BNB $582.40 -0.11%
XRP $1.07 -0.90%
ETH $1,855.51 -1.02%
BTC $62,697.13 -1.09%
BNB $582.40 -0.11%
XRP $1.07 -0.90%
ETH $1,855.51 -1.02%
BTC $62,697.13 -1.09%
BREAKING
Bitcoin News

ZachXBT Walks Away From $88.6M Coldcard Hack as Bitcoin Community Takes Heat

ZachXBT Walks Away From $88.6M Coldcard Hack as Bitcoin Community Takes Heat
ZachXBT Walks Away From $88.6M Coldcard Hack as Bitcoin Community Takes Heat

Community Trust ScoreVerified

88%
Real
Verified26 votes
Updated 1 hour ago

Blockchain investigator ZachXBT won’t touch the Coldcard case. He made it plain: his attention goes to ecosystems that actually value what he does, and Bitcoin’s community, at least right now, doesn’t clear that bar for him.

The hack itself has been running for five days. It started with a firmware flaw inside Coldcard Mk3 hardware wallets made by Coinkite. Specifically, devices running firmware versions 4.0.1 through 4.1.9 had a nasty problem — they generated wallet seeds through a software random-number process instead of the dedicated hardware chip. That made the seeds predictable. Guessable, basically. On July 30, roughly 594 BTC, worth about $38 million at the time, vanished from nearly 500 addresses in under 30 minutes. Coinkite pushed a patch out within two days. Didn’t matter much. By August 2, the total stolen had climbed to 1,367 BTC — $88.6 million — spread across three separate attack waves. The vulnerability, per reports, probably traces back to a firmware build from March 2021, which means wallet seeds generated since that date could still be exposed on unpatched devices.

Fast money. Three waves. Five days.

Advertisement

Coinkite’s Data Mess Makes Things Worse

The stolen bitcoin is only part of the story. Coinkite walked into a separate fire when it came out that the company retains customer email addresses indefinitely. That’s a problem because CEO Rodolfo Novak had previously told customers their data gets deleted after 90 days. It doesn’t, apparently. The breach also pulled back the curtain on an email notification policy that directly contradicted the company’s earlier assurances about anonymous purchasing options. So customers who thought they were buying hardware wallets with some degree of privacy found out they weren’t. Not really.

The backlash was fast. People in the crypto community started asking harder questions about what hardware wallet manufacturers actually do with customer data, how long they keep it, and whether any of those privacy promises mean anything. It’s a fair question. Hardware wallets are supposed to be the gold standard for self-custody — the whole pitch is that you control your own keys and your own privacy. Finding out the company selling you that device kept your email forever, despite saying otherwise, cuts against the entire value proposition.

Some observers have started wondering whether incidents like this push more cautious investors toward exchange-traded funds instead. If self-custody carries this kind of risk — both from firmware flaws and from opaque data practices — the calculus shifts.

Who’s Actually Tracking the Stolen Funds

With ZachXBT stepping back, Galaxy Research picked up the monitoring work. The firm has been tracking the attacker’s movements and putting out updates on where the stolen BTC is going. It’s not a small job. The speed at which the funds moved — 594 BTC gone in 30 minutes during the first wave alone — has led to speculation that whoever pulled this off used automated tools to exploit the vulnerability at scale. Possibly AI-assisted. No confirmation on that yet, but the pace makes manual exploitation look unlikely.

There’s also been some onchain noise. Someone posted a bitcoin laundering offer directly on Bitcoin’s blockchain during the chaos. Public, visible, bizarre. It added another layer of spectacle to an already messy situation.

The broader challenge here is real. ZachXBT’s absence isn’t just a PR problem for Bitcoin’s community — it’s a practical one. Tracking stolen funds across multiple attack waves, with fast-moving addresses and potentially automated laundering, requires sustained investigative effort. Galaxy Research is doing it, but the more eyes on something like this, generally the better the outcome.

Coinkite, for its part, has had to keep defending itself on two fronts simultaneously: the firmware flaw that let the hack happen, and the data retention practices that shouldn’t have been a surprise to customers but were. Neither is a good look. The company released the patch, but the trust damage from the email revelation is a slower, harder thing to fix.

Users still running unpatched Mk3 firmware are the most exposed. Seeds generated between March 2021 and the patch release could still be vulnerable if those wallets haven’t been updated. Galaxy Research continues to track the attacker’s movements as of August 3, with 1,367 BTC — $88.6 million — still unrecovered.

Frequently Asked Questions

Why did ZachXBT refuse to trace the Coldcard hack?

ZachXBT said he focuses on ecosystems that value his work, and cited a lack of support from Bitcoin’s community as the reason he won’t pursue the $88.6 million Coldcard case.

Which Coldcard devices were affected by the firmware flaw?

Coldcard Mk3 devices running firmware versions 4.0.1 through 4.1.9 were vulnerable, with the flaw potentially dating back to a March 2021 firmware build.

Community Trust IndexHigh Confidence
88%
Real
Real88%12%Fake
26 community signals

Bruce Buterin

Bruce Buterin is an American crypto analyst passionate about the evolution of Web3, crypto ETFs, and Ethereum innovations. Based in Miami, he closely follows market movements and regularly publishes in-depth insights on DeFi trends, emerging altcoins, and asset tokenization. With a mix of technical expertise and accessible language, Bruce makes the blockchain ecosystem clear and engaging for both enthusiasts and investors. Specialties: Ethereum, DeFi, NFTs, U.S. regulation, Layer 2 innovations.

Advertisement

Related Stories