This prolific blockchain investigator, known for unmasking the identities of hackers behind some of the largest crypto heists, wrote on X that he currently has no plans to track or investigate the Coldcard incident. He noted that he focuses primarily on ecosystems that value his work, adding that proponents of the Bitcoin "maximalist" approach are not sponsors or supporters of his investigations, so he feels less obligation to assist.

This statement came as the Coldcard hack entered its fifth day, with the total damage amount continuing to rise. ZachXBT has previously worked on major cases pro bono, and his post indicates a significant gap between the goodwill he receives from the Bitcoin community and the efforts demanded of him when things go wrong.
Current State of the Coldcard Hack
The root cause of the vulnerability lies in a firmware defect in hardware wallets from Canadian manufacturer Coinkite. This bug affected Coldcard Mk3 devices with firmware versions from 4.0.1 to 4.1.9, causing some wallets to generate seed entropy using a software random number generator instead of the device's dedicated chip—this defect made some seeds guessable.
The first wave of attacks occurred on July 30, when roughly 594 $BTC, worth about $38 million at the time, were drained from nearly 500 inactive addresses in less than 30 minutes. Coinkite released a patched firmware within two days, but the damage continued to mount. By August 2, Galaxy Research estimated that a total of 1,367 $BTC worth $88.6 million had been stolen from 4,585 addresses across three separate attack waves.
The speed and precision of the thefts have fueled speculation that automated tools, possibly leveraging artificial intelligence, may have assisted the perpetrator in identifying and draining vulnerable addresses within minutes of each attack. The scale of the thefts continued to grow despite a sharp increase in inflows of stolen funds to exchanges and the renewed movement of old, previously inactive $BTC linked to the case.
Data Storage Fuels Further Backlash
Coinkite's handling of the incident's aftermath has become a separate point of contention, given that the company emailed all customer addresses it could find in its store and mailing list databases (some dating back to 2019) to warn them about the vulnerability.
This contradicted earlier statements by CEO Rodolfo Novak that Coinkite deletes customer data 90 days after purchase and offers options for anonymous purchases. Coinkite later acknowledged that it retains the email addresses provided at purchase indefinitely and confirmed the absence of a policy to delete this data—an admission that triggered a separate wave of criticism unrelated to the hack itself.
Novak defended the company's overall security level, noting that competitors regularly face data leaks and that Coinkite takes the matter extremely seriously. However, this incident has already begun to erode trust in self-custody and may push more cautious investors back toward exchange-traded funds instead of managing their own keys.
This story has also ballooned into an on-chain drama extending beyond the theft itself. A brazen money laundering offer addressed to the hacker was posted directly on the Bitcoin blockchain, turning the case into a public spectacle unfolding in real-time across social media and blockchain data.
With heavyweights like ZachXBT stepping aside, the burden of tracking the stolen 1,367 $BTC now falls more heavily on companies like Galaxy Research, which is publishing updates as the perpetrator's wallet activity evolves. Reports have emerged that the entropy bug affecting Coldcard Mk3 devices dates back to the March 2021 firmware build, meaning any wallet seed generated on that version for over the past four-plus years may still be vulnerable until owners replace it with a new seed using the patched firmware.





