Key Takeaways
- The Coldcard hacker moved 30.185 BTC, worth about $1.94 million.
- The attacker is believed to hold 2,055 BTC, worth roughly $130 million, from the original exploit.
- Onchain analysts flagged the transfer as a possible sign the hacker is preparing to cash out.
The Hacker Goes Quiet, Then Moves Again
Just hours ago, the hacker behind the largest share of the theft, holding 2,055 BTC worth roughly $130 million, resurfaced to move 30.185 BTC, worth about $1.94 million, to a newly created wallet. Other onchain sleuths corroborated the transfer within minutes of each other, describing it as the hacker’s first activity since the initial theft.

The move is small relative to the hacker’s total holdings, representing roughly 1.5% of the stolen funds, but it is significant because it breaks a pattern of dormancy that had left investigators and the wider Bitcoin community watching an otherwise untouched pile of stolen coins.
Bitcoin.com News previously reported that the theft, which affected Coldcard Mk3 devices running vulnerable firmware, climbed past $116 million across more than 1,800 BTC pulled from over 5,200 addresses as additional waves of draining were discovered in the weeks after the initial disclosure.
What the Transfer Potentially Means
Onchain analysts commonly treat a dormant hacker’s first movement of stolen funds as an early signal of an attempted cash-out, since attackers typically need to move coins through a series of wallets, mixers, or cross-chain bridges before attempting to convert them into other assets or fiat currency without immediately attracting attention.
The Coldcard hacker’s situation is complicated by how closely the stolen funds have been watched, given that he previously received a brazen offer from another party proposing to help launder the funds directly onchain, an unusual public overture given how much scrutiny the wallets involved have received from the broader security community.
Separately, onchain investigator ZachXBT has said he has no plans to personally trace the stolen funds, leaving that work to other researchers and the handful of blockchain analytics accounts that have kept the wallets under close watch since the exploit first came to light.
A Reminder of the Exploit’s Scale
The underlying vulnerability traces back to a firmware bug in Coldcard devices made by Toronto-based manufacturer Coinkite, which caused certain units to generate seeds with a fraction of their intended cryptographic randomness. That left long-term holders who generated wallets on affected firmware versions exposed to brute-force attacks capable of reconstructing their private keys.
Bitcoin.com News has reported that Canadian users alone accounted for roughly a quarter of all attributable losses, a detail that lines up with Coinkite’s own Toronto base and suggests the affected devices may have circulated more heavily in that market.
The renewed activity from one of the exploit’s largest single beneficiaries is likely to reignite attention on a story that had begun to quiet down as the pace of new draining slowed. For victims still hoping for some path to recovery, a hacker moving funds proves the coins still exist and remain traceable on a public ledger, but it also raises the odds that at least a portion of the stolen bitcoin is about to become far harder to follow.
Over the coming few days, experts will likely keep a close watch on the destination wallet for any further movement, since subsequent transfers often reveal whether a hacker is testing a laundering route, consolidating funds ahead of a larger move, or responding to some outside pressure.


