The Coldcard exploit, which caused more than $100 million in losses, helped push July crypto thefts to $247 million, making it the second-worst month of 2026. July emerged as the second-worst month of 2026 for cryptocurrency thefts, largely due to the recent Coldcard exploit. Hackers stole $247.4 million in crypto in July, the most this year after the $644 million stolen in April, according to DefiLlama data. The total was more than triple the $75 million stolen in June and the $60 million stolen in May. The Coldcard exploit was the month’s biggest exploit, with at least $100 million in Bitcoin (BTC) stolen from 7,300 wallets across three confirmed attack waves, according to Galaxy Digital. The company also identified a suspected fourth wave that could bring total losses to about $130 million. DefiLlama’s hack tracker estimates losses tied to the Coldcard exploit at $115 million. Read more
A week-long streak of inflows into US spot Bitcoin ETFs has coincided with the Coldcard wallet exploit, fueling debate over whether some investors are shifting away from self-custody. Demand for US spot Bitcoin exchange-traded funds (ETFs) has accelerated over the past week, with a string of daily inflows coinciding with the Coldcard wallet hack — timing that has prompted speculation about whether some investors are reconsidering self-custody. According to Bloomberg senior ETF analyst Eric Balchunas, BlackRock’s iShares Bitcoin Trust (IBIT), Fidelity Wise Origin Bitcoin Fund (FBTC), Bitwise Bitcoin ETF (BITB), ARK 21Shares Bitcoin ETF (ARKB) as well as Defiance Daily Target 2X Long MSTR ETF (MSBT) have recorded inflows every trading day since the weekend exploit, totaling roughly $620 million. The cumulative figure is consistent with Cointelegraph’s recent reporting on the ETF inflow streak. The Coldcard exploit drained more than $116 million worth of Bitcoin from over 5,200 wallet addresses, according to blo...
Hackers behind the Coldcard exploit transferred millions in digital assets to cryptocurrency mixers, while most stolen funds remained traceable in attacker-controlled wallets. About 64 Bitcoin, worth $4.17 million, and 200 Ether, worth $380,000, linked to the recent Coldcard exploit were sent to cryptocurrency mixing protocols, according to blockchain security platform CertiK. The Bitcoin transfer was from address bc1q0 to crypto mixing protocol Wasabi on Tuesday, according to blockchain data shared by CertiK. “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” a CertiK spokesperson told Cointelegraph. The 200 Ether (ETH) was transferred to Tornado Cash on Wednesday, according to CertiK’s X post. Read more
The Coldcard entropy flaw caused a crisis of confidence in hardware wallets. Here’s the details you need to know before you entrust Ledger, Trezor or Foundation with your Bitcoin. Just when you thought crypto market morale couldn’t sink any lower, along comes the Coldcard entropy bug to prove you wrong. The discovery of a flaw in one of the industry’s longest-running hardware wallets last Friday serves as a stark reminder that there is no perfectly safe place to put all your Bitcoin. Coldcard disclosed the entropy-generation flaw affecting multiple Coldcard devices on July 31. Since then, researchers at Galaxy Digital say attackers have been able to steal more than 1,596 Bitcoin worth at least $100 million through several coordinated attacks. Read more
Galaxy said that at least 15 different attackers have exploited the Coldcard vulnerability, which may have been avoided with just $2 worth of AI hardening, according to Dragonfly’s managing partner. At least 15 different attackers have exploited the Coldcard vulnerability, according to Galaxy Digital’s head of research, Alex Thorn, citing new victim reports received since the incident. Thorn said Tuesday that the victim reports helped the company label new attackers that would have gone undiscovered, as the nature of the exploit was different from a hack on a centralized exchange. “Due to one single victim’s report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses,” Thorn wrote in a Tuesday X post. Read more
The five-year bug escaped detection because auditors verified that the intended random number generator existed, but not that it was being called. Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco. In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware. “Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco. Read more
Galaxy research head Alex Thorn warned that unconfirmed transactions may give some Coldcard users a narrow opportunity to save their funds. Update (Aug. 3 at 4:19 am UTC): This article has been updated with the latest estimated number of affected addresses and Bitcoin from Galaxy’s Alex Thorn. Coldcard users are being warned of a new wave of coordinated thefts targeting their Bitcoin hardware wallets, coming just days after the first wave of attacks on Thursday. In an X post on Monday, Galaxy research head Alex Thorn flagged hundreds of transactions impacting 709 potential victim addresses, moving around 448.7 Bitcoin (BTC). Read more
The “sickening” loss of $90 million of Bitcoin from cold storage weighs heavily on sentiment, as the Clarity Act stalls with just five days left to hold a Senate vote. After $90 million in Bitcoin was drained from Coldcard wallet users, small hodlers desperately sought refuge on centralized exchanges and via alternative custody methods. Bitcoin transfers below 1 BTC climbed to their highest daily level since 2022 on Friday, with 39,600 BTC moved, according to data shared by CryptoQuant head of research Julio Moreno on Saturday. The figure was just 300 BTC below the 39,900 BTC transferred on Nov. 16, 2022, days after FTX filed for bankruptcy. Galaxy Research, the research arm of crypto investment company Galaxy Digital, reported Saturday that the third wave of attacks on users of the hardware wallet on the weekend brought estimated losses to 1,367 BTC ($88.6 million) across 4,585 addresses. Read more
Bitcoin users moved 39,600 BTC in small transactions as the Coldcard hack continued, with researchers warning that the attack remained active. Smaller Bitcoin transfers have reached levels not seen since the collapse of cryptocurrency exchange FTX amid an ongoing suspected Coldcard hack. Bitcoin transfers below 1 BTC climbed to their highest daily level since November 2022 on Friday, with 39,600 BTC moved, according to data shared by CryptoQuant head of research Julio Moreno on Saturday. The figure was just 300 BTC below the 39,900 BTC transferred on Nov. 16, 2022, days after FTX filed for bankruptcy. “The Bitcoin plebs had not moved this amount of BTC in a day since the FTX collapse,” Moreno said, adding that he was encouraged to see users “taking action.” Read more
Coinkite urged Coldcard Mk3 users to migrate funds after identifying a potential seed-generation risk, as Bitcoin security experts separately examine an unexplained $38 million wallet drain. Canadian Bitcoin hardware maker Coinkite has warned users of its Coldcard Mk3 signing device to move funds from wallets whose seed phrases were generated on affected firmware. On Thursday, Coinkite said seeds created on an Mk3 running firmware version 4.0.1, released in March 2021, or any later Mk3 version may put funds at risk. The issue extends through version 5.0.3, the final firmware supporting the Mk3, while the Mk4, Q and Mk5 are not affected, according to the company’s early analysis. The warning comes as Bitcoin security specialists examine an unexplained, coordinated sweep involving 594.48 BTC from single-signature addresses. However, no definitive public evidence has established that the Mk3 issue caused those transfers. Read more