BlockBeats News, August 3rd, the latest data shows that 1359 bitcoins have been stolen in the Coldcard hardware wallet hack incident. Users have also reported that after installing the update, the device remains on the wrong page, fails to start, or appears to be bricked. This incident has become the largest bitcoin theft event of the year, and BlockBeats has summarized the event as follows:
Analysis shows that the vulnerable Coldcard firmware code in this attack was released in March 2021 and the vulnerability has been present in the open-source code for over 5 years, affecting Mk3 (and some Mk2) devices, as well as subsequent Mk4, Q, Mk5 devices in their seed generation before the fix.
On July 30, 2026, a large-scale attack targeting this vulnerability was executed. The attacker automated sweeps of hundreds to thousands of addresses in approximately 25–41 minutes. Initially, around 500 single-signature wallets and 1324 UTXOs were visible, with about 594.5 BTC attacked. Subsequent on-chain analysis expanded to around 1196 addresses, 1082.65 BTC (worth about $70.2 million). In addition, this attack primarily targeted addresses with larger balances, using a fixed high fee with no change output, swiftly consolidating funds into a few addresses.
Subsequently, Coldcard developer Coinkite issued a security advisory, preliminarily confirming seed generation issues for Mk3 (firmware 4.0.1 and later), advising affected users to proceed with caution in migrations, and speculating that the attacker may have used AI to review the open-source code and find the vulnerability.
As of August 2nd, Galaxy Research Director Alex Thorn stated that the attack incident involving the Coldcard wallet is still evolving, with more small attackers and imitators emerging, targeting the remaining Coldcard mnemonic phrases.
This incident has garnered widespread attention. Bloomberg's Senior ETF Analyst Eric Balchunas revealed that Coldcard's team consists of only 5 employees. For such a crucial company, this number is indeed too low.
In response, CZ commented, "Under the self-custody model, even if developers fix the vulnerability, wallets generated prior to the fix cannot be remedied; for users employing air-gapped devices, developers also cannot directly reach out and notify them. Until users take proactive measures, the related wallets may still be exposed to ongoing attack risks. I support self-custody, but this also means that users bear the security responsibility themselves."
Furthermore, due to the event involving AI breaking encryption devices, the institutional-grade custody platform BitGo took the lead in attempting to restore industry reputation. BitGo CEO Mike Belshe deposited 100 BTC into a public Bitcoin address on August 1st, and invited the Claude model under Anthropic to try to move the funds from that address. The platform utilizes multi-signature or multiparty computation technology to distribute signing authority to multiple independent keys. Anthropic had not publicly responded to this challenge as of August 2nd.
Possibly impacted by this, Bitcoin has been in a continuous downturn since the 31st, falling from $65,000 to $63,000.
