Coldcard RNG exploit attacker moved 0.06 BTC to a new address; $72.7M remains across original attacker wallets.
Security & Exploits ·
The operator behind the Coldcard RNG exploit has begun moving funds, transferring 0.06 BTC (~$3.78K) to a previously unused address while maintaining the bulk of stolen assets across eight original wallets. The exploit cluster accumulated 1,159.42 BTC (~$72.71M) drawn from 870 compromised addresses, leaving 1,159.35 BTC (~$72.70M) stationary in the original attacker wallets.
The movement suggests initial activity after a period of dormancy, though the sum relocated represents less than 0.01% of the total cluster value. Onchain Lens Terminal has established a dedicated monitoring section tracking exploit clusters, fund flows, and address hops to observe how stolen capital propagates across the blockchain.
It remains unclear whether the fresh address signals preparation for exchange deposit, mixing, or testing of operational security. The static position of the overwhelming majority of funds—held across the original eight addresses—leaves open whether the attacker intends gradual liquidation, long-term holding, or if the bulk remains under active control.