BlockBeats report, August 3: Latest data shows that 1,359 bitcoins have been stolen in the Coldcard hardware wallet hacking incident. Additionally, users have reported issues such as devices getting stuck on error pages, failing to boot, or appearing bricked after installing updates. This incident has become the largest bitcoin theft of the year. BlockBeats has compiled the timeline of events as follows:
Analysis shows that the compromised Coldcard firmware code was released in March 2021; the vulnerability existed in the open-source code for over five years and affected seed generation on Mk3 (and some Mk2), as well as subsequent Mk4, Q, and Mk5 models prior to the fix.
Large-scale attacks exploiting this vulnerability were carried out until July 30, 2026. Over a period of approximately 25–41 minutes, attackers automated sweeps targeting hundreds to thousands of addresses. Initially, around 500 single-signature wallets and 1,324 UTXOs, totaling approximately 594.5 BTC, were compromised; subsequent on-chain analysis expanded the scope to about 1,196 addresses and 1,082.65 BTC (valued at approximately $70.2 million). Additionally, the attack prioritized addresses with larger balances, employed fixed high fees, and produced no change outputs, rapidly consolidating funds into a small number of addresses.
Subsequently, Coinkite, the developer of Coldcard, released a security advisory confirming initially that the seed generation issue affects Mk3 (firmware 4.0.1 and later), advising affected users to migrate cautiously, and speculating that attackers may have used AI to review open-source code to identify the vulnerability.
As of August 2, Galaxy research lead Alex Thorn stated that the attacks surrounding the Coldcard wallet are still evolving, with more small-scale attackers and imitators emerging to target remaining Coldcard mnemonic phrases.
This incident has drawn attention from multiple parties. Eric Balchunas, Senior ETF Analyst at Bloomberg, revealed that the Coldcard team consists of only five employees—a surprisingly low number for such an important company.
CZ commented, "In a self-custody model, even if developers patch the vulnerability, they cannot fix wallets that were already generated; for users employing isolated devices, developers cannot directly contact or alert them. Until users take proactive action, affected wallets may remain exposed to attack risks. I support self-custody, but this also means users bear full responsibility for their own security."
Additionally, since the incident may involve AI compromising cryptographic devices, institutional custody platform BitGo took the first action to help restore the industry’s reputation. On August 1, BitGo CEO Mike Belshe deposited 100 BTC into a publicly accessible Bitcoin address and invited Anthropic’s Claude model to attempt to transfer the funds. The platform employs multi-signature or multi-party computation technology to distribute signing authority across multiple independent keys. As of August 2, Anthropic had not publicly responded to this challenge.
Affected by this, Bitcoin has remained weak since the 31st, dropping from $65,000 to $63,000.

