Coldcard Exploiter Moves 45% of Wave 3 Stolen BTC Funds
A firmware bug Coinkite shipped in 2021 is still bleeding wallets nearly two months after the first drain.
Every Zipp story tagged #Coldcard, newest first.
A firmware bug Coinkite shipped in 2021 is still bleeding wallets nearly two months after the first drain.
The case just shifted from a static forensic ledger to a live cross-chain trace: 20.5 BTC routed through 34 swaps while 1,402 BTC of identified loot still sits parked.
The bug was structural rather than random: a feature flag treated as present let attackers reconstruct private keys from a single button press, and Coinkite says severe losses have occurred even…
The patch tightens the RNG and signing flow, but seeds from affected firmware between 2021 and July 2026 still need replacement. AI-assisted auditing is the broader industry signal here.
The bug sat in open-source code for five years while a community built on 'don't trust, verify' outsourced its judgment to one vendor's reputation, Foundation CEO Zach Herbert argues.
The figures put custody choices at the center of Bitcoin's adoption story, while sustained activity will determine how durable the signal is.
Russia's Sept. 1 crypto framework caps retail buying at 300,000 rubles and forces transactions through regulated depositories, so users are moving keys offline before the rules bite.
Security-driven wallet migrations can mimic selling pressure, making bearish on-chain readings a poor standalone signal while the AI findings await validation.
Coldcard's migration guidance adds an immediate wallet-security issue to the fund movement, with specific device versions and seed setups requiring action.
The warning shifts the custody debate from storage location to the controls protecting and using private keys.
Bitcoin trades 50% below its all-time high while long-term holders redistribute, a setup that points to custody reshuffling after the Coldcard breach rather than the profit-taking that has…
Dormant supply from when bitcoin traded near $10 is resurfacing as Coinkite's $114M Coldcard exploit sends long-term holders back to audit old storage setups, with the receiving address already wired…
The spike traces to the Coldcard firmware exploit, with the channel reading it as holders migrating seeds to alternative custody rather than shifting market conviction.
Coldcard losses alone climbed past $100M as investigators widened the scope, proving a vendor-level flaw can drain thousands of cold wallets at once.
The $114M drained from best-practice self-custody users is the strongest argument yet that holding your own keys still means trusting the silicon.
The 77,000 BTC moving isn't selling pressure; it's users fleeing a hardware-wallet bug. Every bearish on-chain reading this week is suspect, since the largest flow since FTX wasn't economic, it was…
Galaxy Research has traced 1,596 BTC stolen across three confirmed attack waves, with a suspected fourth wave that would push total losses to roughly 2,000 BTC.
Four Coldcard wallet sweeps have drained hundreds of BTC, yet BTC still trades above $63,000. The bid is treating it as a per-holder operational leak rather than a protocol-level event.
The 55% surge in on-chain activity is the cleanest real-time signal that the Coldcard breach is forcing users to move funds, not just talk about it.
The figure is roughly twice the early read on the incident and lands Coldcard inside a growing supply-chain risk tier no Bitcoin custodian can ignore.