Blockchain security researchers have tracked significant movements of stolen cryptocurrency from two major breaches—the TripleA payment gateway hack and the Coldcard wallet exploit—into privacy mixing protocols, complicating recovery efforts and raising fresh concerns over illicit crypto flows.
On August 6, 2026, a wallet linked to the hacker behind the July 25 breach of Singapore-based payment processor TripleA transferred 2,620 Ethereum (ETH), worth roughly $4.97 million, into Tornado Cash, according to PeckShield. The transfer represents nearly half of the estimated $10 million in digital assets stolen during the attack, which exploited vulnerabilities in the firm’s infrastructure. Tornado Cash, a decentralized Ethereum mixing service, obscures on-chain links by pooling and shuffling deposits, making it a frequent tool for laundering stolen funds despite its legitimate privacy applications.
In a separate incident, funds stolen from the Coldcard wallet exploit—which drained at least $100 million in Bitcoin (BTC) from over 7,300 victims—have also begun moving through mixers. On August 5, about 64 Bitcoin ($4.17 million) from an address beginning with bc1q0 was sent to the Wasabi privacy protocol. A day later, another portion was converted into approximately 200 Ether via THORChain and forwarded to Tornado Cash, valued at around $380,000. These amounts represent a small fraction of the total Coldcard losses, with most stolen Bitcoin still concentrated in a limited number of attacker-controlled addresses.
Security analysts believe the Coldcard exploit may involve multiple attackers or copycats, as transaction construction varied across at least three confirmed attack waves. The vulnerability stemmed from a 2021 firmware bug that weakened seed phrase randomness, effectively reducing private key strength to just 40 bits—making brute-force key recovery feasible without physical access. Dragonfly managing partner Haseeb Qureshi noted that AI-assisted security testing could have rediscovered the flaw in under 20 minutes, highlighting gaps in wallet hardening.
The use of mixers in both cases mirrors a growing trend observed by blockchain investigators, where hackers leverage privacy protocols to evade traceability. While analytics firms like PeckShield continue to monitor these movements, the involvement of Tornado Cash—previously sanctioned by U.S. authorities for laundering North Korean cybercrime proceeds—draws further regulatory scrutiny. For affected users, the incidents underscore the importance of robust key generation and cold storage; for the industry, they renew the debate over the balance between privacy and compliance in decentralized finance.