BTCC / BTCC Square / Cryptonews /
Coldcard Hacker Moves $1.94M in Stolen Bitcoin—First Sign of a Major Cash-Out?

Coldcard Hacker Moves $1.94M in Stolen Bitcoin—First Sign of a Major Cash-Out?

Cryptonews
Author:
Cryptonews
Release Time:
2026-08-07 15:28:00
0

A wallet linked to the infamous Coldcard hack has stirred after weeks of silence, transferring 30.185 BTC—worth roughly $1.94 million—to a freshly generated address on Aug. 7, according to on-chain tracker Lookonchain. This marks the attacker's first movement since the initial theft of 2,055 BTC (valued at $130 million), reigniting fears that a large-scale liquidation could be imminent. While the transfer alone does not confirm a sale, the shift from dormancy to action has market watchers on high alert, as further transfers could signal an impending cash-out phase that may pressure Bitcoin's price.

Bitcoin News: On-Chain Tracking Flags BTC Cash-Out Risk

The wallet activity follows a major hardware-wallet breach involving more than $100 million in reported losses. On-chain analysis from Galaxy Research identified three confirmed attack waves that drained 1,596 BTC from roughly 7,300 addresses.

A suspected fourth wave could bring the total to about 2,055 BTC, valued at roughly $130 million.

Source: Arkham

Before the latest transfer, Galaxy Research said roughly 90% of the stolen bitcoin had not moved from the wallets where it was sent after the reported theft.

Because bitcoin transactions are public on the blockchain, identified attacker addresses can be tracked as funds move between wallets.

On-chain analysts have described the transfer as a possible early sign of an attempted cash-out. Attackers seeking to convert stolen assets may move funds through a series of wallets before attempting to exchange them for other assets or fiat currency.

Firmware Flaw Exposed Cold Storage Devices

The breach stemmed from a software vulnerability in Coldcard hardware wallets made by Toronto-based Coinkite. In an update, Coinkite said affected firmware dating to March 2021 used a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator when generating wallet seeds.

🚨URGENT COLDCARD SECURITY UPDATE

Read carefully before acting.

Mk3 seed generated on 4.0.1+ without ≥50 private, independent dice rolls: begin a careful migration now.

👉Mk4/Mk5 — COLDCARD (@COLDCARDwallet) July 31, 2026

The flaw allowed attackers to reconstruct wallet seed phrases or private keys without physically obtaining the devices. Seed phrases act as the keys used to authorize bitcoin transactions.

Coinkite advised users who generated seeds on vulnerable firmware to move their funds to safe addresses or use fresh seeds. The company also released firmware updates, though existing seed phrases generated on vulnerable devices remain at risk and should be replaced, according to the company and Galaxy Research.

What to Watch as Attacker Wallets Awaken

The immediate focus is on whether the 30.185 BTC sent to the new address moves again.

Further transfers could provide additional information about how the stolen funds are being handled, though the initial transfer alone does not establish the purpose of the movement.

Galaxy Research said details from the ongoing investigation, including attacker and victim addresses, have been shared with U.S. law enforcement agencies, cryptocurrency exchanges and cyber-investigation groups.

The firm said identifying additional attacker addresses remains important so those addresses can be reported to authorities.

Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit