Morning Edition · Thursday, August 6, 2026Published at 1:48 AM EDT · New York
Coldcard Attacker Begins Mixing Stolen Bitcoin as Volunteer Auditors File 85 Critical Bugs Across Bitcoin Code
Galaxy Research says the largest identified attacker address still holds 1,159 bitcoin untouched. The Bitcoin Red Team has logged 4,962 findings across 390 open-source repositories since the theft.

There is new movement in the theft that drained bitcoin from users of COLDCARD hardware wallets. On-chain investigators told crypto.news that the largest known attacker address, which holds 1,159 bitcoin (BTC), remains untouched. A separate attacker has started sending smaller amounts through a mixing service. Galaxy Research is tracking the balances.
The root cause is not a smart-contract bug but a defect in how the device created keys. A firmware build from March 2021 routed wallet seed creation through a software random number generator (RNG) instead of the hardware one. That narrowed the range of possible seeds and made affected wallets reconstructible by anyone who found the flaw. Thefts began on 30 July from long-dormant addresses. Loss estimates diverge: BleepingComputer put the total near 1,367 BTC, about $88 million, while Bitcoin Magazine describes over $100 million drained and TechCrunch reported more than $130 million. No funds have been recovered or frozen, and no attacker has been identified. Manufacturer Coinkite shipped patched firmware and told users with seeds generated on affected versions to move their funds, a warning amplified on Bitcointalk.
The response has become an audit campaign. The Bitcoin Red Team, led by the developer known as Calle and by Rob Hamilton, says it has filed 4,962 findings across 390 open-source repositories, 85 of them rated critical. The group uses artificial-intelligence-assisted code review to search for the same class of entropy and implementation errors.
Analysts are treating the episode as a question about custody. Cantor expects regulated custody providers to benefit, and FRNT expects some holders to shift toward bitcoin exchange-traded funds (ETFs), according to CoinDesk. Bitcoin Magazine's own commentary argues the opposite conclusion, that a vendor defect is a reason to improve key practice rather than to hand keys to intermediaries.
- If true, who benefits
Regulated custodians and exchange-traded fund issuers gain assets and fee income every time self-custody hardware looks unreliable, and the analysts quoted arguing for that shift work at firms that sell regulated exposure.
- The nuance
The mixing activity, the 1,159 bitcoin balance and the 4,962 findings all check out (crypto.news, Cointelegraph), but every loss figure traces to one clustering estimate by Galaxy Research that ranges from 594 bitcoin in an initial sweep to about 1,367 bitcoin across 4,585 addresses, the count of attackers is unknown, and the $130 million figure is not reconciled with the $88 million one.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The failure sits in key generation, which no on-chain security review would catch, so the exposed group is holders who did exactly what self-custody guidance told them to do and used pre-2021 seeds. The immediate beneficiaries are regulated custodians and ETF issuers, who collect assets each time private key management looks unreliable. The losers are hardware vendors whose certification claims now require independent entropy verification to be credible. A second consequence runs through supply: decade-old balances that move because of theft are no longer a reliable signal of long-term holder intent.
What to watch
- Whether the 1,159 bitcoin in the largest attacker address moves, and whether it goes to a mixing service or to an exchange deposit address, which would tell investigators how confident the attacker is about cashing out.
- Whether other hardware wallet makers publish independent audits of their entropy sources, which would show the industry treating this as a category-wide defect rather than one vendor's error.
- Flows into bitcoin ETFs and regulated custody in the coming weeks, the clearest measure of whether the theft actually pushed holders away from personal key management.
Observations to monitor, not financial advice.
Synthesized from: crypto.news · Bitcoin Magazine · CoinDesk · Bitcoin Magazine (opinion) · Bitcointalk
Part of a tracked trend
Hardware-Wallet Trust Erodes
Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.
More from this edition
- Putin Signs Russia's First Comprehensive Crypto Law, Licensing Exchanges and Custodians While Keeping the Payment Ban
- Senate Has Two Working Days to Move the Crypto Market-Structure Bill Before Recess
- Aztec Proves Private Transactions on a Laptop in Seconds as OpenZeppelin Builds Recovery for Confidential Accounts
- Circle Renews Its Coinbase Distribution Deal for Three More Years and Rules Out Dividends
- Researchers Publish Working Exploits for Two Token Drains as July's Bridge and Oracle Losses Are Documented
- Robinhood Chain Holds Near $1 Billion Secured While Its Tokenized Assets Total $27.6 Million
- 100 Million PROVE Tokens Unlock Into a Market With Thin Exchange Liquidity
- Solana Validators Weigh a Proposal to Raise Daily Token Burns More Than Tenfold
- Ethereum Foundation Funds a Tool That Lets Browsers Verify a Website Has Not Been Tampered With
- BitMart Gives United States Users Days to Withdraw as Binance Sues a Payments Firm for $470 Million
- Bitcoin Holds Above $64,000 as Ether Trades Below Its Realized Price and an ETF Winds Down
Comments
0No comments yet.