Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

tradingview+1tradingview+1forbesNearly two weeks after attackers began draining Bitcoin from compromised Coldcard hardware wallets, blockchain investigators are still working to establish the full scale of what analysts are calling the worst self-custody failure in Bitcoin's history. Estimates of total losses range from roughly $100 million to $130 million, with the final tally likely to remain uncertain because victims must self-report.
Galaxy Research, led by head of firmwide research Alex Thorn, put its high-confidence minimum at 1,730 BTC as of Tuesday, with a potential ceiling near 1,816 BTC. Thorn told Cointelegraph that more than 450 BTC had been directly confirmed through victim reports, which in turn helped identify additional unknown victims holding over 730 BTC combined. TRM Labs independently estimated that attackers drained approximately 1,816 BTC from more than 5,200 addresses across four waves, with global head of policy Ari Redbord warning the number should be expected to climb further.tradingview+1
CryptoQuant takes a stricter, disclosure-based approach. Its head of research, Julio Moreno, said the platform's confirmed tally stands at 1,432 BTC, describing it as a floor. "Because the stolen Bitcoin belonged to individuals and not to a centralized entity, like an exchange, we can only confirm what each victim publicly discloses," Moreno said.crypto-economy+1
The vulnerability traces to a firmware change in March 2021 that caused Coldcard's seed generation to bypass the device's hardware random-number generator, substituting a predictable software function with as few as 40 bits of effective entropy instead of the intended 128. That reduction made brute-force key recovery computationally feasible without physical access to the device. At least 15 independent attackers exploited the weakness starting July 30, sweeping funds from thousands of single-signature wallets in rapid succession.forbes+3
Bitcoin developer James O'Beirne has said he raised the flawed randomness code with Coinkite in May 2025, more than fourteen months before the exploit surfaced. According to reporting by Phemex, Coinkite's response was that the issue would likely have already manifested if it were real.phemex
Coinkite deployed patched firmware on July 31 but warned that the update cannot improve the entropy of seeds already generated. Affected users must create entirely new seeds and migrate funds. The company also reversed its customer-data auto-deletion policy on August 6 and 7, citing "ongoing and anticipated legal proceedings," though no lawsuit has been publicly filed.etfdb+1
The incident has reignited debate over self-custody versus institutional solutions. On Bloomberg Crypto, Thorn said Bitcoin would "survive" the breach, framing it as a manufacturer failure rather than a protocol flaw. River, the Bitcoin financial services firm, echoed that distinction: "The Coldcard vulnerability does not affect the Bitcoin protocol or anything related to how Bitcoin works."bloomberg+2
Still, the episode has driven capital toward exchange-traded products. Spot Bitcoin ETFs recorded $853 million in net inflows for the week ending August 7, the strongest weekly figure since mid-April. BlackRock's iShares Bitcoin Trust captured the majority of those flows.cryptorank+1
For holders still on affected devices, the message from researchers is unambiguous: updating firmware alone is not enough. Only a freshly generated seed on confirmed patched firmware secures remaining funds.phemex+1