The operator behind the Coldcard hardware wallet breach that netted 1,816 BTC in stolen funds moved 30.185 BTC ($1.94M) to a new wallet address in a transfer logged on-chain hours ago, according to blockchain monitoring data.
The movement represents the first activity from the theft cache since the exploit began July 30. TRM Labs confirmed in early August that the total stolen amount reached 1,816 BTC ($116M at the time of analysis), making it the largest hardware wallet compromise on record. The hacker moved funds again as law enforcement and blockchain firms track the breach's proceeds across exchange deposits and wallet consolidations.

The Coldcard exploit, which affected the widely used hardware wallet manufactured by Coinkite, exposed a critical vulnerability in the device's firmware update mechanism. Security researchers determined that attackers gained access to private keys stored on the device by exploiting the update process before firmware patches were released. Coldcard users discovered the breach after unusual transaction attempts appeared on their accounts in late July.

The 1,816 BTC figure that TRM Labs published differs from an earlier estimate by Galaxy Digital, which placed the hacker's cache as high as 2,055 BTC based on preliminary analysis. TRM's lower count reflects forensic work tracing confirmed transfers tied directly to the Coldcard vulnerability; the gap between the two estimates accounts for transactions that may have involved multiple theft campaigns or separate compromises during the same window.
Monitoring firms and exchanges have flagged addresses linked to the hacker's cache. The movement to a new wallet address today may indicate the operator is preparing for conversion to fiat currency or moving funds to avoid seizure as recovery efforts intensify. No exchange deposit has yet been detected from the transferred amount.
Blockchain monitoring remains the primary mechanism for tracking stolen Bitcoin in large breaches; unlike traditional banking infrastructure, on-chain transfers leave permanent records but offer no automatic freeze or recall mechanism. The Coldcard operator's ability to move funds freely means law enforcement faces significant practical constraints in hardware wallet compromises where the attacker gains complete control of private keys.
The hacker has now moved funds on two separate occasions from the original theft cache. Exchanges and compliance firms track whether the funds surface on trading platforms where conversion to traditional currency would trigger regulatory reporting obligations.