Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin Chain SAFU CryptoTax DeFAI AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
Onchain Data, The Market's Most Honest Signal
onchain-bible.com
LATEST
Whale Balances Rose 47%, But They Were Net Sellers of $130K — Three Tokens That Debunk 'Rising Holdings = Bullish'  ·  Only 5 Out of 15 Need to Defect: What the Liquid Network's $320M Exploit Exposes About Multisig Assumptions  ·  Where Did the $116 Million Go? Three Anomalies On-Chain Forensics Found After the Coldcard Hack  ·  When Transactions Get Compressed Into One Proof: What Can On-Chain Analysts Still See on ZK-Rollups?  ·  $300 Million Locked Forever: Why 'Easy to Upgrade' and 'Secure' Pull in Opposite Directions for Proxy Contracts  ·  Circle Minted $5B in USDC in a Week — Does That Mean Buying Pressure Is Coming? The Correlation Data Says It's Not That Simple
news

Where Did the $116 Million Go? Three Anomalies On-Chain Forensics Found After the Coldcard Hack

30-Second Version · For the impatient
After $116M was stolen, on-chain forensics found the attacker barely laundered any of it — most of the funds are just sitting still, while someone left an on-chain message offering to launder it for a 7% cut.

Full Explanation +
01 · Why did this happen?

Does the attacker "barely laundering anything" mean this stolen money is easier to recover?

This is an easy misconception to fall into, and it needs to be split into two layers. Funds sitting concentrated and unlayered genuinely makes it easier for On-Chain Analytics firms to keep tracing where the money is — that's exactly why TRM Labs has been able to draw a relatively clear picture of the fund flows, rather than rapidly losing the trail the way analysts typically do when facing a professional group that launders aggressively. From a pure traceability standpoint, these funds really are more transparent than money that gets rapidly layered and washed clean.

But traceable doesn't mean recoverable. Even if analytics firms can clearly see which addresses the stolen funds are sitting in, law enforcement has no real lever to freeze or seize those assets unless the attacker actively moves the funds into a regulated exchange or service (a centralized platform requiring KYC identity verification, for example) — Bitcoin itself has no centralized freeze mechanism. The funds staying put is, in a sense, the attacker running a wait-and-see strategy: the money can be seen, but as long as it never touches a service Node with the power to freeze assets, it can stay in a permanent state of "visible but unreachable."

02 · What is the mechanism?

If the attacker never touched any physical device, how can an ordinary user determine whether their old seed was genuinely generated on the affected firmware version?

The most direct way is to check which firmware version was installed on your Coldcard device when the seed was originally generated, and whether that generation date falls within the window between March 2021 and when the official patched firmware was released. Most hardware wallets keep firmware version and update history in the device's settings menu or the official companion app, which you can look back through. If you can't find a clear record, or aren't certain of the exact version at the time your seed was generated, the general official recommendation is to take the conservative approach of treating it as affected regardless — the cost of generating a new seed and migrating assets is far lower than the risk of continuing to use a potentially compromised seed based on a mistaken assumption that "it's probably fine."

Beyond that, if you set up an independent BIP-39 passphrase (effectively a "25th word") on top of the original 24-word seed, then even if the seed's own randomness was weakened, an attacker reconstructing the seed alone wouldn't be enough to access your assets — they'd still be missing that additional passphrase. That's also why some security researchers have emphasized after the fact that users who employed a passphrase faced significantly lower actual exposure, even if their seed was technically affected by this vulnerability.

03 · How does it affect me?

How does the "OP_RETURN money-laundering solicitation message" TRM mentioned technically work? Can anyone send this kind of message to an attacker's address?

OP_RETURN is a special opcode in the Bitcoin protocol that lets a user embed up to 80 bytes of arbitrary data within a transaction. This data isn't treated as spendable value — it's purely used as a message carrier, with common legitimate uses including timestamp proofs and asset issuance markers. Technically, anyone can initiate a transaction encoding whatever text they want into the OP_RETURN field and send that transaction to an address the attacker controls (even sending only a trivial amount of bitcoin, or close to zero). As long as that transaction gets mined into a Block, the message content stays permanently on-chain, readable by anyone — including the attacker themselves — via a Block Explorer.

That's exactly why a message like "soliciting money-laundering services to the attacker" can exist: as long as you know the attacker's address (which is public information, findable by anyone), any third party can leave them a message on-chain for free, anonymously, without needing the attacker's consent or any intermediary channel. This mechanism has no built-in identity verification, so who left the message and what their actual motive was can never be confirmed purely from on-chain data alone.

04 · What should I do?

I don't use Coldcard, but does this incident offer any practical takeaway for people using hardware wallets from other brands?

Yes — the core issue this incident exposed isn't "Coldcard the brand is unsafe," it's that "the quality of random number generation sets the ceiling for how secure an entire Seed Phrase can be" — a principle that applies to every Hardware Wallet, regardless of brand. Most users evaluating whether a hardware wallet is trustworthy tend to look at things like "is it open source," "has it been audited," and "is storage offline" — but this incident's vulnerability was hiding inside a product that satisfied all of those criteria. Coldcard's core design philosophy has long been considered an industry benchmark, and its code is publicly available; the problem was a build configuration error in one specific firmware version that accidentally routed a process meant to use hardware-based randomness through a software simulator instead.

