ZachXBT Refuses to Track $88M Coldcard Hack

cryptonews.ruPublicado a 2026-08-03Actualizado a 2026-08-03

Resumen

Well-known blockchain investigator ZachXBT stated on X that he currently has no plans to track or investigate the Coldcard hack, which has resulted in losses of approximately $88.6 million. He cited a focus on ecosystems that value his work and noted a lack of support from Bitcoin maximalists for his investigations. The attack exploited a firmware flaw in Coinkite's Coldcard Mk3 hardware wallets (versions 4.0.1 to 4.1.9), causing some devices to generate guessable seed phrases. The hacker, potentially using automated tools or AI, drained funds from thousands of inactive addresses in multiple waves starting July 30th. Coinkite's incident response sparked separate controversy when the company emailed customers using addresses stored indefinitely, contradicting prior claims about data deletion policies. This has damaged trust in self-custody solutions. With ZachXBT stepping back, tracking the stolen 1,367 BTC falls largely to firms like Galaxy Research. The vulnerability may affect seeds generated over the past four years, requiring users to upgrade firmware and generate new seeds for safety.

This prolific blockchain investigator, known for unmasking the identities of hackers behind some of the largest crypto heists, wrote on X that he currently has no plans to track or investigate the Coldcard incident. He noted that he focuses primarily on ecosystems that value his work, adding that proponents of the Bitcoin "maximalist" approach are not sponsors or supporters of his investigations, so he feels less obligation to assist.

Image source: X

This statement came as the Coldcard hack entered its fifth day, with the total damage amount continuing to rise. ZachXBT has previously worked on major cases pro bono, and his post indicates a significant gap between the goodwill he receives from the Bitcoin community and the efforts demanded of him when things go wrong.

Current State of the Coldcard Hack

The root cause of the vulnerability lies in a firmware defect in hardware wallets from Canadian manufacturer Coinkite. This bug affected Coldcard Mk3 devices with firmware versions from 4.0.1 to 4.1.9, causing some wallets to generate seed entropy using a software random number generator instead of the device's dedicated chip—this defect made some seeds guessable.

The first wave of attacks occurred on July 30, when roughly 594 $BTC, worth about $38 million at the time, were drained from nearly 500 inactive addresses in less than 30 minutes. Coinkite released a patched firmware within two days, but the damage continued to mount. By August 2, Galaxy Research estimated that a total of 1,367 $BTC worth $88.6 million had been stolen from 4,585 addresses across three separate attack waves.

The speed and precision of the thefts have fueled speculation that automated tools, possibly leveraging artificial intelligence, may have assisted the perpetrator in identifying and draining vulnerable addresses within minutes of each attack. The scale of the thefts continued to grow despite a sharp increase in inflows of stolen funds to exchanges and the renewed movement of old, previously inactive $BTC linked to the case.

Data Storage Fuels Further Backlash

Coinkite's handling of the incident's aftermath has become a separate point of contention, given that the company emailed all customer addresses it could find in its store and mailing list databases (some dating back to 2019) to warn them about the vulnerability.

This contradicted earlier statements by CEO Rodolfo Novak that Coinkite deletes customer data 90 days after purchase and offers options for anonymous purchases. Coinkite later acknowledged that it retains the email addresses provided at purchase indefinitely and confirmed the absence of a policy to delete this data—an admission that triggered a separate wave of criticism unrelated to the hack itself.

Novak defended the company's overall security level, noting that competitors regularly face data leaks and that Coinkite takes the matter extremely seriously. However, this incident has already begun to erode trust in self-custody and may push more cautious investors back toward exchange-traded funds instead of managing their own keys.

This story has also ballooned into an on-chain drama extending beyond the theft itself. A brazen money laundering offer addressed to the hacker was posted directly on the Bitcoin blockchain, turning the case into a public spectacle unfolding in real-time across social media and blockchain data.

With heavyweights like ZachXBT stepping aside, the burden of tracking the stolen 1,367 $BTC now falls more heavily on companies like Galaxy Research, which is publishing updates as the perpetrator's wallet activity evolves. Reports have emerged that the entropy bug affecting Coldcard Mk3 devices dates back to the March 2021 firmware build, meaning any wallet seed generated on that version for over the past four-plus years may still be vulnerable until owners replace it with a new seed using the patched firmware.

Preguntas relacionadas

QWhy did blockchain researcher ZachXBT decline to investigate the Coldcard hack?

AZachXBT stated that he currently does not plan to track or investigate the Coldcard incident. He prioritizes working for ecosystems that value his efforts and noted that 'maximalist' Bitcoin supporters are not sponsors or backers of his investigations, so he feels less obligated to assist.

QWhat was the technical vulnerability that led to the Coldcard hack?

AThe vulnerability was a firmware defect affecting Coldcard Mk3 devices running firmware versions 4.0.1 to 4.1.9. The flaw caused some wallets to generate seed entropy using a software-based random number generator instead of the device's dedicated hardware chip, making the seed values predictable or guessable.

QWhat was the total estimated financial loss from the Coldcard hack according to Galaxy Research?

AAccording to Galaxy Research, the total estimated loss from the Coldcard hack was 1,367 BTC, valued at approximately $88.6 million at the time of the report.

QWhat controversy arose regarding Coinkite's handling of customer data after the hack?

ACoinkite faced criticism for emailing all customer addresses it could find in its store and mailing list databases (some dating back to 2019) to warn them of the vulnerability. This contradicted earlier CEO statements about deleting customer data after 90 days and offering anonymous purchase options. The company later admitted it indefinitely retains purchase email addresses with no deletion policy.

QWhat does the article suggest about the future impact of this incident on cryptocurrency storage practices?

AThe article suggests the incident is beginning to undermine trust in self-custody of cryptocurrency and may push more cautious investors towards exchange-traded funds (ETFs) instead of managing their own private keys.

Lecturas Relacionadas

Wells Fargo Joins Major US Banks in Creating Tokenized Deposit Network by 2027

Wells Fargo has joined major U.S. banks including JPMorgan, Bank of America, and Citigroup in a consortium to launch a shared network for tokenized deposits by the first half of 2027. The system, to be operated by The Clearing House, will enable the 24/7 exchange of digital versions of customer deposits on a blockchain platform. The initiative aims to provide instantaneous settlement, moving beyond traditional banking hours, with initial users expected to be large multinational corporations benefiting from enhanced liquidity for cross-border payments. While a specific blockchain partner has not yet been chosen, the network is seen as a way for banks to offer the speed and programmability of blockchain without ceding clients to crypto-native competitors. This move builds on existing bank projects, such as Wells Fargo's earlier pilot of a digital cash platform and JPMorgan's institutional tokenized deposit on Ethereum's Base network. It also comes amidst the growth of the stablecoin market and pending U.S. legislation that could allow stablecoin issuers to pay interest, posing potential competition to traditional bank deposits. Bank executives note that while customer demand for tokenized deposits is not yet overwhelming, the network prepares the industry for future adoption. The shared infrastructure, as opposed to individual bank systems, is intended to spread the benefits across the broader banking ecosystem.

cryptonews.ruHace 1 hora(s)

Wells Fargo Joins Major US Banks in Creating Tokenized Deposit Network by 2027

cryptonews.ruHace 1 hora(s)

Trading

Spot
活动图片