The Coldcard exploit has shaken the crypto community this week with an estimated loss of $100 million in Bitcoin to users.
In a latest update, smart contract audit platform CertiK has flagged suspicious movements of funds linked to the incident, with two separate 200 ETH deposits into Tornado Cash detected on August 5, 2026. The activity centers on Ethereum address 0x41B7…3268, which received Bitcoin converted through THORChain before the proceeds were mixed.
The Coldcard incident involves a firmware vulnerability that produced low-entropy seed phrases on certain models, allowing attackers to drain Bitcoin from thousands of affected wallets.
THORChain Bridge and Tornado Cash Transfers
Most of the traced activity involves cross-chain bridging and subsequent mixing. Multiple Rapid Swap transactions on THORChain converted BTC into ETH and directed the output to the identified Ethereum address.
Data shared by CertiK show several of these swaps occurring within a short window roughly 16 to 19 hours before the alert. Individual transfers included amounts such as approximately 2 BTC converting to around 68 ETH, 1 BTC converting to roughly 34 ETH, and similar pairings totaling several hundred thousand dollars in value at prevailing rates. One smaller test-like swap of about 0.01 BTC also appeared in the same flow.
From the THORChain router contract, five transactions valued at approximately $382,800 flowed into the 0x41B7…3268 address, which functioned as an intermediate mixer deposit point.
Shortly afterward, two outbound transactions totaling about $374,000 moved from that address into a sanctioned Tornado Cash contract. The two 200 ETH deposits highlighted by CertiK form the core of this final leg, effectively consolidating and obfuscating the bridged proceeds.
The pattern—BTC drained from Coldcard-linked addresses, swapped via THORChain’s decentralized liquidity network into ETH, briefly held at a single intermediary, then deposited into Tornado Cash—matches classic post-theft laundering steps.
Tornado Cash remains under sanctions, yet continues to receive significant volumes. On-chain diagrams released alongside the alert illustrate the clean progression: THORChain router to the intermediate address to the Tornado Cash deposit contract.
The address itself showed limited prior activity outside these inflows, reinforcing its role as a temporary collection point rather than a long-term holding wallet. As the Coldcard exploit continues, further bridging and mixing of this type are expected while attackers attempt to obscure the origin of the stolen Bitcoin.
This is a developing story and more information will be added as the event unfolds.
Also read: Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis
