Coldcard Hacker Moves Bitcoin Amid CoinKite’s RNG Clarification

As per Lookonchain, a blockchain analytics platform, posted on social media platform X today, August 7, 2026 and stated that the hacker behind the Coldcard wallet incident has moved another 30.185 BTC, worth around $1.9 million, to a new wallet. This transfer comes after hackers linked to the incident stole around 2,055 BTC, or approximately $130 million. This transfer brings the incident into the spotlight once again.
Moreover, CoinKite, which is Coldcard’s parent company, stated in an X post that there was no knowingly designed weak entropy fallback in the seed generation system.
Coldcard Hacker Moves Another 3.185 BTC
The Coldcard hacker has transferred 30.185 BTC, worth approximately $1.94 million, to a new wallet. The incident represents another fund movement from an exploit that has resulted in an estimated loss of around $130 million. The hacker managed to steal 2,055 BTC through the Coldcard exploit and the above transfer shows that the wallets joined to the attack remain active, garnering attention on where the stolen Bitcoin is shifting and whether more funds will be transacted.
Amidst all of this, the company has issued a clarification statement on X and is seen to be defending itself. CoinKite denied the weakness in the X post, claiming there is no entropy fallback in its scheme. The company said that the weak PRNG, called Yesmeral, was part of MicroPython in-built random number generators. The library was released upstream in May 2018 and never integrated into the seed generation routine of Coldcard. This was done in March 2021, when migrating to IibngU. According to CoinKite, software RNG was not meant to be used for seed generation.
The company’s pattern, intended seed generation to depend exclusively on hardware true random number generator, or TRNG. CoinKite had attempted to shut down the software RNG through a setting called. However, the setting did not have the desired effect. Instead, the symbol solved MicroPython’s default implementation, allowing the software RNG to become active.
The difference is important as according to CoinKite, labeling the vulnerability as the fallback makes it look like the firm intentionally built the backup randomness mechanism into seed generation procedure. The vulnerability was inherited from the underlying platform and enabled due to a link-time error. Thus, CoinKite claims that the issue is not intentional and was enabled accidentally during the migration to IibngU in March 2021.
Canadian Bitcoin Holders Constitute for Large Losses
This exploit has shaken up the crypto industry and it has also had an effect across the geographical regions. According to Chainalysis, Canadian Bitcoin holders have been affected the most as they accounted for around 25% of the losses from the Coldcard incident. This is important because CoinKite itself is based in Toronto. Then there is Australia where there was a loss of around 15-20%, while the United States and Thailand accounted for up to 10-15% in losses. Galaxy Research previously estimated that a flawed 2021 firmware update left some Coldcard wallets generating private keys.
By Tuesday, the research firm estimated that hackers had stolen approximately $130 million. The latest Bitcoin incident is still unfolding even as the technical explanation around the issue becomes more clear. With another $1.94 million worth of BTC shifted to a new wallet, attention will remain on the hackers’ movement and whether extra stolen Bitcoin begins moving through different addresses.
Moreover, according to the data presented by Glassnode, this incident also led to a sharp rise in Bitcoin on-chain activity. On the platform, the active addresses have reached 0.98 million per day. This has been the highest level since December 2024, demonstrating holders were moving funds and shifting seeds in response to the safety threat, rather than taking up new market positions. The rise reflects a fear-centric safety response, not a shift in the comprehensive market sphere.
