The perpetrator behind the crypto theft from Coldcard hardware wallet users has struck again. Just an hour before on-chain tracker @lookonchain released its report, the hacker transferred 30.185 BTC worth $1.94 million to a new wallet address.
This move ends a period of inactivity following the July 30 incident. Previously, about 90% of the stolen Bitcoin remained untouched, with the main hacker leaving 1,159 BTC dormant across seven different addresses. The movement of the 30 BTC alters this prolonged dormancy pattern and provides an early signal that the perpetrator is starting to move the hacked proceeds.
According to records from Galaxy Research, 1,596 BTC has been confirmed lost from approximately 7,300 wallet addresses. A fourth hacking wave, which is not yet fully confirmed, has the potential to push total losses even higher, reaching 2,055 BTC or equivalent to $130 million.
Why is Data Deletion Suspended?
As the hacker begins to move the stolen funds, the wallet manufacturer is caught in the bureaucracy of the investigation. Coldcard has officially suspended its automatic customer data deletion system due to legal obligations related to this series of hacking incidents. The data retention period has been forced to extend, although customers who object are welcome to contact the company’s technical support service to find a solution.
This entire chain of security disasters originated from a programming error. Instead of using the hardware random number generator (RNG) provided by the component, the wallet firmware accidentally used a deterministic MicroPython PRNG module since March 2021. This erroneous technical decision made the security layer during wallet creation fragile and easy for attackers to reverse-engineer.
A firmware update has now been released and the security loophole has been patched. However, wallets that have already been created using old seed phrases are by no means automatically secure. Wallet owners must generate a new seed under the latest firmware system and immediately transfer all their remaining funds without delay.
Narrowing Room for Maneuver
The hacker may feel confident moving 30 BTC to a new wallet, but their options for cashing out are shrinking. On-chain investigators have shared the list of attacker addresses with law enforcement agencies in the United States, crypto exchange platforms, and various cyber investigation groups.
This means these stolen coins are automatically placed under close watch at almost all conventional exit points. Any exchange platform that subsequently detects coin flows from these dirty addresses can immediately freeze the funds based on instructions from investigators.
The Coldcard incident shows how vulnerable premium hardware is if its code foundation is outdated. The wallet company now bears a heavy burden: completing security fixes for users while dealing with legal bureaucracy that is holding up the deletion of customer privacy data. Sourced from @lookonchain on X.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




