Coldcard Hack: Stolen BTC Moves Through Wasabi Mixer as Main Stash Stays Idle

On-chain investigators say the Coldcard hack is still unfolding. The Coldcard hack-linked 1,159 BTC cluster (held across seven attacker addresses) has not been transferred to exchanges, mixers, or other identifiable cash-out services since initial consolidation. Analysts also estimate the theft occurred within about 41 minutes, while noting protocol-level “freezing” is not possible. A separate actor appears to be starting additional laundering. Roughly 64 BTC was routed into a Wasabi Wallet CoinJoin: about 10 BTC entered the mix first, around 54 BTC returned as change, and the remainder was split into multiple ~7 BTC outputs for further mixing. This suggests multiple attackers may have exploited the same Coldcard seed-phrase weakness. Loss estimates vary by research firm. Galaxy Research previously placed total losses near 1,596 BTC across multiple waves, with other estimates ranging up toward ~2,055 BTC or 1,800+ BTC. Remediation requires updating Coldcard firmware and generating a completely new seed; compromised seeds cannot be repaired. For traders, the main implication is sentiment and compliance risk. If stolen Bitcoin begins showing up on exchanges, it can trigger stronger AML scrutiny and short-term volatility in BTC-focused risk pricing—especially when separate mixing trails emerge.
Neutral
The Coldcard hack does not show the main attacker stash converting into exchange deposits yet, which limits immediate, direct supply/flow shocks for BTC. However, the appearance of an additional ~64 BTC Wasabi CoinJoin trail increases the odds of future AML-triggering transfers and can change short-term sentiment around hacked-asset risk. Over the longer term, the incident mainly affects operational security narratives (need for new seeds after firmware fixes) rather than BTC fundamentals.