Stolen Coldcard Bitcoin Moves for the First Time — $1.94M Transfer Reignites Cash-Out Watch
A wallet tied to the Coinkite hardware-wallet breach shifted 30.185 BTC on Aug. 7, its first activity since the theft — but on-chain analysts say a single transfer isn't proof of an imminent sale.
By Jane Doe
Published on Aug 8, 2026
Quick Take
- A wallet linked to the Coldcard hack sent 30.185 BTC (~$1.94M) to a new address on Aug. 7 — its first movement since the theft, per on-chain tracker Lookonchain.
- That's about 1.5% of the roughly 2,055 BTC investigators tie to the breach; a move doesn't confirm the coins are being sold.
- The breach itself came from a firmware flaw in Coinkite's Coldcard wallets that let attackers reconstruct seed phrases without touching the physical device.
- Galaxy Research says about 90% of the stolen BTC hadn't moved before this transfer, and it has shared attacker-address data with law enforcement and exchanges.
What Happened
On Aug. 7, a wallet connected to the Coldcard hardware-wallet hack sent 30.185 BTC — worth roughly $1.94 million at the time — to a newly created address. On-chain tracker Lookonchain flagged the transfer as notable because it followed weeks of dormancy and marked the first time this attacker wallet had moved funds since the original theft.
The amount is small relative to the scale of the breach: it represents about 1.5% of the estimated 2,055 BTC investigators have linked to the incident. A transfer to a new address doesn't by itself confirm the bitcoin is headed for a sale or exchange — it simply means the funds are no longer sitting untouched.
Background: What was the Coldcard breach?
The theft stemmed from a firmware vulnerability in Coldcard hardware wallets made by Toronto-based manufacturer Coinkite. Affected firmware dating back to March 2021 used a deterministic pseudo-random generator instead of the device's intended hardware-backed true random number generator when creating wallet seeds. Because the seed generation wasn't truly random, attackers could reconstruct a wallet's seed phrase or private keys — the credentials used to authorize transactions — without ever physically obtaining the device itself.
Why It Matters
Why It Matters
Because bitcoin transactions are recorded on a public ledger, once investigators identify an attacker's wallet, every subsequent movement of those funds can be tracked in real time. That's exactly what happened here: Lookonchain and Galaxy Research have been watching this specific wallet since the breach, and its first movement in weeks is treated as a signal worth monitoring — a possible early step in an attempt to convert stolen bitcoin into other assets or fiat currency, since attackers seeking to cash out often route funds through a series of intermediate wallets first.
The Numbers
Methodology & sourcing notes
All figures above come from the supplied report, attributed to on-chain tracker Lookonchain and Galaxy Research. The bar chart is a direct visual comparison of the two BTC figures stated in the source; no additional data points were estimated or added. An approximate BTC price of roughly $64,000–$64,500 can be inferred by dividing the dollar and BTC figures given in the source (e.g., $1.94M ÷ 30.185 BTC), but no such price was itself stated in the source, so it is presented here only as a calculated cross-check, not as reported market data.
Market Reaction
The source does not report a broader bitcoin price move tied to this transfer, nor any exchange or trading reaction. What it does note is that roughly 90% of the total stolen bitcoin had not moved from its post-theft wallets before this Aug. 7 transfer, according to Galaxy Research — meaning the vast majority of the stolen funds remain parked and unaccounted for in terms of market impact so far.
What's Next / Things to Watch
- Whether the 30.185 BTC moves again. The source frames this as the immediate focal point — further transfers would offer more insight into how the funds are being handled, though even that would not by itself confirm a sale.
- Law-enforcement coordination. Galaxy Research says it has shared attacker- and victim-address details with U.S. law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups, and considers identifying additional attacker addresses important so they can be reported to authorities.
- Remaining exposure for Coldcard users. Coinkite has advised users who generated seeds on the vulnerable firmware to migrate funds to safe addresses or generate fresh seeds; the company has released firmware updates, but seed phrases originally generated on the flawed firmware remain at risk until replaced.
FAQs
What is the Coldcard hack?
It's a breach affecting Coldcard hardware wallets made by Coinkite, caused by a firmware flaw dating to March 2021 that generated wallet seeds using a deterministic pseudo-random generator instead of true hardware-based randomness — letting attackers reconstruct seed phrases and steal funds without physical access to the device.
Has the stolen bitcoin been sold?
Not confirmed. A wallet tied to the hack moved 30.185 BTC (~$1.94M) on Aug. 7, its first movement since the theft, but the source is explicit that this transfer alone doesn't establish whether the funds will be sold or exchanged.
How much bitcoin was stolen in total?
Galaxy Research confirmed three attack waves draining 1,596 BTC from about 7,300 addresses; a suspected fourth wave could push the total to roughly 2,055 BTC (~$130 million). The fourth wave is described as suspected, not confirmed.
What should Coldcard owners do?
Coinkite has advised users who generated seed phrases on the vulnerable firmware to move their funds to safe addresses or generate new seeds, and has released firmware updates. Existing seed phrases created on affected firmware remain at risk until replaced.
Can the stolen funds be tracked?
Yes — because bitcoin transactions are recorded on a public blockchain, identified attacker addresses can be monitored as funds move between wallets, which is how this latest transfer was detected and reported.
This article is based on a single news report and on-chain data as cited within it. Figures marked ⚠️ reflect suspected or interpretive claims from the source, not confirmed facts. No specific source URLs were included in the original report to cite as endnotes.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.