More than $100m in bitcoin has been swept because of a five-year-old firmware flaw. Advisors should read it as an operational risk story.
Beginning 30 July, an attacker started sweeping bitcoin from addresses generated by Coldcard, a bitcoin-only hardware wallet made by Canadian firm Coinkite. The first burst took roughly 594 BTC from around 500 wallets in about 25 minutes.1 As of 4 August, Galaxy Research said it had high confidence that 1,596 BTC had been taken from about 7,300 addresses across three confirmed waves and 14 smaller incidents, worth more than $100m. Including a suspected but unconfirmed fourth wave, the total could reach roughly 2,055 BTC, or about $130m. At least 15 independent attackers were exploiting the same flaw, and it remained live.2
No one was phished. No device was stolen. Coinkite’s advisory traces the problem to a firmware change in March 2021 that handed key generation to a predictable software randomizer instead of the chip’s hardware one. That narrowed the range of possible keys far enough for an attacker to reconstruct them offline, without ever seeing the device. Only single-signature wallets are affected. Coinkite has published the affected models and firmware versions.3
The detail that matters for suitability
Fixed firmware shipped on 31 July, but a patch cannot repair a key that has already been generated. Owners must create a new one and move their coins, and a minority of setups built with enough independent private entropy are exempt.3
This did not catch the careless. It caught holders who had read the arguments, bought a respected bitcoin-only device and moved their coins off exchanges. The defect sat undetected for more than five years, and nothing an owner did would have revealed it. That is the part worth carrying into a client meeting: the risk was real, material and undetectable by the end user.
The flow response inverted the FTX pattern. In late 2022 holders pulled coins off exchanges. This time they sent them back. CryptoQuant recorded 39,600 BTC moving in transfers under 1 BTC on 31 July, just short of the 39,900 BTC moved on 16 November 2022, days after FTX filed for bankruptcy. Net exchange inflows hit 11,163 BTC.4
Content continues below advertisement
Custody is a spectrum, not a virtue test
Hold your own keys, or hold a listed product? The question resurfaces with every incident, and the people who built this industry decline to pick a side.
We put it to Adam Back last year. The cryptographer, now Blockstream’s chief executive, is among the handful of researchers whose work is cited in the Bitcoin whitepaper. His answer: “Both. I have done both actually. ETFs offer portfolio integration and borrowing advantages… But self-custody is crucial for maintaining decentralization and immutability.” He had already cautioned that “self custody is not for everyone.”5
David Marcus, the former PayPal president who went on to run Meta’s digital currency effort and now leads Lightspark, argues openly for self-custody and still hedges: “Personally, I think the best way to do it is a combination of custodial services by trusted entities and self-custody.”6

