Hackers Move Millions in Stolen Crypto Through Mixers After TripleA and Coldcard Exploits

2 hour ago 2 sources negative

Key takeaways:

  • Stolen ETH routed to Tornado Cash may precede liquidation, risking near-term Ether price pressure.
  • Coldcard's weak seed flaw undermines hardware wallet trust, favoring decentralized custody token adoption.
  • THORChain's utilization for laundering invites regulatory scrutiny, potentially weighing on RUNE's value.

Blockchain security researchers have tracked significant movements of stolen cryptocurrency from two major breaches—the TripleA payment gateway hack and the Coldcard wallet exploit—into privacy mixing protocols, complicating recovery efforts and raising fresh concerns over illicit crypto flows.

On August 6, 2026, a wallet linked to the hacker behind the July 25 breach of Singapore-based payment processor TripleA transferred 2,620 Ethereum (ETH), worth roughly $4.97 million, into Tornado Cash, according to PeckShield. The transfer represents nearly half of the estimated $10 million in digital assets stolen during the attack, which exploited vulnerabilities in the firm’s infrastructure. Tornado Cash, a decentralized Ethereum mixing service, obscures on-chain links by pooling and shuffling deposits, making it a frequent tool for laundering stolen funds despite its legitimate privacy applications.

In a separate incident, funds stolen from the Coldcard wallet exploit—which drained at least $100 million in Bitcoin (BTC) from over 7,300 victims—have also begun moving through mixers. On August 5, about 64 Bitcoin ($4.17 million) from an address beginning with bc1q0 was sent to the Wasabi privacy protocol. A day later, another portion was converted into approximately 200 Ether via THORChain and forwarded to Tornado Cash, valued at around $380,000. These amounts represent a small fraction of the total Coldcard losses, with most stolen Bitcoin still concentrated in a limited number of attacker-controlled addresses.

Security analysts believe the Coldcard exploit may involve multiple attackers or copycats, as transaction construction varied across at least three confirmed attack waves. The vulnerability stemmed from a 2021 firmware bug that weakened seed phrase randomness, effectively reducing private key strength to just 40 bits—making brute-force key recovery feasible without physical access. Dragonfly managing partner Haseeb Qureshi noted that AI-assisted security testing could have rediscovered the flaw in under 20 minutes, highlighting gaps in wallet hardening.

The use of mixers in both cases mirrors a growing trend observed by blockchain investigators, where hackers leverage privacy protocols to evade traceability. While analytics firms like PeckShield continue to monitor these movements, the involvement of Tornado Cash—previously sanctioned by U.S. authorities for laundering North Korean cybercrime proceeds—draws further regulatory scrutiny. For affected users, the incidents underscore the importance of robust key generation and cold storage; for the industry, they renew the debate over the balance between privacy and compliance in decentralized finance.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.