Coldcard Hacker Moves $7.7M Across 293 Vaults: On-Chain Forensics of Bitcoin's Third Wave
The logs show $7.7 million in Bitcoin transfers originating from Coldcard-linked addresses over the past 24 hours. These funds represent nearly half of the third wave in a suspected series of coordinated thefts. The movement pattern splits assets across 293 independent vault addresses, with each batch cleared from largest to smallest. This is not random theft. It is deliberate operational strategy.
Context begins with Coldcard by Coinkite. Launched as a premium Bitcoin self-custody hardware wallet, it prioritizes air-gapped security where private keys remain offline. The device relies on open-source firmware and physical separation from network exposure. Users generate seed phrases offline, then import them manually into air-gapped environments. Coinkite positions Coldcard in the high-security segment, targeting enthusiasts who distrust hot wallets or exchange custody. Historical precedent includes the 2018 Bitcoin Gold hack and earlier Ledger firmware incidents, where supply-chain or firmware vectors exposed users. Yet Coldcard's design assumes private keys never touch the internet. The third-wave scale of $7.7 million from 293 vaults challenges this premise without revealing the exact vector. On-chain data shows no single address compromise. Instead, multiple signatures appear in transaction graphs. Coinkite maintains transparent repositories, but silence on any product vulnerability persists. This gap leaves attribution unresolved: device firmware flaw, user seed exposure, or external supply-chain insertion.