What's Hot

    Amazon confirms retail layoffs impacting underneath 1,000 company roles | Invesloan.com

    October 7, 2026

    Jacob Coxon Says This Is Why Pacing the Frontier Might Not Work | Invesloan.com

    October 7, 2026

    Options merchants are betting on a dramatic drop in rates of interest | Invesloan.com

    October 7, 2026
    Facebook Twitter Instagram
    Finance Pro
    Facebook Twitter Instagram
    invesloan.cominvesloan.com
    Subscribe for Alerts
    • Home
    • News
    • Politics
    • Money
    • Personal Finance
    • Business
    • Economy
    • Investing
    • Markets
      • Stocks
      • Futures & Commodities
      • Crypto
      • Forex
    • Technology
    invesloan.cominvesloan.com
    Home » A Coldcard Hacker Just Moved $1.94 Million in Stolen Bitcoin for the First Time, Is a Cash-Out Coming? | Invesloan.com
    Crypto

    A Coldcard Hacker Just Moved $1.94 Million in Stolen Bitcoin for the First Time, Is a Cash-Out Coming? | Invesloan.com

    August 7, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In the latest Bitcoin news, a wallet associated with the Coldcard hack transferred 30.185 BTC, worth about $1.94 million, to a newly created address on Aug. 7, according to on-chain tracker Lookonchain.

    The movement followed weeks of inactivity and represents roughly 1.5% of the estimated 2,055 BTC linked to the theft.

    The #Coldcard hacker, who stole 2,055 $BTC($130M), is active again.

    An hour ago, the hacker transferred 30.185 $BTC($1.94M) to a new wallet.https://t.co/Edirjbd2G0https://t.co/ksoTpGxx3g pic.twitter.com/VTL5UB9xgH

    — Lookonchain (@lookonchain) August 7, 2026

    The transfer does not confirm that the bitcoin will be sold or exchanged. However, Lookonchain reported that it was the attacker’s first movement since the initial theft, drawing attention to whether further transfers follow.

    Discover: Everyone’s Got a Take. Get Free $25 to Actually Trade Yours

    Bitcoin News: On-Chain Tracking Flags BTC Cash-Out Risk

    The wallet activity follows a major hardware-wallet breach involving more than $100 million in reported losses. On-chain analysis from Galaxy Research identified three confirmed attack waves that drained 1,596 BTC from roughly 7,300 addresses.

    A suspected fourth wave could bring the total to about 2,055 BTC, valued at roughly $130 million.

    Source: Arkham

    Before the latest transfer, Galaxy Research said roughly 90% of the stolen bitcoin had not moved from the wallets where it was sent after the reported theft.

    Because bitcoin transactions are public on the blockchain, identified attacker addresses can be tracked as funds move between wallets.

    On-chain analysts have described the transfer as a possible early sign of an attempted cash-out. Attackers seeking to convert stolen assets may move funds through a series of wallets before attempting to exchange them for other assets or fiat currency.

    Discover: Your Market Calls Are Worth Something. Start With Free $25 on Kalshi

    Firmware Flaw Exposed Cold Storage Devices

    The breach stemmed from a software vulnerability in Coldcard hardware wallets made by Toronto-based Coinkite. In an update, Coinkite said affected firmware dating to March 2021 used a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator when generating wallet seeds.

    🚨URGENT COLDCARD SECURITY UPDATE

    Read carefully before acting.

    Mk3 seed generated on 4.0.1+ without ≥50 private, independent dice rolls: begin a careful migration now.

    👉Mk4/Mk5 <5.6.0 or Q <1.5.0Q: update first, generate a new seed, then migrate.https://t.co/HshUxevCl3 https://t.co/zrkUuACRyE

    — COLDCARD (@COLDCARDwallet) July 31, 2026

    The flaw allowed attackers to reconstruct wallet seed phrases or private keys without physically obtaining the devices. Seed phrases act as the keys used to authorize bitcoin transactions.

    Coinkite advised users who generated seeds on vulnerable firmware to move their funds to safe addresses or use fresh seeds. The company also released firmware updates, though existing seed phrases generated on vulnerable devices remain at risk and should be replaced, according to the company and Galaxy Research.

    What to Watch as Attacker Wallets Awaken

    The immediate focus is on whether the 30.185 BTC sent to the new address moves again.

    Further transfers could provide additional information about how the stolen funds are being handled, though the initial transfer alone does not establish the purpose of the movement.

    Galaxy Research said details from the ongoing investigation, including attacker and victim addresses, have been shared with U.S. law enforcement agencies, cryptocurrency exchanges and cyber-investigation groups.

    The firm said identifying additional attacker addresses remains important so those addresses can be reported to authorities.

    Discover: Get Paid to Be Right, $25 to Start on Kalshi

    Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit

    The post A Coldcard Hacker Just Moved $1.94 Million in Stolen Bitcoin for the First Time, Is a Cash-Out Coming? appeared first on Cryptonews.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Keep Reading

    Google Gemini AI Predicts Chainlink (LINK) Could Hit $100 in 2026 | Invesloan.com

    Sam Altman ChatGPT AI Predicts XRP Could Hit an Unbelievable Price by 2027 | Invesloan.com

    XRP Price Eyes New Catalyst as Ripple Partners With South Korea’s Meritz | Invesloan.com

    Bitcoin Price Prediction: Should You Buy Gold or BTC Before FOMC? | Invesloan.com

    XRP News: XRPL $2.2B Tokenization Depends on Energy Token | Invesloan.com

    Bitcoin Price Set for a Boost: Arthur Hayes Bets on an AI Boom Bust | Invesloan.com

    French President Betting Odds: What Does Le Pen’s 43.3% Snapshot Mean? | Invesloan.com

    Cardano News: CIP-0113 Upgrade Could Change ADA Future | Invesloan.com

    Why is Crypto Down? Bitcoin Lost $2,000 in A Flash Crash | Invesloan.com

    LATEST NEWS

    Amazon confirms retail layoffs impacting underneath 1,000 company roles | Invesloan.com

    October 7, 2026

    Jacob Coxon Says This Is Why Pacing the Frontier Might Not Work | Invesloan.com

    October 7, 2026

    Options merchants are betting on a dramatic drop in rates of interest | Invesloan.com

    October 7, 2026

    Jamaal Howard executed after Supreme Court rejects pentobarbital attraction | Invesloan.com

    October 7, 2026
    POPULAR

    China’s first passenger jet completes maiden commercial flight

    May 28, 2023

    Numbers taking US accountancy exams drop to lowest level in 17 years

    May 29, 2023

    Toyota chair faces removal vote over governance issues

    May 29, 2023
    Advertisement
    Load WordPress Sites in as fast as 37ms!
    Facebook Twitter Pinterest WhatsApp Instagram
    © 2007-2023 Invesloan.com All Rights Reserved.
    • Privacy
    • Terms
    • Press Release
    • Advertise
    • Contact

    Type above and press Enter to search. Press Esc to cancel.

    invesloan.com
    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}