BNB $592.59 +0.36%
XRP $1.02 -1.04%
ETH $1,916.88 +0.45%
BTC $64,921.56 +0.78%
BNB $592.59 +0.36%
XRP $1.02 -1.04%
ETH $1,916.88 +0.45%
BTC $64,921.56 +0.78%
BREAKING
Bitcoin News

Coldcard Hacker Moves 30 BTC as $130 Million Theft Enters New Phase

Coldcard Hacker Moves 30 BTC as $130 Million Theft Enters New Phase
Coldcard Hacker Moves 30 BTC as $130 Million Theft Enters New Phase

Community Trust ScoreVerified

81%
Real
Verified16 votes
Updated 4 hours ago

A wallet tied to the Coldcard hack just moved. On August 7, on-chain tracker Lookonchain caught a transfer of 30.185 BTC — roughly $1.94 million — sliding into a new address. First significant movement since the original theft. And nobody knows what comes next.

The total haul from the Coldcard breach sits at 2,055 BTC, currently worth around $130 million. The 30.185 BTC that moved is about 1.5% of that. Small fraction, big signal — or maybe not. It’s genuinely unclear whether the hacker is testing the waters before a larger cash-out, or just shuffling funds around for reasons nobody outside that wallet can see. On-chain analysts watching Lookonchain’s data say the transfer could be an early move toward liquidation, but that’s still speculation. No confirmed exchange deposit. No obvious laundering pattern confirmed yet.

The math is pretty stark: roughly 90% of the stolen bitcoin hasn’t moved at all.

Advertisement

How the Coldcard Breach Actually Worked

Coinkite, the Toronto-based company behind Coldcard hardware wallets, got hit hard by a firmware flaw that most users probably didn’t know existed. The vulnerability came down to how wallet seeds were generated. Instead of pulling from a hardware-backed true random number generator — the kind of entropy source you actually want when creating a cryptographic key — the affected firmware used a deterministic pseudo-random generator. Deterministic means predictable. Predictable means exploitable.

Galaxy Research dug into the attack history and found multiple waves. The first waves drained 1,596 BTC from around 7,300 addresses. A possible fourth wave pushed the total up to 2,055 BTC. The breach traces back to a vulnerability discovered in March 2021, which makes the long dormancy of these funds even stranger — years of sitting still, then a single transfer on August 7, 2026.

Coinkite has urged affected users to migrate their funds. The company’s position is straightforward: move assets out of compromised wallets, because the security flaw is real and documented.

Why Blockchain Transparency Cuts Both Ways

Here’s the uncomfortable part for the hacker. Bitcoin’s public ledger is basically a live feed. Every address, every transaction, every satoshi — visible to anyone running a node or using a block explorer. That’s great for analysts tracking stolen funds. It’s a serious problem for anyone trying to quietly convert $130 million in flagged bitcoin into something spendable.

The 30.185 BTC that moved on August 7 is already tagged. Exchanges with decent compliance programs — and most major ones have them now — flag incoming funds linked to known theft addresses. Converting that bitcoin to fiat or to another cryptocurrency without hitting a wall somewhere takes real effort. Mixers, chain-hopping, privacy coins — none of it is foolproof, and blockchain forensics firms have gotten a lot better at unwinding those trails.

So the hacker’s next move matters. A lot.

Most of the stolen BTC is still sitting in original wallets, which on-chain analysts have been watching for months. The inactivity had been notable on its own — $130 million parked and untouched suggested either extreme caution or some kind of longer-term strategy. Now that 1.5% of the funds shifted, the question is whether it’s a test run or a one-off.

Hardware wallet security has been a recurring problem across the industry. Coldcard’s breach isn’t the only case where firmware-level flaws created exploitable weaknesses, but the scale here — thousands of addresses drained across multiple attack waves — puts it in a different category. The fact that the vulnerability involved seed generation makes it particularly damaging. A compromised seed means the wallet was never really secure, even if the physical device looked fine sitting on a desk.

Coinkite’s response has focused on getting users to move funds and on pushing the importance of true random number generators for seed creation. Whether that guidance reached all affected users in time is a separate question, and probably one without a clean answer.

The 7,300 addresses identified by Galaxy Research represent real people — traders, long-term holders, people who bought a hardware wallet specifically because they wanted better security than a hot wallet. For most of them, the funds are gone. What happens to the remaining 2,025 BTC still sitting in those original addresses is now the live question.

Lookonchain is still watching. So is everyone else with a block explorer and a reason to care.

Frequently Asked Questions

How much Bitcoin did the Coldcard hacker transfer on August 7?

The hacker moved 30.185 BTC, valued at approximately $1.94 million, to a new address on August 7, per on-chain tracker Lookonchain.

What caused the Coldcard hardware wallet vulnerability?

A firmware flaw caused affected Coldcard devices to use a deterministic pseudo-random generator instead of a hardware-backed true random number generator for wallet seed creation, making seeds predictable and exploitable.

How much total Bitcoin was stolen in the Coldcard hack?

Galaxy Research identified at least 1,596 BTC drained across multiple attack waves from around 7,300 addresses, with a possible fourth wave pushing the total to 2,055 BTC — worth roughly $130 million.

Community Trust IndexModerate Confidence
81%
Real
Real81%19%Fake
16 community signals

Dan Saada

Dan Saada holds a Master of Finance from ISEG Business School (France). With years of experience covering digital assets, Dan specializes in cryptocurrency market analysis, blockchain technology, and decentralized finance.

Advertisement

Related Stories