Most of the Bitcoin stolen through a vulnerability in COLDCARD wallets remains unmoved, with 1,159 BTC held across seven addresses, while a separate attacker has started routing smaller amounts through a cryptocurrency mixer.
Galaxy Research identified the 1,159 BTC holding as the largest known theft linked to the flaw. The funds have remained in the seven addresses since the initial sweep and have not been sent to exchanges, mixers or other services commonly used to conceal the movement of stolen cryptocurrency.
On-chain monitoring cited by Bitcoin News indicates that the Bitcoin was taken within a 41-minute period. Although the addresses have been flagged by investigators, the assets are more accurately described as unmoved rather than frozen. Bitcoin transactions cannot be halted at protocol level simply because an address is suspected of holding stolen funds.
The attacker could nevertheless face significant obstacles when attempting to convert the Bitcoin into fiat currency or other assets. Law enforcement agencies, cryptocurrency exchanges and blockchain analytics companies have reportedly identified about 600 addresses linked to the wider theft.
A transfer to a compliant exchange could therefore activate transaction-monitoring systems and lead to requests for information about the account receiving the funds.
Separate blockchain activity points to another attacker trying to obscure part of the stolen Bitcoin. Analysts traced 64 BTC into a transaction pattern associated with a mixer. Around 10 BTC was mixed at the outset, while approximately 54 BTC was returned as change. That remaining amount was then split into outputs of roughly 7 BTC each for further mixing.
Mixers combine or restructure transactions in an attempt to make it more difficult to connect cryptocurrency with its original source and eventual destination. They do not, however, guarantee that the funds will become impossible to trace.
According to analysts, the relatively large outputs and their consistent size make this particular laundering attempt easier to monitor. Investigators can continue following the Bitcoin as it moves through further addresses.
The activity also appears unrelated to the seven-address cluster holding 1,159 BTC. Earlier reporting suggested that several attackers may have taken advantage of the same wallet weakness, meaning transactions from one group of addresses should not automatically be attributed to every COLDCARD theft.
Galaxy Research previously confirmed that attackers stole 1,596 BTC from about 7,300 addresses during three attack waves. It also found 14 smaller incidents connected to the same seed-generation flaw.
A suspected fourth wave could increase the total loss to about 2,055 BTC, although Galaxy had not confirmed those additional losses through enough victim reports.
The vulnerability was caused by a firmware error that weakened the randomness used to create wallet seed phrases. Attackers were able to reproduce possible seeds offline, derive the associated Bitcoin addresses and compare them with addresses visible on the blockchain.
They did not require physical access to the devices, the users’ PINs or the Bitcoin network itself. The underlying Bitcoin protocol was not compromised.
Coinkite has released corrected firmware, but installing the update does not protect a seed phrase created with a vulnerable version. Affected users must generate a completely new seed and move their Bitcoin to addresses derived from it.
Galaxy has previously said it provided confirmed attacker and victim addresses to US law enforcement agencies, exchanges and cyber-investigation groups. The growing list of linked addresses could help authorities identify stolen funds if attackers try to use regulated services.
Recovery remains uncertain. Funds could be moved through multiple addresses, mixers, decentralised platforms or services outside US jurisdiction before an attempt is made to convert them.
For investigators, the latest mixer activity provides a fresh transaction trail. Meanwhile, the 1,159 BTC held by the largest known attacker remains visible and subject to continuous public monitoring.
