ZachXBT Declines to Investigate $88M Coldcard Bitcoin Hack

Binance
Bitbuy


TL;DR:

  • Blockchain investigator ZachXBT confirmed that he will not trace the theft of approximately $88.6 million in Bitcoin linked to Coldcard wallets.
  • The security breach affected more than 4,500 addresses following an entropy flaw in the random number generator of Coinkite’s firmware.
  • The analyst justified his decision citing previous instances of non-payment and lack of bounty rewards from assisted projects and influencers.

On-chain investigator ZachXBT declined to monitor or trace the stolen funds from the Coldcard hardware wallet security breach, an incident recorded in late July 2026. With this decision, the sleuth is excluded from one of the largest reported hacks in the self-custody sector in 2026.

The illicit movement of funds involved 1,367 BTC, equivalent to $88.6 million USD at the time of the initial transactions. According to data from Galaxy Research, the exploitation of the compromised addresses occurred in three successive waves between July 30 and August 1, 2026, affecting more than 4,585 Bitcoin addresses.

ZachXBT publicly explained that he will focus his resources on ecosystems and projects that demonstrate appreciation for his technical work. The stance is a direct response to previous experiences where he claims to have suffered systematic non-payments after recovering assets or conducting detailed forensic analysis.

okex

Among the cases cited by the investigator, an incident from June 2026 involving a crypto influencer stands out. After devoting more than five hours to tracing and successfully freezing $96,000 from a total $600,000 fraud, the affected party refused to report the incident to authorities and declined to pay the agreed-upon $5,000 fee for the service.

Additionally, the analyst pointed out that an ecosystem project maintains an outstanding debt of $25,000 for nine months regarding research bounties. This accumulation of unfulfilled financial commitments prompted his refusal to voluntarily intervene in the Coldcard event.

Technical Origin of the Incident in Coinkite Wallets

ZachXBT – $88 million Bitcoin hack involving ColdcardZachXBT – $88 million Bitcoin hack involving Coldcard

The security issue in wallets manufactured by Coinkite originated from a firmware flaw introduced in March 2021. According to the technical report published by engineering firm Block, affected firmware versions used a predictable software random number generator instead of the hardware chip integrated into the device.

This technical deficiency reduced the entropy in the creation of 128-bit recovery seed phrases to approximately 72 bits across several models. Data from Galaxy Research indicates that attackers used automated tools to calculate predictable private keys and withdraw funds without physical access to the devices.

The three stages of asset extraction showed automated execution patterns. The first wave, recorded on July 30, 2026, stole 1,082.65 BTC from 1,195 addresses in a span of 41 minutes, applying identical network fees that were higher than the market average.

Subsequent phases recorded between July 31 and August 1, 2026, covered 1,478 and 1,912 additional addresses, respectively. According to on-chain monitoring metrics, all stolen BTC remains immobilized at the destination addresses controlled by the attacker.

Industry Responses and Mitigation Measures

Manufacturer Coinkite issued an emergency security notice recommending immediate migration of funds to new wallets generated with updated firmware or onto unaffected devices. The company confirmed that updating firmware alone does not fix recovery seeds previously created under reduced entropy parameters.

Various figures in the crypto industry issued operational recommendations following confirmation of the flaw. Data from the Strike platform indicates that the firm offered temporary exchange mechanisms and suggested transferring assets to custody schemes with verified key generation.

Over the coming weeks, Coinkite will maintain open technical investigations alongside independent audit teams to certify secure software versions. Affected users must complete manual balance transfers before further automated executions occur on the vulnerable range of addresses.



Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*