Coldcard Hacker Moves 30 BTC in First Transfer in Weeks, Sparking Cash-Out Concerns
The hacker behind the Coldcard wallet exploit, believed to hold 2,055 BTC (approximately $130 million) in stolen bitcoin, moved funds for the first time in weeks, transferring 30.185 BTC (about $1.94 million) to a newly created wallet. On-chain analysts flagged the transfer as a possible sign the hacker is preparing to cash out.
The move is small relative to the hacker’s total holdings—roughly 1.5% of the stolen funds—but significant as it breaks a pattern of dormancy. Bitcoin.com News previously reported that the theft, affecting Coldcard Mk3 devices with vulnerable firmware, climbed past $116 million across over 5,200 addresses.
On-chain analysts commonly view a dormant hacker’s first movement as an early signal of a cash-out attempt. The Coldcard hacker’s situation is complicated by intense scrutiny of the stolen funds, following a brazen public offer by another party to help launder them.
Separately, on-chain investigator ZachXBT has declined to personally trace the funds, leaving that to other researchers and blockchain analytics accounts.
The exploit stems from a firmware bug in devices made by Toronto-based Coinkite, causing certain units to generate seeds with insufficient randomness. This left long-term holders vulnerable to brute-force key reconstruction. Canadian users accounted for roughly a quarter of all attributable losses, aligning with Coinkite’s local market concentration.
The renewed activity is likely to reignite attention on the case. For victims, the movement confirms the coins still exist on the public ledger but raises the odds that a portion may soon become harder to follow. Experts will monitor the destination wallet for further transfers, which could indicate a laundering route, consolidation, or external pressure.
Source: https://news.bitcoin.com/featured/coldcard-hacker-resumes-moving-stolen-bitcoin/