Loading market data...

Wallet Tied to Coldcard Hack Moves 30 BTC in First Activity Since Theft

Wallet Tied to Coldcard Hack Moves 30 BTC in First Activity Since Theft

On-chain trackers say a wallet tied to the Coldcard hardware wallet breach moved 30.185 BTC — roughly $1.94 million — to a fresh address on Aug. 7. It's the first time any of the stolen funds have shifted since the initial theft, and it comes after weeks of silence from the attacker's wallets.

The transfer is small next to the haul. Galaxy Research puts the total stolen at about 2,055 BTC, worth around $130 million, and the Aug. 7 move accounts for roughly 1.5% of that. Before this transaction, about 90% of the stolen bitcoin had sat untouched in the wallets where it landed after the theft.

First movement in weeks

The transaction was flagged by Lookonchain, an on-chain tracking firm. On-chain analysts read it as a possible early sign of an attempted cash-out, though they caution it doesn't confirm the bitcoin will be sold or exchanged. The destination is a new address, which means the funds are still traceable — just not yet tied to any exchange.

That distinction matters. A transfer to a wallet isn't the same as a transfer to a trading platform. The movement could be consolidation, a test, or preparation for a sale. Without more on-chain activity, the intent stays unclear.

How the seed flaw worked

The breach traces back to a software vulnerability in Coldcard hardware wallets made by Coinkite. Firmware dating to March 2021 relied on a deterministic pseudo-random generator to create wallet seeds, instead of a hardware-backed true random number generator. That flaw let attackers reconstruct seed phrases or private keys without ever physically touching the devices.

Coinkite advised anyone who generated seeds on the vulnerable firmware to move funds to safe addresses or start fresh with new seeds, and it pushed firmware updates. But the company has been blunt: existing seed phrases remain at risk. Updating the firmware doesn't fix seeds that were already created on the flawed code.

Galaxy Research's accounting

Galaxy Research traced the attack to three confirmed waves that drained 1,596 BTC from roughly 7,300 addresses. A suspected fourth wave could push the total to about 2,055 BTC. The firm has shared attacker and victim addresses with U.S. law enforcement, cryptocurrency exchanges, and cyber-investigation groups.

Identifying additional attacker addresses is still a priority, Galaxy said, because those addresses are what gets reported to authorities. Each new wallet that moves funds — like the one that shifted 30 BTC this week — becomes another data point in that effort.

The next question is whether the 30 BTC ends up on an exchange. That would be the clearest sign of a cash-out. For now, the bulk of the stolen funds still hasn't moved, and the wallets holding them remain under scrutiny.