Home » ZachXBT Refuses to Trace the $88M Coldcard Hack

ZachXBT Refuses to Trace the $88M Coldcard Hack

by Jack Davies


Key Takeaways

ZachXBT Says He Has “Less Obligation” to Help

The prolific onchain investigator, known for unmasking hackers behind some of crypto’s biggest thefts, posted on X that he has no current plans to monitor or trace the Coldcard incident. He said his time is focused on ecosystems that value his work, adding that Bitcoin maxis are not donors or supporters of his investigations, so he has less obligation to help.

ZachXBT has said he does not want any part of the Coldcard investigation.
Image source: X

The remark landed as the Coldcard breach entered its fifth day and its running total kept climbing. ZachXBT has previously worked pro bono on major cases, and his post suggests there is a major divide between the goodwill Bitcoin’s community has shown him and the effort he is asked to out forth when things go wrong.

The Coldcard Breach so Far

The exploit traces back to a firmware flaw in hardware wallets made by Canadian manufacturer Coinkite. The bug affected Coldcard Mk3 devices running versions 4.0.1 through 4.1.9, causing some wallets to generate seed entropy through a software random-number generator instead of the hardware’s dedicated chip, a defect that made certain seeds guessable.

The first wave hit on July 30 when roughly 594 BTC, worth about $38 million at the time, drained from close to 500 dormant addresses in under 30 minutes. Coinkite pushed patched firmware within two days, but the damage kept spreading and by August 2, Galaxy Research had tracked the running total to 1,367 BTC, worth $88.6 million, pulled from 4,585 addresses across three separate attack waves.

The pace and precision of the thefts fueled speculation that automated tooling, possibly AI-assisted, helped the attacker identify and drain vulnerable addresses within minutes of each sweep. The theft continued to balloon even as exchange deposits from the stolen funds spiked and older, previously dormant BTC linked to the case started moving again.

Data Retention Adds to the Backlash

Coinkite’s handling of the aftermath has become its own controversy given that the company emailed every customer address it could reach from its store and newsletter records, some dating back to 2019, to warn them about the bug.

That contradicted earlier claims from CEO Rodolfo Novak that Coinkite erased customer data 90 days after a purchase and offered anonymous buying options. Coinkite later admitted it retains purchase email addresses indefinitely and acknowledged it lacks a deletion policy for that data, a disclosure that drew its own wave of criticism separate from the hack itself.

Novak has defended the company’s overall security record, noting that competitors face breaches regularly and that Coinkite takes the matter extremely seriously. Still, the episode has already started to erode faith in self-custody and could push more cautious investors back toward exchange-traded funds instead of managing their own keys.

The saga has also spilled into onchain drama beyond the theft itself. A brazen bitcoin laundering offer aimed at the hacker was posted directly onto Bitcoin’s blockchain, turning the case into a public spectacle playing out in real time across social media and onchain data.

With heavyweights like ZachXBT stepping back, the burden of tracing the stolen 1,367 BTC now falls more heavily on firms like Galaxy Research, which has been publishing wave-by-wave updates as the attacker’s wallet activity evolves. Reports have surfaced that the entropy bug affecting Coldcard Mk3 devices dates back to a March 2021 firmware build, meaning any wallet seed generated on that version over more than four years could still be exposed until owners rotate to a fresh seed on the patched firmware.



Source link

You may also like

Leave a Comment