The hacker behind the Coldcard hardware wallet exploit has resumed moving funds on-chain, transferring 30.185 BTC — worth roughly $1.94 million — to a new wallet, according to blockchain analytics firm Lookonchain. The transfer is the latest sign of activity from an attacker who has already stolen more than 2,055 BTC, worth around $130 million, since the exploit first surfaced.

The underlying vulnerability traces back five years, to a March 2021 firmware release from Coldcard maker Coinkite that contained a build configuration error. That error caused affected devices to generate wallet seeds using a weak software random number generator instead of the hardware's dedicated entropy source, leaving any seed generated during that window theoretically predictable to an attacker who understood the flaw.

Coldcard Exploit Hacker Resumes Moving Stolen Bitcoin
Image via @lookonchain on X

A theft that unfolded in waves

The exploitation began July 30, when the attacker drained 1,196 addresses in just 41 minutes, taking roughly 1,082.65 BTC — about $70.2 million at the time. Blockchain monitors have since tracked four separate waves of thefts affecting more than 5,200 individual addresses, with total losses climbing past $130 million as the attacker continued sweeping vulnerable wallets discovered after the initial rush.

Related: Active Bitcoin Addresses Hit 18-Month High as Coldcard Exploit Drives Mass Wallet Migration

Why the risk doesn't end with a firmware patch

Coinkite has since patched the firmware flaw, but the fix does nothing for wallets that already generated a seed under the vulnerable versions — those seeds must be treated as permanently compromised. Security researchers have urged anyone who set up a Coldcard between March 2021 and the patch to migrate funds to a freshly generated seed immediately, since, as this latest transfer shows, the attacker is still actively working through the pool of exposed addresses rather than having exhausted it in the initial waves.