ZachXBT Refuses to Track $88M Coldcard Hack

cryptonews.ruPublished on 2026-08-03Last updated on 2026-08-03

Abstract

Well-known blockchain investigator ZachXBT stated on X that he currently has no plans to track or investigate the Coldcard hack, which has resulted in losses of approximately $88.6 million. He cited a focus on ecosystems that value his work and noted a lack of support from Bitcoin maximalists for his investigations. The attack exploited a firmware flaw in Coinkite's Coldcard Mk3 hardware wallets (versions 4.0.1 to 4.1.9), causing some devices to generate guessable seed phrases. The hacker, potentially using automated tools or AI, drained funds from thousands of inactive addresses in multiple waves starting July 30th. Coinkite's incident response sparked separate controversy when the company emailed customers using addresses stored indefinitely, contradicting prior claims about data deletion policies. This has damaged trust in self-custody solutions. With ZachXBT stepping back, tracking the stolen 1,367 BTC falls largely to firms like Galaxy Research. The vulnerability may affect seeds generated over the past four years, requiring users to upgrade firmware and generate new seeds for safety.

This prolific blockchain investigator, known for unmasking the identities of hackers behind some of the largest crypto heists, wrote on X that he currently has no plans to track or investigate the Coldcard incident. He noted that he focuses primarily on ecosystems that value his work, adding that proponents of the Bitcoin "maximalist" approach are not sponsors or supporters of his investigations, so he feels less obligation to assist.

Image source: X

This statement came as the Coldcard hack entered its fifth day, with the total damage amount continuing to rise. ZachXBT has previously worked on major cases pro bono, and his post indicates a significant gap between the goodwill he receives from the Bitcoin community and the efforts demanded of him when things go wrong.

Current State of the Coldcard Hack

The root cause of the vulnerability lies in a firmware defect in hardware wallets from Canadian manufacturer Coinkite. This bug affected Coldcard Mk3 devices with firmware versions from 4.0.1 to 4.1.9, causing some wallets to generate seed entropy using a software random number generator instead of the device's dedicated chip—this defect made some seeds guessable.

The first wave of attacks occurred on July 30, when roughly 594 $BTC, worth about $38 million at the time, were drained from nearly 500 inactive addresses in less than 30 minutes. Coinkite released a patched firmware within two days, but the damage continued to mount. By August 2, Galaxy Research estimated that a total of 1,367 $BTC worth $88.6 million had been stolen from 4,585 addresses across three separate attack waves.

The speed and precision of the thefts have fueled speculation that automated tools, possibly leveraging artificial intelligence, may have assisted the perpetrator in identifying and draining vulnerable addresses within minutes of each attack. The scale of the thefts continued to grow despite a sharp increase in inflows of stolen funds to exchanges and the renewed movement of old, previously inactive $BTC linked to the case.

Data Storage Fuels Further Backlash

Coinkite's handling of the incident's aftermath has become a separate point of contention, given that the company emailed all customer addresses it could find in its store and mailing list databases (some dating back to 2019) to warn them about the vulnerability.

This contradicted earlier statements by CEO Rodolfo Novak that Coinkite deletes customer data 90 days after purchase and offers options for anonymous purchases. Coinkite later acknowledged that it retains the email addresses provided at purchase indefinitely and confirmed the absence of a policy to delete this data—an admission that triggered a separate wave of criticism unrelated to the hack itself.

Novak defended the company's overall security level, noting that competitors regularly face data leaks and that Coinkite takes the matter extremely seriously. However, this incident has already begun to erode trust in self-custody and may push more cautious investors back toward exchange-traded funds instead of managing their own keys.

This story has also ballooned into an on-chain drama extending beyond the theft itself. A brazen money laundering offer addressed to the hacker was posted directly on the Bitcoin blockchain, turning the case into a public spectacle unfolding in real-time across social media and blockchain data.

With heavyweights like ZachXBT stepping aside, the burden of tracking the stolen 1,367 $BTC now falls more heavily on companies like Galaxy Research, which is publishing updates as the perpetrator's wallet activity evolves. Reports have emerged that the entropy bug affecting Coldcard Mk3 devices dates back to the March 2021 firmware build, meaning any wallet seed generated on that version for over the past four-plus years may still be vulnerable until owners replace it with a new seed using the patched firmware.

Related Questions

QWhy did blockchain researcher ZachXBT decline to investigate the Coldcard hack?

AZachXBT stated that he currently does not plan to track or investigate the Coldcard incident. He prioritizes working for ecosystems that value his efforts and noted that 'maximalist' Bitcoin supporters are not sponsors or backers of his investigations, so he feels less obligated to assist.

QWhat was the technical vulnerability that led to the Coldcard hack?

AThe vulnerability was a firmware defect affecting Coldcard Mk3 devices running firmware versions 4.0.1 to 4.1.9. The flaw caused some wallets to generate seed entropy using a software-based random number generator instead of the device's dedicated hardware chip, making the seed values predictable or guessable.

QWhat was the total estimated financial loss from the Coldcard hack according to Galaxy Research?

AAccording to Galaxy Research, the total estimated loss from the Coldcard hack was 1,367 BTC, valued at approximately $88.6 million at the time of the report.

QWhat controversy arose regarding Coinkite's handling of customer data after the hack?

