2417: A $114 Million Bitcoin Hack Just Escalated - Why the Hackers Can't Cash Out artwork

2417: A $114 Million Bitcoin Hack Just Escalated - Why the Hackers Can't Cash Out

Bitcoin News Alerts | Daily BTC Macro Signal

August 3, 2026

The Coldcard incident continues escalating. Estimated losses have climbed beyond $114 million, researchers believe a fourth wave of attacks may already be underway, and the emergency firmware hotfix is now facing additional issues.
Speakers: Justin Verrengia
**Justin Verrengia** (0:00)
The Coldcard hackers have a new problem, and it has nothing to do with stealing Bitcoin. It has everything to do with trying to spend it. Let's get right into it. Just when Bitcoiners thought this nightmare couldn't get any worse, it did. Researchers now believe a fourth wave of Coldcard attacks is already underway. The estimated losses have now climbed to more than $114 million, and the emergency firmware hotfix is no longer the end of the story. For many Bitcoiners, the damage has already been done. More than 4,500 Coldcard wallet addresses have now reportedly been affected. Life savings have disappeared. Families have watched years of disciplined savings vanish in a matter of minutes. Confidence in one of Bitcoin's most trusted hardware wallets has been shaken. But while the hackers may have stolen the Bitcoin, they haven't solved the hardest part, spending it. The attacker's largest known wallet now holds 562 stolen Bitcoin. Every movement is being watched. Every transaction is being analyzed. Every blockchain analytics company, every exchange and countless independent Bitcoiners tracking those coins in real time. Bitcoin may be permissionless, but converting stolen Bitcoin into spendable wealth is an entirely different challenge. The larger the theft, the harder it becomes to disappear. That's the irony. Bitcoin's transparency is one of its greatest strengths. Every transaction is public. Every movement leaves a permanent record. And unlike cash, there's nowhere to hide. The blockchain never forgets. The attacker may control the private keys, but they don't control the world's attention. That's why stealing Bitcoin and successfully turning it into spendable wealth are two completely different things. In one of the stranger developments this weekend, someone even sent the attackers an on-chain message advertising Bitcoin laundering services for a 10% fee. Think about that for a moment. A $1 blockchain message trying to sell money laundering to someone holding 10s of millions of dollars and stolen Bitcoin, it almost sounds absurd, but it also highlights the reality facing the attackers. Owning Bitcoin and freely spending Bitcoin are not the same thing. Meanwhile, the situation surrounding Coldcard continues evolving. Researchers have identified another issue affecting the emergency firmware hotfix itself. The update addresses the original entropy vulnerability, but researchers have now identified another bug that under certain conditions can reportedly brick your Coldcard devices, leaving them stuck before the pin prompt and unable to access the upgrade menu. For users ready on the edge, it's another reminder that security incidents rarely end with a single patch. If you're still using a Coldcard device, the safest course of action is to move your Bitcoin to a trusted wallet under your control as soon as possible and spread this with others who you think may be using one, just in case. Don't wait for another headline, protect your Bitcoin first. Yet despite all of this, Bitcoin itself hasn't changed. The protocol wasn't hacked. Keep that in mind. The 21 million supply wasn't altered. Blocks continue being produced every 10 minutes. The network keeps doing exactly what it was designed to do. This wasn't a failure of Bitcoin. It was a failure in one hardware wallet's firmware. That's an important distinction. Because while fear dominated the conversation, many people confused short-term fear with long-term fundamentals. Bitcoin kept producing blocks. Companies kept accumulating. Developers kept improving the ecosystem. The network never paused. Only the headlines changed. History has a habit of rewarding people who separate temporary fear from permanent fundamentals. The Coldcard incident will almost certainly change how Bitcoiners think about hardware wallets, entropy and self-custody, best practices. But it doesn't change the one thing that has always mattered most. Bitcoin's monetary policy remains exactly the same today as it was before the wallet was ever compromised. Sometimes the biggest headlines change everything around Bitcoin while changing nothing about Bitcoin itself. If you were impacted by the Coldcard hack, do let me know in the chat. And I will read comments out loud when we do our live Q&A, as we always do. Now let's break down everything that changed over the past 24 hours, starting with the latest Coldcard developments. As I shared here last night, the fourth wave of the Coldcard attacks is underway. And if you're using any Coldcard wallet, move your Bitcoin to a trusted wallet immediately. So this is an example what the Coldcard looks like. There's different models. There's like an MK2, an MK3, an MK4, as well as a Q. Regardless of which model you're using, if it's any hardware device from CoinKite, which is the company behind the Coldcard, I strongly encourage you to move the Bitcoin to a trusted wallet source immediately. And the first question may be, but JV, I don't have another hardware wallet device at my house. What do I do? It's an emergency. I'd say send it anywhere that's trusted. Temporarily, you can send it to a centralized exchange, Coinbase, Kraken, Gemini.

12 more minutes of transcript below

Feed this to your agent

Try it now โ€” copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID