Nearly $32 Million in Dormant Bitcoin Moves After Coldcard Hack Reaches Estimated $130 Million
Key Takeaways
- •A Bitcoin address inactive since 2013 transferred 500 BTC, worth approximately $31.8 million, in a single transaction with a fee of only about $0.12.
- •Hackers have exploited a vulnerability in Coldcard hardware wallet software, with estimated stolen funds rising from $35 million to potentially $130 million across at least four attack waves.
- •Coinkite, the manufacturer of Coldcard, acknowledged that all of its hardware wallet models are now considered vulnerable to the exploit.
- •The coins were last moved in 2013 when Bitcoin traded below $150, meaning the holder's original cost basis was a tiny fraction of the current transfer value.
- •Galaxy Research is investigating a fourth wave of attacks tied to the Coldcard vulnerability, and engineers have warned that all associated Bitcoin addresses could eventually be at risk.

A Bitcoin address that had been inactive for 12 years moved 500 BTC — worth approximately $31.8 million at current prices — in a single transaction on Tuesday, drawing attention from the cryptocurrency community amid an ongoing security crisis involving Coldcard hardware wallets.
Blockchain data confirms that the legacy address transferred all funds in one transaction, paying a fee of just 191 sats, or roughly $0.12. The on-chain activity was first flagged by blockchain analytics account Lookonchain on X.
The transaction attracted heightened interest due to the recent wave of wallet drainages tied to Coldcard devices, with some observers speculating that the long-term holder relocated the funds to a more secure setup.
Last week, hackers began draining more than $35 million in Bitcoin from wallets after exploiting a vulnerability in Coldcard's wallet software. The estimated total has since risen sharply. Galaxy Research said on Monday that it was investigating a fourth wave of attacks and that the total amount drained could now stand at approximately $130 million.
Coinkite, the company behind Coldcard, acknowledged on Sunday that all of its hardware wallet models are now considered vulnerable following additional thefts. Engineers have warned that all Bitcoin addresses associated with Coldcard devices could eventually be at risk, prompting urgent calls within the community for users to migrate their holdings to a new security configuration. Coldcard wallets are Bitcoin-only devices manufactured by Coinkite and have been widely used by self-custody advocates for their air-gapped design, making the scope of the vulnerability particularly significant within the hardware wallet segment.
Bitcoin that remains unmoved for many years is often presumed to be lost, as early investors sometimes lose access to their private keys. However, large holders — commonly referred to as whales, or entities controlling more than 1,000 BTC — do occasionally relocate funds after extended periods of inactivity. The coins in question were last moved in 2013, when Bitcoin traded below $150, meaning the holder's cost basis was a small fraction of the current transfer value. Such movements can trigger market reactions, as other market participants sometimes interpret them as a precursor to a large sale. In many cases, however, whales are simply transferring holdings to a hardware wallet or consolidating positions.
The original article by Mathew Di Salvo was published by Bitcoin Magazine.