Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

techcrunch+1crypto+1247wallstHackers have exploited a five-year-old firmware flaw in Coldcard hardware wallets to drain more than $130 million worth of Bitcoin from thousands of supposedly secure offline accounts, in what has become the third-largest crypto theft of 2026. The breach, which began on July 29, has rattled self-custody advocates and appears to have driven a wave of money into spot Bitcoin exchange-traded funds.
The attack traces to a March 2021 firmware integration error in Coldcard devices made by Toronto-based Coinkite. The bug routed wallet seed phrase generation to a deterministic software pseudorandom number generator instead of the device's hardware random number generator, making the resulting seed phrases predictable and vulnerable to brute-force reconstruction.thehackernews+1
At least a dozen different hacker groups appear to be exploiting the flaw, according to Galaxy Research. The first confirmed wave on July 30 drained 1,082 BTC from 1,196 addresses in just 41 minutes. By early August, Galaxy Research identified approximately $130 million stolen from roughly 7,300 addresses across multiple attack waves. TRM Labs has put the figure at over $116 million from more than 5,200 addresses.techcrunch+3
"Between 9:36 and 9:43 pm on July 29th, all three of my wallets were completely drained," victim Johnathan Goodman told Bloomberg.futurism+1
Coinkite has urged users to update firmware and migrate to new seed phrases but has declined to confirm total losses, telling Bloomberg it would not "speculate on a number we can't verify directly".futurism
In the week ending August 7, U.S. spot Bitcoin ETFs recorded $853.5 million in net inflows across five consecutive positive sessions, their strongest week since April, according to SoSoValue. BlackRock's iShares Bitcoin Trust captured over $693 million, more than 80 percent of the total.crypto+1
Eric Balchunas, senior ETF analyst at Bloomberg Intelligence, argued on August 2 that the hack made the case for ETF custody, noting that an ETF holder never touches a seed phrase because a custodian holds the Bitcoin. On-chain data showed roughly 210,000 BTC shifted from private wallets to exchanges in the days following the exploit, reversing a two-year trend of self-custody accumulation.247wallst
The timing is suggestive but not conclusive. Some 88 percent of the week's ETF inflows arrived before Friday's weak July jobs report, which showed payrolls declining by 23,000 against expectations of an 80,000 gain. That macro data better explains Friday's price rally than the ETF flows that preceded it.247wallst
However, QCP Capital noted the breach caused only limited concern in options markets, and Ethereum ETFs also posted four straight days of inflows over the same period — an anomaly if the buying were driven solely by Bitcoin holders fleeing hardware wallets. Whether the custody argument holds will depend on whether Bitcoin ETFs continue to outpace Ethereum fund flows in the weeks ahead.247wallst