ZachXBT Blocks $88M Coldcard Trace Citing Unpaid Industry Debts

Key Takeaways

On-chain investigator ZachXBT refused to trace the $88.6 million Coldcard breach, citing chronic non-payment by clients. The hack exploited a 2021 firmware flaw, draining 1,367 BTC across three waves in late July 2026.

Woofun AI reports that prominent on-chain investigator ZachXBT has formally declined to trace the stolen assets from the Coldcard hardware wallet security breach, a decision rooted in longstanding financial disputes with industry participants. The refusal excludes the sleuth from analyzing one of the most significant self-custody incidents of 2026, involving manufacturer Coinkite and a massive extraction of Bitcoin funds.

The scale of the breach is substantial, with illicit movements totaling 1,367 BTC, valued at approximately $88.6 million USD at the time of the initial transactions in late July 2026. Data compiled by Galaxy Research indicates that the exploitation occurred in three distinct waves between July 30 and August 1, 2026. This coordinated attack compromised more than 4,585 Bitcoin addresses, marking a severe disruption in the cold storage sector.

ZachXBT justified his withdrawal by stating he will prioritize ecosystems that demonstrate genuine appreciation for technical forensic work, citing a history of systematic non-payment. In June 2026, after dedicating five hours to trace and freeze $96,000 from a $600,000 fraud involving a crypto influencer, the client refused to report the crime and withheld the agreed $5,000 fee.

Furthermore, an ecosystem project has maintained an outstanding debt of $25,000 for nine months regarding research bounties, reinforcing the investigator’s stance against uncompensated labor.

The technical vulnerability originated from a firmware flaw introduced in March 2021, published by engineering firm Block. Affected firmware versions utilized a predictable software random number generator rather than the integrated hardware chip, critically reducing the entropy of 128-bit recovery seed phrases to approximately 72 bits. This reduction rendered the private keys computationally feasible to derive, exposing multiple device models to automated cracking.

Galaxy Research data reveals that attackers employed automated tools to calculate these predictable private keys, executing withdrawals without physical access to the devices. The first wave on July 30, 2026, drained 1,082.65 BTC from 1,195 addresses within 41 minutes, using identical network fees higher than the market average. Subsequent phases recorded between July 31 and August 1, 2026, targeted 1,478 and 1,912 additional addresses respectively, demonstrating a methodical, script-driven approach.

Woofun AI data shows that all stolen BTC remains immobilized at destination addresses controlled by the attacker, with no further movement detected as of August 2, 2026. Manufacturer Coinkite issued an emergency security notice, emphasizing that updating firmware alone does not remediate recovery seeds generated under reduced entropy parameters. Users are urged to migrate funds immediately to new wallets or unaffected devices to prevent future exploitation.

Industry figures, including the Strike platform, have recommended transferring assets to custody schemes with verified key generation while Coinkite collaborates with independent audit teams. This incident underscores the critical risk of legacy firmware vulnerabilities, requiring affected users to complete manual balance transfers before further automated executions occur on the vulnerable address range.

Vote

Do you think ZachXBT was right to refuse tracing the $88M cold wallet hack?

0 people voted

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions