TRM Labs said the attackers could reconstruct affected private keys without opening, stealing, or modifying the hardware wallets. The blockchain intelligence firm attributed the error to a build configuration introduced with firmware version 4.0.1.
On-chain estimates cited by TRM Labs placed the preliminary loss at about 1,816 $BTC, worth approximately $116 million, across more than 5,200 addresses. Four suspected waves began on July 30, though TRM warned that the total could change as investigators confirm victim reports and trace additional addresses.
Gray says self-custody itself did not fail
In an Aug. 6 analysis, Gray described the incident as a failure in the process used to create private keys rather than a compromise of Bitcoin or the physical security components inside Coldcard devices.
No attacker needed to steal a device, obtain its PIN, or install malicious firmware, according to Gray. Once attackers reconstructed a vulnerable seed, they could derive its associated private keys and sign transactions from another system.
“The people who bothered adding their own dice rolls for extra entropy walked away untouched, while the people who just trusted the device to handle it got wiped out,” Gray said.
Coinkite’s advisory supports the distinction involving independent randomness. Users who entered at least 50 fair, private, and independent dice rolls while creating their seed are not considered at risk from the random-number-generator flaw alone. Between 50 and 98 rolls added at least 128 bits of entropy, while 99 or more added about 256 bits, the company said.
Fewer than 50 rolls do not meet Coinkite’s stated exception. Users who cannot remember how many rolls they entered, whether the process was private, or which final seed words they retained were advised to migrate their funds.
Gray argued that the incident should not be treated as evidence that centralized custody is safer in every case. In his view, self-custody requires users to verify how their keys are created instead of relying only on the product’s listed security features.
“Blind trust is what failed here, and self-custody is taking the blame it doesn’t deserve. If you haven’t independently verified your entropy, you don’t actually know what you’re holding, no matter how many security features are stacked around it.”
His TEXITcoin post also separated the event from phishing, malicious firmware, and supply-chain attacks. Gray classified the firmware problem as a severe mistake by a wallet maker rather than evidence that Coinkite designed the product to steal customer funds.
Coldcard losses have changed custody decisions
User behavior has moved in a different direction from Gray’s recommendation. OKX reported record deposits after the incident, as some Bitcoin holders transferred assets from personal wallets to centralized platforms.
As previously reported by crypto.news, OKX Chief Compliance Officer Jonathan Brockmeier said the inflows represented the opposite of the behavior seen after FTX collapsed, when users withdrew assets from exchanges and moved them into self-custody.
Gray rejected the idea that leaving Bitcoin on an exchange resolves the problem. Centralized services control customer keys and can freeze withdrawals, suffer security breaches, or fail financially, he said.
“Running back to an exchange because a device let you down isn’t a solution either, since that’s just handing your risk, and your keys, to someone else to lose instead,” Gray said.
Blockchain investigators have not attributed the theft to one identified group. TRM said differences in transaction construction across the suspected waves could indicate several attackers, while most stolen Bitcoin had initially remained in consolidation addresses.
The firm detected limited laundering activity, including a 64.9 $BTC deposit to Wasabi and 200 ETH sent through Tornado Cash on Aug. 4. TRM said the transaction pattern differed from the fast laundering methods often associated with organized state-backed hacking groups.
US investors face a different custody trade-off
For American investors who only want exposure to Bitcoin’s price, U.S.-listed spot Bitcoin exchange-traded funds remove the need to generate seeds, update wallet firmware, or maintain physical backups.
Bloomberg Intelligence analyst Eric Balchunas said the Coldcard losses strengthened the case for regulated spot Bitcoin ETFs. A report on ETF custody noted that products such as BlackRock’s iShares Bitcoin Trust ETF rely on institutional custodians rather than requiring shareholders to control private keys.
BlackRock’s SEC filing identifies Coinbase Custody as the main custodian for IBIT’s Bitcoin and names Anchorage Digital Bank as another custodian the trust may use. Shareholders own exchange-traded securities, however, and cannot withdraw the underlying Bitcoin to a personal wallet or use it for payments.
Institutional custody also transfers risk instead of removing it. IBIT’s filing lists hacking, employee misconduct, technical failures, and unauthorized transfers among possible sources of loss. The filing also says insurance shared by Coinbase may not cover every potential incident.
Coldcard users must replace vulnerable seeds
Coinkite has released fixed firmware for every affected model, including version 4.2.0 for Mk2 and Mk3 devices, version 5.6.0 for standard Mk4 and Mk5 devices, and version 1.5.0Q for the standard Coldcard Q.
Installing an update only corrects the generation of future seeds. Coinkite said firmware cannot add randomness to an existing recovery phrase because the weakness remains attached to the seed even if a user imports it into another wallet.
Affected users were instructed to install the correct firmware, generate a completely new seed, verify its fingerprint and receiving address, and send a small test transaction before moving the remaining balance. Coinkite advised users to retain the old backup until the transfer reaches the replacement wallet and receives network confirmation.