

Stolen Bitcoin linked to the Coldcard wallet vulnerability has started moving through a mixer, although the largest known attacker still holds about 1,159 BTC. Investigators have detected no movement from seven addresses controlling that balance. A separate attacker appears to be obscuring roughly 64 BTC through Wasabi Wallet.
Galaxy Research linked the largest theft to 1,159 BTC held across seven attacker-controlled addresses. The attacker consolidated the funds after stealing them within about 41 minutes. Since then, the seven addresses have not sent Bitcoin to exchanges, mixers, or other identifiable services. The funds remain spendable because Bitcoin’s protocol cannot freeze flagged addresses.
Still, converting such a large balance could expose the attacker. Exchanges, law enforcement agencies, and blockchain analytics firms reportedly track about 600 addresses tied to the wider exploit.
Analysts identified another attacker attempting to obscure approximately 64 BTC. Around 10 BTC entered an initial mixing transaction, while about 54 BTC returned as change. The remaining Bitcoin later moved into outputs of roughly 7 BTC each, apparently for further mixing. The activity involved Wasabi Wallet, which uses CoinJoin transactions.
CoinJoin combines multiple inputs and outputs, making direct links harder to establish. However, timing, output sizes, later consolidations, and exchange deposits can still reveal useful patterns.
Can attackers convert such a large flagged balance without exposing their route? A regulated exchange could trigger anti-money-laundering checks and requests for account information.
Investigators consider the mixing activity separate from the seven-address cluster. Earlier findings suggested that several attackers exploited the same Coldcard weakness across different waves.
Galaxy Research estimated confirmed losses near 1,596 BTC. A suspected additional wave could raise the total to about 2,055 BTC, while other researchers placed losses above 1,800 BTC. The flaw affected seed phrases created with weakened random-number generation. Firmware updates prevent new vulnerable seeds, but they cannot repair seed phrases already exposed.
Affected users must create a new wallet seed and move their Bitcoin. Coldcard also destroyed remaining vulnerable inventory and urged users to generate fresh seeds.
South Korea’s Bitcoin community reported virtually no direct losses despite many experienced holders owning Coldcard devices. Analyst Koji Higashi linked that outcome to local self-custody practices. Community leaders had promoted independent entropy generation instead of relying on one device maker. Users often rolled dice or flipped coins before deriving BIP39 seed phrases offline.
Local guides described 128 coin flips for 12-word seeds and 256 flips for 24-word seeds. Some users converted binary results with hardware calculators rather than phones.
Also Read: Coldcard Flaw Linked to $70M Bitcoin Theft Across 1,196 Addresses
Most stolen Bitcoin linked to the Coldcard exploit remains unmoved, while a separate attacker has begun using CoinJoin. Investigators continue tracking flagged addresses. Users with affected seeds must create new wallets and transfer funds because firmware updates cannot secure compromised seed phrases.