Points of Focus
- Coldcard-linked wallet moved 30 BTC worth $1.94 million to a new address.
- Confirmed losses stand at 1,596 BTC, with a suspected fourth wave pushing the total to 2,055 BTC.
- Onchain evidence points to multiple exploiters, not a single Coldcard hacker.
A Bitcoin (BTC) wallet linked to the Coldcard exploit moved 30 BTC worth about $1.94 million to a new address on Friday, marking fresh activity from funds tied to one of the year’s largest Bitcoin wallet exploits. Lookonchain flagged the transfer as investigators continue tracking Coldcard-linked Bitcoin across attacker-controlled wallets and privacy tools.
The #Coldcard hacker, who stole 2,055 $BTC($130M), is active again.
An hour ago, the hacker transferred 30.185 $BTC($1.94M) to a new wallet.https://t.co/Edirjbd2G0https://t.co/ksoTpGxx3g pic.twitter.com/VTL5UB9xgH
— Lookonchain (@lookonchain) August 7, 2026
The transfer is small compared to the wider theft, but it stands out because most of the Bitcoin tied to Galaxy’s confirmed incidents had remained stationary. Galaxy Research said 90% of those funds hadn’t moved as of its latest update, leaving large balances available for continued onchain monitoring.
Coldcard exploit losses top $100 million across confirmed waves
Galaxy Research has confirmed 1,596 BTC stolen from roughly 7,300 addresses across three major waves and 14 smaller incidents. A suspected fourth wave could raise the total to 2,055 BTC, worth about $130 million, but Galaxy excluded it from the confirmed total because researchers had not received enough victim confirmation.
The attack traces back to a firmware error introduced in March 2021. Coinkite said affected devices could generate seeds with far less randomness than the expected 128 bits. The company estimated effective entropy at about 40 bits for affected Mk3 seeds and around 72 bits for Mk4, Mk5, and Q devices, although separate analysis from Block argued the effective security could be lower under some conditions.
Multiple coldcard attackers complicate fund tracing
The latest 30-BTC move shouldn’t be read as proof that one operator controls every Coldcard-linked wallet. TRM Labs found differences in transaction construction across attack waves, while Galaxy identified activity linked to at least 15 suspected attackers. CertiK also said a wallet that sent 64 BTC worth $4.17 million to Wasabi may belong to a smaller exploiter or copycat.
CertiK separately traced 200 Ether (ETH) worth about $380,000, bridged from Bitcoin through THORChain, into Tornado Cash. Mixing obscures the direct onchain link between incoming and outgoing funds, making attribution and recovery harder once coins leave identifiable attacker clusters.
Coinkite shipped emergency firmware on July 31, but installing it doesn’t repair a seed generated under vulnerable firmware. The company advised affected users to generate a new seed on patched firmware and move their Bitcoin.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


