Skip to main content

ZachXBT Refuses to Trace the $88M Coldcard Hack

Importance High

Blockchain investigator ZachXBT says he has no plans to trace the $88.6 million Coldcard hack, telling followers that Bitcoin’s community has offered him little support in return for his work in years past.

The prolific onchain investigator, known for unmasking hackers behind some of crypto’s biggest thefts, posted on X that he has no current plans to monitor or trace the Coldcard incident. He said his time is focused on ecosystems that value his work, adding that Bitcoin maxis are not donors or supporters of his investigations, so he has less obligation to help.

The remark landed as the Coldcard breach entered its fifth day and its running total kept climbing. ZachXBT has previously worked pro bono on major cases, and his post suggests a major divide between the goodwill Bitcoin’s community has shown him and the effort he is asked to put forth when things go wrong.

The exploit traces back to a firmware flaw in hardware wallets made by Canadian manufacturer Coinkite. The bug affected Coldcard Mk3 devices running versions 4.0.1 through 4.1.9, causing some wallets to generate seed entropy through a software random-number generator instead of the hardware’s dedicated chip, a defect that made certain seeds guessable.

The first wave hit on July 30 when roughly 594 BTC, worth about $38 million at the time, drained from close to 500 dormant addresses in under 30 minutes. Coinkite pushed patched firmware within two days, but the damage kept spreading. By August 2, Galaxy Research had tracked the running total to 1,367 BTC, worth $88.6 million, pulled from 4,585 addresses across three separate attack waves.

The pace and precision of the thefts fueled speculation that automated tooling, possibly AI-assisted, helped the attacker identify and drain vulnerable addresses within minutes of each sweep. The theft continued to balloon even as exchange deposits from the stolen funds spiked and older, previously dormant BTC linked to the case started moving again.

Coinkite’s handling of the aftermath has become its own controversy. The company emailed every customer address it could reach from its store and newsletter records, some dating back to 2019, to warn about the bug. This contradicted earlier claims from CEO Rodolfo Novak that Coinkite erased customer data 90 days after a purchase and offered anonymous buying options. Coinkite later admitted it retains purchase email addresses indefinitely and acknowledged it lacks a deletion policy for that data, drawing its own wave of criticism.

Novak has defended the company’s overall security record, noting that competitors face breaches regularly and that Coinkite takes the matter extremely seriously. Still, the episode has started to erode faith in self-custody and could push more cautious investors back toward exchange-traded funds instead of managing their own keys.

A brazen bitcoin laundering offer aimed at the hacker was posted directly onto Bitcoin’s blockchain, turning the case into a public spectacle playing out in real time across social media and onchain data.

With heavyweights like ZachXBT stepping back, the burden of tracing the stolen 1,367 BTC falls more heavily on firms like Galaxy Research, which has been publishing wave-by-wave updates as the attacker’s wallet activity evolves. Reports have surfaced that the entropy bug affecting Coldcard Mk3 devices dates back to a March 2021 firmware build, meaning any wallet seed generated on that version over more than four years could still be exposed until owners rotate to a fresh seed on the patched firmware.

Source: https://news.bitcoin.com/security/zachxbt-declines-trace-coldcard-hack/