Why Hasn't the Coldcard Stolen Bitcoin Moved?
Coldcard stolen bitcoin has sat almost untouched for three weeks straight. Of the 1,789.28 BTC — worth $114.7 million when it was stolen, and closer to $143 million at today's roughly $80,000 bitcoin price — that attackers pulled from vulnerable Coldcard hardware wallets in a rapid series of thefts starting July 30, roughly 1,561 BTC — 87.3% of the total — remains sitting in the same addresses it landed in, according to Galaxy Research's tally published Aug. 24. That's unusual for a hack this size. Most large crypto thefts see attackers scramble to cash out within days, before trackers and exchanges can react. Here, the opposite happened: the money went quiet.
The explanation isn't that the attackers lost interest or got scared off. It's that Bitcoin's ledger works against them. Every transaction is permanently public, and Galaxy Research has already attributed the theft to a specific cluster of 8,865 addresses, sharing that list with exchanges, compliance vendors and law enforcement. Any coin from that list that lands at a KYC exchange, an OTC desk, or almost any regulated on-ramp risks an automatic flag, or a frozen account, before the attacker ever gets fiat out. Sitting still costs nothing. Moving costs everything if it's spotted.
How Bitcoin's Public Ledger Traps the Attackers
This is the mechanism behind the whole story: the transparency built to let anyone audit Bitcoin's supply also lets researchers trace stolen coin the moment it moves. Once Galaxy tagged the exploit's address cluster and pushed it out to exchanges, every one of those addresses became radioactive. A transfer doesn't erase the trail, it just moves the tag one hop further down the chain, and any automated compliance system checking deposits against known-stolen-fund lists can catch it at that next hop.
That's why the rational move for an attacker holding freshly stolen, well-tagged bitcoin is to wait. Scrutiny fades over time as new stories crowd out old ones, monitoring teams reprioritize, and address lists risk going stale if nobody keeps updating them. The attackers appear to be betting on exactly that erosion. Confirmed on-chain activity from the exploit's addresses has gone quiet since August 6, and the total attributed loss has held flat at $114.7 million rather than climbing toward the roughly $130-150 million some outlets floated in early reporting, a figure that was never confirmed.
The Coins That Did Move Tell Their Own Story
The 228 BTC that did move, about 12.7% of the total, didn't head straight for an exchange. Instead, attackers ran it through CoinJoin transactions and peel chains, techniques that mix coins together or break a large sum into a trail of smaller transfers specifically to make the original theft harder to trace. That's a tell. If the attackers thought they could move stolen bitcoin straight to a cash-out point without consequence, they wouldn't bother obscuring it first. The fact that only a minority of coins got this treatment, while the bulk of the haul stayed frozen in place, suggests the attackers are laundering selectively and slowly rather than preparing a single mass cash-out.
Does This Improve the Odds of Recovery?
Not by itself, but it changes the shape of the fight. As long as the stolen coins stay in known, tagged addresses, they're effectively frozen in the open: visible, traceable, and unusable at any venue that checks deposits against compliance lists. That's a real constraint, even without an arrest. The moment any of it moves toward a regulated exchange, the same tagging that's kept the coins parked gives investigators a chance to intercept the deposit before the attacker gets paid out.
The catch is that this window only stays open as long as exchanges keep enforcing it and the address list stays current. Attackers have already shown, with the 228 BTC routed through CoinJoin, that they know how to break the trail before attempting a cash-out. A patient attacker who waits months or years, then routes everything through mixers and non-KYC venues before ever touching a compliant exchange, could still get most of it out clean. Full recovery of the $114.7 million is unlikely. A partial freeze on whatever surfaces at a compliant venue is plausible, precisely because the addresses are already known, but nothing here guarantees it.
What Happens Next
The near-term picture is more of the same: most of the 1,561 unmoved BTC likely stays parked for weeks or months, with the occasional small test transfer rather than a sudden mass movement. Coinkite, the company behind Coldcard, has already shipped firmware fixes (versions 5.6.1 for Mk4/Mk5 devices and 1.5.1Q) that close the vulnerability exploited in the original attacks, so this specific hole shouldn't produce new victims, but it does nothing for the bitcoin already taken. The story from here is a waiting game between attackers betting on fading scrutiny and researchers betting their tagging holds up long enough to matter. Readers holding a Coldcard should confirm they're on updated firmware; the theft itself is now a forensics story, not an active one.
Sources
- https://www.gncrypto.news/news/coldcard-hack-1789-btc-stolen-87-percent-unmoved/
- https://decrypt.co/375656/coldcard-bitcoin-thefts-slow-losses-top-150-million
- https://crypto.news/coldcard-hackers-leave-87-of-stolen-bitcoin-unmoved-after-114m-theft/
- https://cointelegraph.com/news/coldcard-hack-galaxy-btc-lost-87-unmoved
- https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/
- https://finance.yahoo.com/markets/crypto/articles/coldcard-hacker-just-moved-1-152800878.html
- https://finance.yahoo.com/personal-finance/investing/article/bitcoin-and-ethereum-prices-today-friday-august-28-2026-bitcoin-moves-above-81000-before-falling-back-111816647.html