Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Coldcard Firmware Bug Drains Nearly 1,367 Bitcoin, CZ Tells Holders to Split Their Wallets

A cold-storage device wasn't cold enough
Bitcoin holders who thought a hardware wallet sitting in a drawer for years was untouchable got a hard lesson this week. Coldcard, a hardware wallet made by Canadian company Coinkite, shipped firmware between March 2021 and version 5.0.3 with a bug in how it generated recovery seeds. Coinkite disclosed the flaw July 30 and pushed emergency patches, according to Coinkite's own advisory as reported by The Daily Hodl.
The bug is specific and ugly. Instead of relying fully on the device's hardware random-number generator, affected firmware leaned on a software-based source of randomness when creating recovery seeds. Weak randomness means fewer possible seed combinations, which means an attacker with enough computing power can guess or reconstruct the private keys offline. No phishing. No malware. No physical theft of the device. Just math, according to financefeeds.
This wasn't a user mistake. It was a manufacturing-level flaw baked into the product for roughly four years before anyone caught it.
Three waves, falling further underground
Blockchain analytics firm Galaxy Research has been tracking the drain in real time. The first wave hit fast and hard: 1,082.65 BTC pulled from 1,195 addresses in just 41 minutes starting at 01:10 UTC on July 30, according to Galaxy Research figures cited by ZeroHedge. That's an average of nearly a full coin per victim, worth roughly $70-75 million depending on which snapshot you use. Cryptotimes.io put the running total at $75.1 million shortly after wave one.
Wave two, on July 31, was smaller: just 76.16 BTC taken from 1,478 addresses, a median loss of only 0.010 BTC per wallet. Wave three ran into Saturday morning, August 1, pulling another 207.73 BTC from 1,912 addresses, with a median loss of 0.013 BTC. Total observed losses across all three waves now stand near 1,367 BTC, close to $89 million, according to ZeroHedge's reporting on the Galaxy Research data.
The attacker's methods shifted across the waves. Waves one and two moved stolen coins through shared collector addresses into plain, traceable single-key wallets. Wave three didn't. Each victim's coins now land in separate destinations, sitting in 293 individual P2WSH vaults, a wallet format that hides spending conditions until the coins move again. The sweeper also started batching multiple victims per transaction and stopped scanning multiple derivation paths, tightening its process. That's either the same operator adapting after being tracked in public, or a second party working the same broken key space independently, ZeroHedge reported.
Separately, cryptotimes.io noted that Galaxy Research found the stolen Bitcoin sitting untouched across seven attacker-controlled addresses in the early going, unusual for a theft this size. Researchers suggested the attacker may be waiting for public attention to fade, or hasn't yet found a way to move funds without being traced. Wave three's shift to fragmented, less-traceable wallets suggests that calculus may be changing.
CZ's advice, and its limits
Binance founder Changpeng Zhao, known widely as CZ, weighed in Saturday, August 1, on X. "Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs," he wrote, according to financefeeds and The Daily Hodl. His suggested mitigation: "Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!"
CZ's fix is reasonable but incomplete, and he says so himself. Splitting funds across wallets reduces the damage if one device or firmware version fails, but it multiplies the number of recovery phrases a holder has to protect and track. More seeds means more chances to lose one, mislabel one, or botch a restore. Wallet diversification cuts concentration risk. It doesn't touch the underlying operational burden of managing self-custody at all, as financefeeds pointed out.
There's also a harder truth buried in this incident that goes beyond any one company's bug. Coinkite's patch fixes future seed generation. It does nothing for a seed that was already created under the flawed firmware. Anyone who generated a wallet on affected Coldcard devices between 2021 and now has a seed that is permanently compromised, whether or not they ever update the software. The only real fix is generating a brand-new seed on trusted hardware and moving funds, which is exactly the kind of task lazy or inactive holders—the ones hit hardest in this attack—are least likely to do.
Nobody knows how many vulnerable wallets are still sitting out there, un-swept, waiting for whoever runs this operation, or a rival, to keep grinding through the same broken key space.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.