Attackers behind the $116 million Coldcard hardware wallet breach transferred 64 bitcoin and 200 ether to cryptocurrency mixers on August 4, according to blockchain intelligence firm TRM Labs. The transfers went to Wasabi and Tornado Cash, privacy-focused services used to obscure fund origins.
The Coldcard hack represents the largest single exploit of a hardware wallet in 2026. Victims stored private keys on the devices, which Coldcard manufactures as offline signing tools meant to isolate crypto holdings from internet-connected computers. The breach exposed the security model that has defined hardware wallet marketing for over a decade: the claim that air-gapped devices eliminate hacking risk.
The attackers hold approximately 1,159 bitcoin from the total haul, according to on-chain tracking. Hardware wallet breaches have historically centered on supply chain compromise, firmware flaws, or physical device tampering. Coldcard has not yet published a detailed post-mortem on the attack vector. The company released a firmware update in early August but did not specify whether the breach exploited a zero-day or a known vulnerability in its signing process.
TRM Labs' analysis shows the stolen funds moving into Wasabi, which operates a coin mixing service that breaks transaction history into smaller denominations, and Tornado Cash, a smart contract mixer on Ethereum. Both services have faced regulatory scrutiny. The U.S. Treasury designated Tornado Cash as a sanctions target in August 2022, citing its use in money laundering. Wasabi remains operational but has reduced anonymity guarantees following regulatory pressure.

The timing of the mixer transfers points to the attackers moving to obscure holdings before law enforcement or blockchain intelligence firms complete fund tracking. Galaxy Research and TRM Labs independently confirmed the $116 million total, up from earlier estimates of $71 million. On-chain data shows the attackers testing smaller transfers before moving major portions into mixing services, a pattern consistent with operational security testing.
Coldcard competes with Ledger, Trezor, and other hardware wallet makers. The company markets its devices on the premise that offline signing prevents remote theft. A $116 million breach will force the company to disclose the attack surface and demonstrate remediation to institutional and retail users who rely on hardware wallets to custody assets.
The scale of mixer inflows from a single breach event is unusual in crypto history. The $116 million total exceeds the 2022 Ronin bridge hack payout in mixing activity and ranks as one of the largest coordinated fund obscurement efforts in blockchain crime on record. If the attackers complete mixing without government interception, the funds become nearly impossible to trace on public blockchains.