Blockchain investigator ZachXBT says he will not currently trace the $88.6m (£69.1m) Coldcard hack, arguing that the Bitcoin community has provided little support for his previous work.
ZachXBT, who has built a reputation for identifying hackers behind some of the cryptocurrency sector’s largest thefts, said on X that he had no plans to monitor or investigate the latest incident.
He said he was concentrating on ecosystems that valued his work, adding that Bitcoin maxis were not donors or supporters of his investigations and that he therefore felt less obliged to assist.
His comments came as the security breach entered its fifth day and the amount stolen continued to rise. ZachXBT has previously worked pro bono on major cases, and his decision has highlighted a perceived gap between the support he has received from the Bitcoin community and the demands placed on him when attacks occur.
The hack was linked to a firmware flaw in hardware wallets produced by Canadian manufacturer Coinkite. Coldcard Mk3 devices running firmware versions 4.0.1 to 4.1.9 were affected.
The defect meant some wallets generated seed entropy through a software random-number generator rather than the hardware’s dedicated security chip. As a result, some wallet seeds became potentially predictable.
The first wave of attacks took place on 30 July, when about 594 BTC, valued at approximately $38m at the time, was taken from nearly 500 dormant addresses in less than 30 minutes.
Coinkite released patched firmware within two days. However, the thefts continued. By 2 August, Galaxy Research had calculated that 1,367 BTC, worth $88.6m, had been removed from 4,585 addresses in three separate attack waves.
The speed and accuracy of the thefts prompted speculation that the attacker had used automated tools, potentially assisted by artificial intelligence, to identify and drain exposed addresses within minutes of each sweep.
Activity linked to the theft continued even as deposits of the stolen funds to exchanges increased. Older Bitcoin addresses that had previously been inactive and were associated with the incident also began moving again.
Coinkite criticised over customer data
Coinkite’s response has created a separate controversy. The company emailed every customer address it could identify through its store and newsletter records in an attempt to warn users about the vulnerability. Some of those records dated back to 2019.
That action appeared to conflict with earlier statements by chief executive Rodolfo Novak, who had said Coinkite deleted customer data 90 days after a purchase and offered anonymous purchasing options.
Coinkite later acknowledged that it keeps customer email addresses linked to purchases indefinitely and does not have a deletion policy for that information. The admission led to further criticism beyond the original security breach.
Novak has defended Coinkite’s wider security record, saying rival companies regularly suffer breaches and that the firm is treating the incident with the utmost seriousness.
Nevertheless, the hack has begun to undermine confidence in self-custody, the practice of individuals managing their own cryptocurrency keys. It could encourage more cautious investors to use exchange-traded funds instead of holding and securing assets themselves.
The incident has also generated a public onchain dispute. A brazen Bitcoin laundering offer directed at the hacker was posted directly to Bitcoin’s blockchain, turning the response into a spectacle followed through social media and publicly visible transaction data.
With investigators such as ZachXBT stepping back, companies including Galaxy Research face increased pressure to track the stolen 1,367 BTC. Galaxy Research has continued publishing updates on each attack wave as the attacker’s wallets remain active.
Reports have also indicated that the entropy flaw affecting Coldcard Mk3 devices may date back to a firmware build released in March 2021. That could mean any wallet seed created using that version during the following four years remains exposed, unless users move to patched firmware and generate a fresh seed.
Bitcoin advocate Samson Mow outlined five immediate actions for users affected by the Coldcard wallet losses after the vulnerability was disclosed.
