Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.




Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Five days after the first sweep, the Coldcard incident has stopped looking like a single event and started looking like a slow harvest. Blockchain analysts tracked a fourth round of drains running through Monday, and the running total of observed losses is now closing on $114 million. What has not happened is the price collapse many traders expected. Bitcoin reclaimed $63,000 in Asian hours on Tuesday and touched just above $64,100 overnight, up roughly 2 percent on the day.

That gap between the severity of the security failure and the calm in the order book is the real story right now.
What actually happened to the Coldcard wallets?
The failure was not a phishing attack, not malware, and not physical access to anyone's device. It happened at the moment each wallet was created.
Coldcard firmware calls a function to pull randomness when it generates a recovery seed. Two implementations of that function sat in the codebase with the same signature: the hardware random number generator that Coinkite wrote for the STM32 chip, and a software fallback inherited from MicroPython. A preprocessor guard checked only whether a build setting was defined and never tested its value, so the build completed against the software fallback without a single warning.
The result was seeds that looked completely normal. The firmware kept producing valid BIP-39 recovery phrases, and the values passed routine testing because they appeared random enough, which is exactly why the weakness sat undetected for so long. Block's analysis showed that an attacker able to determine or narrow down the device UID, timer state, and prior call history could reproduce candidate output streams offline, without ever touching the device.
Block traced the change to a commit dated 1 March 2021, shipped in firmware 4.0.0 that same month. That means some of the affected wallets were quietly guessable for more than five years.
How large are the losses now?
The figures have moved every day, and the reason is that different firms are measuring different transaction sets.
The first public number came from Coinkite's own advisory and Chainalysis: roughly 594 BTC, about $38 million, taken from around 500 wallets in a 25 minute window that ended just before 02:00 UTC on 31 July. Galaxy Research then mapped a separate and larger sweep, identifying 1,196 addresses holding about 1,082.65 $BTC, worth roughly $70.2 million, drained across 41 minutes.
A third wave surfaced over the weekend. By Monday the tally across three waves stood at roughly 1,367 BTC, close to $89 million, taken from about 4,585 addresses. The average haul per address fell with each round, which suggests the operator worked through the large balances first and then moved down to wallets worth a few thousand dollars. The fourth wave ran through Monday and took roughly 449 BTC from 709 addresses on the revised count, and Galaxy has not confirmed whether the same operator is behind it.
Add it up and observed losses are in the $114 million to $116 million range, from a bug in a device whose entire purpose was to make this impossible.
Which devices are affected, and does a firmware update fix it?
This is the part that matters most for anyone holding a Coldcard.
Coinkite says the issue covers Mk3 firmware versions 4.0.1 through 4.1.9, and its updated advisory also includes seeds generated on Mk4, Mk5, and Q devices before the latest firmware fixes. The initial advisory suggested Mk4, Q, and Mk5 were clear, so the scope has widened since Friday.
Updating does not repair anything. A weak seed is already a weak seed, and new firmware cannot retroactively add entropy to a key that was generated years ago. The correct sequence is to update the device first, generate a completely new seed, and only then move funds across after verifying the replacement wallet.
Block, Trezor, and Ledger have all confirmed their own devices are unaffected.
Was AI used to find the bug?
Coinkite thinks so, and said as much publicly.
The company assumes someone ran AI tooling over previous versions of its open-source firmware to surface the flaw, and noted that it had put one of the best available models over its own code a few weeks earlier and the model found nothing serious. Its blunt conclusion was that attackers and defenders now hold the same tools, and in this case the tools only helped one side.
There is a second detail worth flagging. Investigators found the operator used a paid account at a well known blockchain services provider to run the queries needed for the sweep, with the provider apparently serving what looked like ordinary requests. Block has handed the information to authorities.
Taken together, the incident redraws the threat model for cold storage. Cold storage guarantees that a key is unguessable. Holders read that as a guarantee that a key is unreachable. Those are not the same promise, and the cost of finding flaws in the first one keeps falling.
Why has Bitcoin held up despite all of this?
Because the money that left those wallets did not leave the market, and because positioning never got panicked.
Options desks show no stress. The 30 day implied volatility index has sat near 37 percent for several sessions, and the most traded contracts on Deribit are calls at $68,000 and $70,000, which are bullish bets. Spot flows told a similar story: ether funds took small inflows while Bitcoin funds saw an outflow, an unusual split for a market where BTC normally leads.

The bigger drag on price this week arguably is not the hack at all. Strategy disclosed on Monday that it sold 1,638 BTC for about $105 million between 27 July and 2 August, its third sale of 2026, at an average price of $63,957 against a cost basis of $75,419. Proceeds went to preferred dividends and STRC buybacks rather than back into Bitcoin. Holdings now sit at 842,138 BTC and the company has not bought any in more than five weeks.
A treasury company selling below its own cost basis is a clearer signal about demand than a wallet exploit is.
What should holders take from this?
Three practical points.
First, verify at creation, not after. Every major failure of this class, including the 2023 Milk Sad PRNG bug, happened at the moment the wallet was made, which is the one moment a user cannot independently check no matter how disciplined they are afterwards. Generating a seed with a verifiable process, or splitting risk across devices from different manufacturers, addresses that directly.
Second, single vendor concentration is a risk in itself. Roughly 500 holders in the first wave alone shared the same failure because they shared the same supply chain.
Third, keep the numbers in perspective. TRM Labs counted 207 separate incidents in the first half of 2026, the most ever recorded in a half year period, yet total losses came to about $972 million, less than half the $2.3 billion stolen in the first half of 2025. More attacks, smaller hauls. The Coldcard event is severe because of where it broke, not because of its size.
What to watch next
The immediate level is $63,000, which has been reclaimed and lost twice in three days. A third failure would point to thinner support below $62,500. Beyond price, two things will shape the aftermath: whether consumer protection or financial regulators respond at all, which will tell us how governments intend to classify hardware wallets, and whether Galaxy confirms the fourth wave came from the same operator or a copycat working from published research.
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text.
Related articles
- 594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
- Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
- $130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
- How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
- How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
October 2, 2026 10:36 AM

Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Hot wallet or cold wallet: the difference rests solely on whether the private key is online. What separates the two forms, where the limits of hardware lie and why moving to your own device triggers no tax.
August 23, 2026 10:15 AM

Coldcard 5.6.1 Is Here: Why the Update Will Not Rescue Your Old Seed
Coinkite shipped Coldcard firmware 5.6.1 and 1.5.1Q on August 20, 2026. The update closes the gap for new seeds but does not repair a seed already affected.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 21, 2026 7:26 PM

Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
Your seed is yours; the device belongs to a company. This article explains what the open BIP39 standard actually guarantees, why a wrong derivation path makes a full wallet look empty, and the test that settles both in twenty minutes.
September 24, 2026 10:11 PM

Bitcoin Price Prediction: What to Check on Levels, Holding Period and Leverage Before the October 28 Rate Decision
Bitcoin is trading at around $83,800, a third below its October 2025 high, while the sentiment index reads greed. Which dates, levels and deadlines over the coming weeks really decide your net gain, and which of them you steer yourself.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
August 1, 2026 10:59 AM

Bitcoin Treasury Model Under Fire: Strategy Posts $8.22 Billion Loss as BTC Slips Below $63,000
Strategy booked an $8.22 billion quarterly loss and Coinbase missed again. Here is what crypto's brutal earnings week means for Bitcoin.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 2, 2026 10:04 AM

Crypto News Today: Hawkish Fed, a $70M Wallet Hack and Bitcoin's Shaky Start to August
Crypto news today: the Fed split 9-3, a Coldcard flaw drained $70M in BTC, and ETFs turned red. Here is the full week and what lands next.
August 20, 2026 4:24 PM

Bitcoin Across Multiple Wallets: How Austria Works Out the Acquisition Cost
Bitcoin spread across several wallets? How Austria works out the acquisition cost and the rolling average price for tax purposes.
August 22, 2026 10:29 AM

Bitcoin Fork: What Happens to Your Coins When the Chain Splits
On October 31, 2026 a new chain called ECX splits off from Bitcoin, and every holder is credited automatically. Who actually receives the coins depends on the private keys, on voluntary replay protection and on a tax rule many overlook.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
July 6, 2026 5:43 PM

Ethereum Price Prediction: BitMine Buys $74M ETH as Strategy Sells Bitcoin
Ethereum price prediction as BitMine adds more ETH while Strategy sells Bitcoin. Is institutional money rotating from BTC to ETH?
April 17, 2026 10:14 PM

FIBE Berlin 2026 Review: Bitcoin, AI Trading & Tokenization at Europe's Biggest FinTech Conference
FIBE Berlin 2026 brought together the future of finance — from AI-powered crypto portfolios to Bitcoin self-custody and tokenized real-world assets.
February 18, 2026 9:19 PM

Why Bitcoin is Crashing: The Quantum Threat and the Ghost of Lost Coins
Bitcoin underperforms in 2026 as markets weigh the return of 4M lost coins against quantum computing threats. Discover why institutional demand isn't enough.
September 1, 2026 10:22 AM

Crypto News Today: Bitcoin Stalls While Zcash and Monero Steal the Show
Crypto news today: Bitcoin cools after its best week in three years, Saylor buys again, and privacy coins keep running. Here are the prices and levels.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
August 11, 2026 5:35 PM

Is Bitcoin a Good Buy at Current Prices?
Bitcoin trades about a third below its twelve-month high and has reclaimed both moving averages. What chart structure, RSI and trading volume say about buying at current prices.
May 15, 2026 9:47 AM

Top 10 Altcoins to Buy in May 2026 as Bitcoin Recovers
Here are the top 10 altcoins to buy in May 2026 as Bitcoin rebounds near $80K and market momentum shifts.
August 31, 2026 4:12 AM

Cronos chain halt: how a Tectonic exploit emptied the chain's largest lending market
On August 30, 2026, the validators of the Cronos chain halted block production after an attacker had emptied the lending market Tectonic via an inflated TONIC price. What is established, why the damage figures diverge, and what you can check if your balance sits on a haltable chain.
March 29, 2026 7:02 PM

Is This the First Real Global Liquidity Crisis of the Crypto Era?
War, oil shocks, and tightening liquidity are hitting crypto markets. Is this the first real global liquidity crisis of the crypto era?
October 2, 2026 7:16 AM

$1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
The security firm CertiK counts around $1.26 billion in damage from 247 incidents for the third quarter of 2026. September was the worst month of the year with 99 cases, and this is the background and what it means for your custody.
September 25, 2026 1:47 PM

Magic Eden and Limit Break exploit: 530 WETH and thousands of NFTs drained, how to revoke your approvals
A bug in Limit Break's Payment Processor, the protocol behind Magic Eden's former Ethereum marketplace, has been draining NFTs and WETH since Thursday. Our blockchain analysis shows 911 affected wallets. What happened, why hardware wallets do not protect you and which two approvals to revoke now.
More from CryptoTicker


