Just a few hours ago, the hacker who holds the largest share of the stolen funds (2,055 $BTC worth approximately $130 million), became active again and transferred 30.185 $BTC worth about $1.94 million to a newly created wallet. Other blockchain researchers confirmed this transfer within minutes, characterizing it as the first activity from the hacker since the initial theft.

This transfer is small compared to the hacker's total asset volume, constituting about 1.5% of the stolen funds, but it is significant as it breaks the period of inactivity during which investigators and the broader Bitcoin community watched the untouched pile of stolen coins.
Bitcoin.com News previously reported that the theft amount, affecting Coldcard Mk3 devices with vulnerable firmware, exceeded $116 million in the form of over 1,800 $BTC withdrawn from more than 5,200 addresses, as additional waves of withdrawals were discovered in the weeks following the initial disclosure.
What This Transfer Could Mean
Onchain analysts typically view the first movement of stolen funds by a "dormant" hacker as an early signal of an attempted cash-out, as perpetrators generally need to move coins through a series of wallets, mixers, or cross-chain bridges before attempting to convert them into other assets or fiat currency without attracting immediate attention.
The situation with the Coldcard hacker is complicated by how closely the stolen funds have been tracked, given that the hacker previously received a brazen offer from another party offering to help launder the funds directly on-chain — an unusual public offer considering how closely the relevant wallets have been monitored by the broader security community.
Furthermore, blockchain researcher ZachXBT stated they do not plan to personally track the stolen funds, leaving that work to other researchers and several blockchain analytics accounts that have been closely watching these wallets since the vulnerability first became known.
A Reminder of the Vulnerability's Scale
The underlying vulnerability stems from a bug in the firmware of Coldcard devices manufactured by Toronto-based Coinkite, which caused some devices to generate seeds with cryptographic randomness that was only a fraction of what was intended. As a result, long-term holders who created wallets on vulnerable firmware versions became vulnerable to brute-force attacks allowing the recovery of their private keys.
Bitcoin.com News reported that Canadian users alone accounted for roughly a quarter of all losses related to this vulnerability; this detail aligns with the fact that Coinkite itself is based in Toronto and suggests that affected devices may have been more widely distributed in that market.
The resumption of activity by one of the largest beneficiaries of this vulnerability is likely to refocus attention on this story, which had begun to fade as the pace of new thefts slowed. For victims still hoping for a chance of recovery, the hacker's movement of funds proves the coins still exist and remain trackable on the public ledger, but also increases the likelihood that at least a portion of the stolen Bitcoin will soon become much harder to trace.
In the coming days, experts are likely to closely monitor the recipient wallet for further movements, as subsequent transfers often reveal whether the hacker is testing a laundering route, consolidating funds ahead of a larger operation, or responding to some external pressure.







