Key Takeaways
- ZachXBT declined to trace the Coldcard hack, citing weak support from bitcoin holders.
- Coinkite’s Coldcard breach has drained 1,367 BTC from 4,585 addresses since July 30, 2026.
- Galaxy Research is still tracking the stolen funds as Coinkite’s email-retention policy draws fresh backlash.
ZachXBT Says He Has “Less Obligation” to Help
The prolific onchain investigator, known for unmasking hackers behind some of crypto’s biggest thefts, posted on X that he has no current plans to monitor or trace the Coldcard incident. He said his time is focused on ecosystems that value his work, adding that Bitcoin maxis are not donors or supporters of his investigations, so he has less obligation to help.

The remark landed as the Coldcard breach entered its fifth day and its running total kept climbing. ZachXBT has previously worked pro bono on major cases, and his post suggests there is a major divide between the goodwill Bitcoin’s community has shown him and the effort he is asked to out forth when things go wrong.
The Coldcard Breach so Far
The exploit traces back to a firmware flaw in hardware wallets made by Canadian manufacturer Coinkite. The bug affected Coldcard Mk3 devices running versions 4.0.1 through 4.1.9, causing some wallets to generate seed entropy through a software random-number generator instead of the hardware’s dedicated chip, a defect that made certain seeds guessable.
The first wave hit on July 30 when roughly 594 BTC, worth about $38 million at the time, drained from close to 500 dormant addresses in under 30 minutes. Coinkite pushed patched firmware within two days, but the damage kept spreading and by August 2, Galaxy Research had tracked the running total to 1,367 BTC, worth $88.6 million, pulled from 4,585 addresses across three separate attack waves.
The pace and precision of the thefts fueled speculation that automated tooling, possibly AI-assisted, helped the attacker identify and drain vulnerable addresses within minutes of each sweep. The theft continued to balloon even as exchange deposits from the stolen funds spiked and older, previously dormant BTC linked to the case started moving again.
Data Retention Adds to the Backlash
Coinkite’s handling of the aftermath has become its own controversy given that the company emailed every customer address it could reach from its store and newsletter records, some dating back to 2019, to warn them about the bug.
That contradicted earlier claims from CEO Rodolfo Novak that Coinkite erased customer data 90 days after a purchase and offered anonymous buying options. Coinkite later admitted it retains purchase email addresses indefinitely and acknowledged it lacks a deletion policy for that data, a disclosure that drew its own wave of criticism separate from the hack itself.
Novak has defended the company’s overall security record, noting that competitors face breaches regularly and that Coinkite takes the matter extremely seriously. Still, the episode has already started to erode faith in self-custody and could push more cautious investors back toward exchange-traded funds instead of managing their own keys.
The saga has also spilled into onchain drama beyond the theft itself. A brazen bitcoin laundering offer aimed at the hacker was posted directly onto Bitcoin’s blockchain, turning the case into a public spectacle playing out in real time across social media and onchain data.
With heavyweights like ZachXBT stepping back, the burden of tracing the stolen 1,367 BTC now falls more heavily on firms like Galaxy Research, which has been publishing wave-by-wave updates as the attacker’s wallet activity evolves. Reports have surfaced that the entropy bug affecting Coldcard Mk3 devices dates back to a March 2021 firmware build, meaning any wallet seed generated on that version over more than four years could still be exposed until owners rotate to a fresh seed on the patched firmware.