For users of other brands, practical takeaways include: periodically checking whether the manufacturer of your device has issued security advisories, especially anything touching "seed generation" or "random number generation" at the low-level firmware layer; and if your device supports the BIP-39 passphrase feature, setting one up even if the manufacturer has never disclosed a similar flaw — an extra passphrase provides another layer of defense, so that even if the seed itself is somehow reconstructed, that alone still isn't enough to access the assets. This habit isn't specific to any one manufacturer's vulnerability — it's a defense-in-depth practice that applies to every hardware wallet.

Full Content +

The Coldcard Hardware Wallet firmware vulnerability that rocked the Bitcoin community in early August has seen its total loss figure repeatedly revised upward as On-Chain Analytics firms Galaxy Research and TRM Labs continued tracing it — as of August 5, following the fourth wave of attacks, the total stood at roughly 1,816 BTC, worth close to $116 million, affecting over 5,200 addresses, making it the third-largest crypto hack of 2026 so far. But more revealing than the dollar figure itself is where that money actually went after being stolen — TRM Labs' forensic analysis of the stolen funds surfaced three unusual signals.

Signal One: The Stolen Funds Show Almost No Laundering Layering

Most sophisticated hacking groups (like North Korea-linked TraderTraitor) typically begin aggressive laundering within hours to days of a successful theft — rapidly splitting funds, moving across chains, and routing through mixers to break the trail. But TRM Labs' analysis found that the vast majority of the Coldcard funds remain concentrated at a small number of attacker-controlled addresses, with movement limited to a single additional hop of consolidation from the original receiving address — no signs of layering or mixing. The only documented laundering activity so far is a single 64.9 BTC deposit into Wasabi Wallet (a privacy-focused mixing protocol) and a 200 ETH deposit into Tornado Cash on August 4. This mostly sitting still pattern led TRM to conclude the attacker may still be figuring out how to move a sum large enough to attract attention, rather than being a seasoned professional laundering operation working from a pre-established playbook.

Signal Two: Differences in Transaction Construction Suggest Possibly More Than One Attacker

The incident unfolded across four waves — starting with the first wave on July 30 (roughly 594 BTC drained from about 500 dormant addresses within 25 minutes), through a fourth wave in early August that kept pushing the cumulative total upward. TRM observed differences in how transactions were specifically constructed between waves, hinting that more than one attacker might be exploiting the same vulnerability. Since the blockchain itself doesn't directly reveal whether separate sweeps were coordinated by the same party, TRM's report explicitly states it isn't attributing this incident to a specific hacking group at this stage — a notable contrast to the instinct, common after many major hacks, to rush toward speculating whether North Korea was behind it.

Signal Three: An On-Chain Message Openly Soliciting Money-Laundering Business

While analyzing the transaction data, TRM's team noticed that among the Bitcoin transactions the attacker received, the OP_RETURN field (a mechanism that lets arbitrary text messages be embedded within a transaction) was flooded with spam messages — one of which directly propositioned the attacker, offering money-laundering services for a 7% fee. Whether this message was a genuine offer to help launder funds or an attempt to scam the hackers themselves in return can't currently be confirmed, but the phenomenon itself makes one thing clear: once a stolen sum is large enough and publicly visible on-chain, it immediately draws attention from all corners — including other opportunists looking to skim a cut for themselves.

What This Means for Your Money

The root cause of this incident traces to a firmware version Coldcard released in March 2021, which mistakenly routed the process that should have used a hardware random number generator to create wallet seeds through a predictable software-based generator instead, weakening effective key strength from a designed 128 bits down to as little as 40 bits on some affected devices — weak enough to be brute-forced with modern computing power, and without ever needing physical access to the device. If your seed was generated sometime between March 2021 and when the official patched firmware was released, that seed should be treated as compromised regardless of whether you've since updated your firmware — updating the firmware doesn't retroactively fix the security of an old seed; only generating a brand-new seed on the updated device and migrating your assets over will actually resolve the issue.

Sources: The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs, Bitcoin Owners Rocked by $116 Million Hack: What We Know About the Coldcard Exploit — Fortune, Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News
Ask a Question
Please enter at least 10 characters
Related Articles
When Transactions Get Compressed Into One Proof: What Can On-Chain Analysts Still See on ZK-Rollups?
advanced · Sep 03
$300 Million Locked Forever: Why 'Easy to Upgrade' and 'Secure' Pull in Opposite Directions for Proxy Contracts
smart-contracts · Sep 03
Circle Minted $5B in USDC in a Week — Does That Mean Buying Pressure Is Coming? The Correlation Data Says It's Not That Simple
data-analysis · Sep 03
MVRV and SOPR: Are You Only Watching One? The Full Picture Only Emerges When You Read Them Together
data-analysis · Aug 31
Related News
More Related Topics