Halil, the clean split is this: Coldcard is a key-integrity incident; Verus is a bridge-accounting incident. Treat them differently.
For Coldcard, the source pack alleges about 1,367 BTC / ~$88.6M tied to a March 2021 seed-randomness flaw affecting 4,585 addresses, and BleepingComputer describes an RNG integration error where deterministic fallback behavior made some seeds guessable offline. My 24-hour call: custodians and users should treat affected seeds as burned, not repaired by firmware update. Move any remaining funds generated on affected COLDCARD Mk3 firmware to freshly generated wallets using trusted entropy. But for exchanges: do not taint “Coldcard coins” broadly. Taint should attach only to the confirmed attacker sweep transactions, their direct outputs, and provable downstream peel-chain descendants. Owner-initiated migration from a vulnerable wallet to a clean wallet is risk containment, not laundering by default.
For exchanges and investigators, use the larger 4,585-address / 1,367 BTC perimeter for monitoring and customer warnings, but keep enforcement freezes narrower: freeze or hold deposits only where the UTXO lineage touches confirmed sweep clusters. Public reporting does not establish a full address list, exchange deposit hits, mixer usage, or an attributed actor, so I would not support sanctions-style labeling, broad exchange blocks, or claims about final laundering destination yet. Preserve account KYC, IP/device metadata, withdrawal destinations, and any attempt to consolidate matching-fee sweep outputs.
For Verus, the call is stricter on bridge assets but narrower on native assets. The reported loss is around $7.44M through a Verus Ethereum bridge notarization/deserialization mismatch. Related Verus bridge reporting has described forged cross-chain import payloads and unbacked payouts. So: pause Verus Ethereum bridge operations and quarantine bridge-origin deposits until Verus publishes canonical exploit txs, fixed validation logic, and a reconciled asset state. But do not taint all ETH, USDC, USDT, tBTC, VRSC, or every wallet that ever used Verus. Taint only the exploit transaction proceeds, attacker-controlled recipient wallets, swaps/conversions from those proceeds, and directly traceable descendants. If USDC/USDT are in the confirmed exploit path, issuer-freeze escalation is time-sensitive.
The evidence is still too thin in two places: Coldcard lacks public wallet/tx granularity, and Verus has inconsistent public loss figures across related bridge incidents. Operationally, monitor the broader perimeter; legally and compliance-wise, freeze only lineage-confirmed funds.