ACoinkite faced criticism for emailing all customer addresses it could find in its store and mailing list databases (some dating back to 2019) to warn them of the vulnerability. This contradicted earlier CEO statements about deleting customer data after 90 days and offering anonymous purchase options. The company later admitted it indefinitely retains purchase email addresses with no deletion policy.

QWhat does the article suggest about the future impact of this incident on cryptocurrency storage practices?

AThe article suggests the incident is beginning to undermine trust in self-custody of cryptocurrency and may push more cautious investors towards exchange-traded funds (ETFs) instead of managing their own private keys.

Related Reads

Once-Popular Web3 Enters Wave of Layoffs

The once-hot Web3 industry is experiencing a severe wave of layoffs. While many companies attribute job cuts to AI-driven restructuring, the primary reason is often financial pressure. The Web3 sector, at the intersection of tech and finance, has been hit particularly hard. Employees at major cryptocurrency exchanges report sudden, impersonal layoffs—often with system access revoked overnight—and minimal or no severance. Common tactics include setting impossible performance targets or terminating employees for minor policy violations. The working atmosphere has become toxic, marked by intense monitoring, excessive meetings, and management obsessed with control and internal politics rather than product innovation. The industry's core business model is collapsing. Exchange revenue from trading fees and listing charges has plummeted due to a decline in quality projects and retail investor exodus. Events like the massive forced liquidation on October 10th further shattered confidence. Competition from on-chain derivatives platforms and prediction markets is intensifying the downturn. As layoffs continue, displaced workers struggle to find new opportunities. Many transition to the AI sector, but face significant bias from traditional finance and even some AI firms, which view crypto industry experience with suspicion. The current downturn appears more structural than cyclical, driven by unsustainable practices, internal strife, and a failure to innovate, raising questions about the industry's future trajectory.

marsbit6m ago

Once-Popular Web3 Enters Wave of Layoffs

marsbit6m ago

Sales Drop 26% But Prices Rise? Xiaomi's Dilemma

Xiaomi, facing a significant 26.3% year-on-year decline in global smartphone shipments in Q2 2026, has implemented its third price hike of the year. On August 2nd, prices were raised for nine models, including the flagship Mi 17 series (up 400-500 yuan) and Redmi K90/Turbo 5 series (up 300 yuan). This move completes a pattern where cost pressure, originating from surging memory chip prices, has climbed from entry-level to mid-range and now flagship products. The primary driver is a severe supply squeeze on consumer-grade DRAM and NAND flash memory, as major manufacturers like Samsung shift advanced capacity to more profitable HBM for AI applications. According to Xiaomi President Lu Weibing, memory prices for the same configuration have skyrocketed nearly fourfold since Q1 2025, adding roughly 1500 yuan to the cost of a mainstream 12GB+512GB phone. IDC estimates consumer memory costs have risen nearly 300% year-on-year. While the price increases hurt demand and contributed to the sales slump, Xiaomi's strategy of reducing entry-level models and upgrading its product mix also played a role. Domestically, its market share in China fell to 12% (5th place), while leaders Huawei and Apple saw shipments grow over 24%. To mitigate future risks, Xiaomi is accelerating its in-house "Surge" chip development and optimizing memory configurations across its lineup. Xiaomi is not alone; major brands like OPPO, vivo, and Apple have already raised prices in 2026, with industry insiders predicting another round of increases (200-800 yuan) in the second half. A full-scale industry-wide涨价 cycle is underway, forcing both manufacturers and consumers to recalibrate their strategies and purchasing decisions amid sustained cost pressures.

marsbit17m ago

Sales Drop 26% But Prices Rise? Xiaomi's Dilemma

marsbit17m ago

Three Consecutive Quarters of Decline: The Crypto Market is Experiencing Its Longest Ebb Since 2022

The cryptocurrency market experienced its third consecutive quarterly decline in Q2 2026, marking its longest downturn since 2022, according to a CoinGecko report. The total market capitalization fell 12.6% to $2.1 trillion, a retreat of roughly 52% from its October 2025 peak. Multiple indicators signal an orderly capital exit from the sector. For the first time since Q3 2023, the total stablecoin market cap shrank (-1.6% to $305.1B), indicating funds are leaving the ecosystem entirely, not just rotating to safer crypto assets. Trading volumes on centralized exchanges dropped 27.9%, while DeFi's Total Value Locked (TVL) plummeted 23.4%. Both Bitcoin (-14.2%) and Ethereum (-25.4%) underperformed traditional risk assets like equities in Q2, breaking from previous correlative narratives. Ethereum saw its first-ever three-quarter losing streak, with its market share falling to around 10%. A few areas saw growth. Prediction market volumes surged 48.7%, largely driven by sports betting. Hyperliquid's HYPE token entered the top 10 by market cap, and tokenized collectibles platforms grew, though primarily via gamified mechanics. Despite a ~9.8% Bitcoin rebound in July, historical trends suggest caution for August. The market, now ~49% below its 2025 high, is undergoing a measured retreat. Its recovery hinges on future Federal Reserve policy and the industry's ability to develop sustainable revenue streams beyond speculation.

marsbit31m ago

Three Consecutive Quarters of Decline: The Crypto Market is Experiencing Its Longest Ebb Since 2022

marsbit31m ago

Trading

Spot
活动图片