Blockchain investigator ZachXBT says he has no plans to trace the $88.6 million Coldcard hack, telling followers that Bitcoin’s community has offered him little support in return for his work in years past.
Key Takeaways
ZachXBT declined to trace the Coldcard hack, citing weak support from bitcoin holders.Coinkite’s Coldcard breach has drained 1,367 BTC from 4,585 addresses since July 30, 2026.Galaxy Research is still tracking the stolen funds as Coinkite’s email-retention policy draws fresh backlash.The remark landed as the Coldcard breach entered its fifth day and its running total kept climbing. ZachXBT has previously worked pro bono on major cases, and his post suggests there is a major divide between the goodwill Bitcoin’s community has shown him and the effort he is asked to out forth when things go wrong.
The Coldcard Breach so FarThe exploit traces back to a firmware flaw in hardware wallets made by Canadian manufacturer Coinkite. The bug affected Coldcard Mk3 devices running versions 4.0.1 through 4.1.9, causing some wallets to generate seed entropy through a software random-number generator instead of the hardware’s dedicated chip, a defect that made certain seeds guessable.
That contradicted earlier claims from CEO Rodolfo Novak that Coinkite erased customer data 90 days after a purchase and offered anonymous buying options. Coinkite later admitted it retains purchase email addresses indefinitely and acknowledged it lacks a deletion policy for that data, a disclosure that drew its own wave of criticism separate from the hack itself.
Novak has defended the company’s overall security record, noting that competitors face breaches regularly and that Coinkite takes the matter extremely seriously. Still, the episode has already started to erode faith in self-custody and could push more cautious investors back toward exchange-traded funds instead of managing their own keys.
With heavyweights like ZachXBT stepping back, the burden of tracing the stolen 1,367 BTC now falls more heavily on firms like Galaxy Research, which has been publishing wave-by-wave updates as the attacker’s wallet activity evolves. Reports have surfaced that the entropy bug affecting Coldcard Mk3 devices dates back to a March 2021 firmware build, meaning any wallet seed generated on that version over more than four years could still be exposed until owners rotate to a fresh seed on the patched firmware.


















