesn't erase history, it adds a second flag to the one already there.

How does wallet screening catch Coldcard-hack exposure?

Anyone can pull up an address's inbound transfers on a block explorer and manually check them against the small set of attacker addresses TRM has published, one transaction at a time. Screening a wallet with Plastron does that automatically, checking sanctions, mixer, and stolen-funds exposure across Ethereum and six other chains in one pass, the same categories covered in our hack-exposure walkthrough.

Plastron's dataset already tags 121 of its 3,901 labeled addresses as hack or exploit related, cross-checked against the full 780-address OFAC SDN list. A Coldcard-attacker address gets added the same way any other exploit wallet does, and any address downstream of it inherits the same exposure category.

What should Coldcard owners do right now?

Treat any seed generated on a Coldcard between March 2021 and the patched firmware as compromised, full stop, even if the device never left a locked drawer. Move the funds to a new seed on patched hardware. Don't reuse the old seed phrase anywhere, ever.

FAQ

Is Coldcard still safe to use?

Yes, for wallets generated on the patched firmware. The risk sits with seeds generated during the vulnerable window, March 2021 through the fix, regardless of how careful the owner was afterward.

How do I check if a bitcoin address is linked to the Coldcard hack?

Cross-reference it against the attacker addresses TRM Labs has published, or run it through a screening tool that already tags hack-and-exploit addresses and updates as new ones surface.

Can an exchange freeze bitcoin linked to the Coldcard hack?

Bitcoin has no issuer-level freeze switch the way USDC or USDT does. An exchange can only hold or reject a deposit at the account level, after its own screening flags the address.

Will the stolen bitcoin eventually all move through mixers?

Maybe, but as of August 4, 2026 it hadn't. Most of it still sat at the original consolidation addresses, which is the window a screening tool has to flag it before any laundering starts.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

How to Audit Your Wallet for Tornado Cash Residue Before Sending to CEXDid Your Wallet Receive Funds From the Bybit Hack? How to CheckWhat Happens If Your Wallet Touched a $292M Hacked Bridge?Why Didn't Circle Freeze $232M in Stolen USDC After the Drift Hack?