The Coldcard hack has entered its laundering phase. On August 4 and 5, whoever drained an estimated 1,816 to 2,055 BTC — worth roughly $116-130 million — from vulnerable hardware wallets sent a first slice of it, about 65 BTC and 200 ETH, through Wasabi CoinJoin and Tornado Cash. It's the first real movement since the theft came to light on July 30, and it raises the two questions every Coldcard owner actually cares about: is my device on the list, and if the money is being laundered, is it still traceable?

The short answers: laundering has started, but it's small and cautious so far, and it doesn't change much for the roughly 96% of stolen bitcoin still sitting untouched. Whether you personally are exposed is a separate, answerable question that has nothing to do with how the laundering unfolds.

Is your Coldcard wallet actually affected?

The root cause is a firmware bug, not a hack of Coldcard's servers or a compromised app. A flaw introduced in firmware version 4.0.1, shipped back in March 2021, quietly weakened the randomness Coldcard devices used to generate seed phrases. Mk2 and Mk3 devices on the affected firmware fell to roughly 40 bits of real entropy; Mk4, Mk5 and Q devices on pre-fix firmware fell to roughly 72 bits — both far short of the 128 bits a standard seed is supposed to carry. A seed that weak can be brute-forced offline, and attackers appear to have spent months to years doing exactly that before this summer's theft waves.

That means exposure depends on three things: which device you have, which firmware version generated your current seed, and whether you added a passphrase on top of it. Every current Coldcard model — Mk2, Mk3, Mk4, Mk5 and Q — is affected if it generated a seed on buggy pre-patch firmware; Mk4, Mk5 and Q are less severely weakened than Mk2 and Mk3, but none of them are exempt. If your seed was generated any time firmware 4.0.1 or a later buggy build was installed, before Coinkite's patch, the underlying key material may be weak even though the wallet itself looks and behaves normally today. A passphrase adds a second layer of entropy that isn't dependent on the device's flawed RNG, which is why passphrase users appear to have fared better across the reported thefts.

Critically, installing the patched firmware now does not fix an already-weak seed — the weakness lives in the private key itself, not in the software checking it. Coinkite has published the affected firmware ranges and migration guidance on its blog; if your device falls in that window, the only real fix is moving funds to a brand-new seed generated on patched firmware, not just updating and continuing to use the old one.

The Coldcard hack's bitcoin laundering trail so far

This wasn't one heist. At least 15 separate attackers, working independently and with varying levels of sophistication, exploited the entropy bug across four distinct waves starting July 30, hitting somewhere between 5,200 and 7,300-plus addresses. Galaxy Research and TRM Labs, the chain-analysis firms tracking the case, put the combined haul at 1,816-2,055 BTC, and the tally has kept creeping up as more victims discover their wallets were drained.

For the first week, none of it moved. Then, on August 4-5, one attacker sent 64.9 BTC into a Wasabi CoinJoin round — a coin-mixing protocol that blends many users' transactions to obscure the trail — and pushed 200 ETH through Tornado Cash, the Ethereum equivalent. The same address also swapped a portion of BTC into ETH via THORChain, a cross-chain swap protocol, which is a common way to break the on-chain link between two assets before mixing the proceeds further.

That's roughly 3-4% of the total haul. The remaining ~96% has stayed put in attacker-controlled wallets since the theft, untouched by mixers or exchanges.

Can the stolen funds still be traced or recovered?

The dormant majority is the more recoverable part of this story, not the moved slice. Chain-analysis firms can watch untouched addresses indefinitely; if any of those funds move toward a centralized exchange, compliance systems have a real chance to flag and freeze them before conversion to cash. That's the mechanism that has recovered stolen crypto in past cases — not clawing coins back after the fact, but catching them at the cash-out point.

The 65 BTC and 200 ETH that already went through Wasabi and Tornado Cash are a different story. Once coins are mixed, tracing them gets sharply harder, though not always impossible — pre-mix flows are already documented, and some mixed coins still get flagged by exchange compliance tooling if they resurface. But the realistic odds of full recovery on that portion drop fast the longer it stays inside a mixer, and Tornado Cash in particular tends to end the practical trail.

The pattern so far — a small test transaction, spread across two different mixing tools, from just one of at least 15 attackers — looks more like cautious probing than a coordinated mass cash-out. With multiple uncoordinated groups holding stolen funds, expect this to keep happening in small, staggered tranches rather than one decisive dump, which is itself a reason recovery odds for the dormant 96% could hold up better than a single dramatic headline might suggest.

What to do if you think you're at risk

If you own any Coldcard model — Mk2, Mk3, Mk4, Mk5 or Q — check Coinkite's published advisory for the exact affected firmware versions and generation dates before assuming you're fine. If your seed was generated during the vulnerable window and you didn't use a passphrase, the safest move is treating that seed as compromised: generate a new one on current, patched firmware, and move your funds to it rather than continuing to use the old wallet. A firmware update alone does not retroactively strengthen a seed that was already generated weak.

Sources