Cold Wallet Exploit Drains $89M as Bitcoin Returns to Exchanges artwork

Cold Wallet Exploit Drains $89M as Bitcoin Returns to Exchanges

Crypto News Today

August 2, 2026

Trade cryptocurrency with Kraken Protect your cryptocurrency with Ledger Protect yourself online with NordVPN Listen to Crypto News Today on Spotify Subscribe to Crypto News Today on YouTube Follow Crypto News Today on X A major Bitcoin cold-wallet exploit has now spread across more than 4,500...
**SPEAKER_1** (0:00)
Welcome back to the Daily Crypto Roundup. A hardware wallet attack has just turned one of Bitcoin's oldest safety assumptions upside down. Nearly $89 million in Bitcoin has now been traced to an exploit involving thousands of Coldcard-generated wallets. And the attacker did not need to steal a device, infect a computer or trick anybody into revealing a recovery phrase. Researchers believe the private keys were rebuilt offline because some wallets were created using dangerously weak randomness.
That story is now causing frightened holders to move Bitcoin back onto centralized exchanges. The exact opposite of what happened after FTX collapsed. We also have strategy keeping the dividend on its high-yield STRC preferred shares at 12%, despite the stock continuing to trade below its intended $100 level. And SpaceX shares are sitting close to crucial support before the company's first public earnings report and a massive insider share unlock.
At the time of recording, Bitcoin is trading at approximately $63,130.
Ethereum is close to $1,862.
XRP is around $1.08.
BNB is just above $587.
Solana is trading near $73.
Cardano is around $0.19, while Dogecoin is close to $0.07. The wider market is relatively steady, but the Coldcard exploit is creating a different kind of fear, because it attacks confidence in the mechanics of self-custody.
This episode is brought to you by Kraken. Kraken offers access to Bitcoin, Ethereum, XRP, and a wide range of other digital assets. You can support the podcast by using our Kraken link when opening and funding an account. As always, this is not financial advice, and cryptocurrency trading involves a risk of loss. Before we get into the details, follow the podcast, subscribe wherever you are watching, and leave a rating if you have not already. The estimated losses have already grown as researchers have identified more addresses and additional waves of theft. The first major sweep took place on July 30th. Galaxy Research says approximately 1,082.65 Bitcoin was drained from 1,196 wallets in just 41 minutes. The transactions appeared across six blocks and were apparently broadcast in batches. At that stage, the stolen Bitcoin was worth roughly $70 million, almost double the amount initially identified because investigators had only tracked one of the attacker's destination addresses. The incident then expanded. Three separate waves have now reportedly swept a combined 1,367 Bitcoin from 4,585 addresses, bringing estimated losses close to $89 million.
The later attacks targeted smaller wallets, with one wave taking around 208 Bitcoin from 1,912 addresses. That is only a little more than one-tenth of a Bitcoin from each victim on average, suggesting the attacker may now be working through the less valuable remainder of the vulnerable key space. The method is what makes this so alarming. A normal Bitcoin seed phrase is produced from an enormous pool of unpredictable possibilities. Properly generated, it is so unlikely to be guessed that brute forcing it is effectively impossible.
Coldcard devices were supposed to use a dedicated hardware random number generator when creating that seed. Researchers say a firmware flaw dating back to March 2021 caused some devices to fall back to a basic software randomizer using information, including the chip's serial number and clock registers. Those values are far more limited and predictable than true hardware generated randomness. On some affected models, researchers estimated that the attacker may have needed to search roughly 4 billion possibilities.
4 billion sounds enormous to a human being, but for modern computing hardware, it is searchable. The attacker could generate possible seeds on their own machines, derive the Bitcoin addresses connected to each candidate, and compare those addresses with the public blockchain. When a candidate produced an address containing Bitcoin, the attacker could reconstruct the private key and move the funds. The victim's Coldcard did not need to be switched on, connected to the Internet or physically accessible. It could have been locked in a safe throughout the attack. That is why describing this simply as a hardware wallet hack is misleading. The attacker was not remotely reaching inside thousands of devices. The vulnerability appears to have existed at the moment the wallets were created. If a recovery seed was generated with weak randomness, the wallet may have been compromised from birth. There is also no simple test that proves a seed is safe. Reports differ over precisely which Coldcard models and firmware combinations are affected. CoinKite has warned owners of older Mark III devices, while outside researchers have identified a potentially broader scope. Anyone who believes they generated a seed using affected firmware should follow the manufacturer's current guidance, rather than assume that updating the device will repair an already weak seed. An update may fix the process used for future wallets, but it cannot transform an existing predictable seed into a secure one. The on-chain reaction has been almost as remarkable as the exploit. After FTX failed in November 2022, holders rushed to remove Bitcoin from exchanges because they feared insolvency, frozen withdrawals and missing customer assets. Self-custody became the answer. This time, the perceived danger sits inside a particular self-custody product, so some holders are moving in the opposite direction. Crypto Quant reported that Bitcoin deposits to exchanges involving transfers smaller than 10 Bitcoin jumped to approximately 7,300 Bitcoin on July 31, the highest level since February 6 Daily active Bitcoin addresses reportedly climbed from around 645,000 on July 30 to almost 1 million on July 31, their highest level since December 10, 2024 The combined volume of transfers smaller than 1 Bitcoin reached approximately 39,600 Bitcoin, almost matching the smallholder activity recorded immediately after the FTX bankruptcy. Separate analysis estimated net exchange inflows of more than 11,000 Bitcoin, with funds moving to major platforms including Binance, River, Kraken and OKX. Exchange linked balances increased from approximately 2.704 million Bitcoin to 2.715 million. That does not mean centralized exchanges have suddenly become risk-free, and it does not mean self-custody has failed. It shows that investors move toward whichever option appears safer at that moment. After FTX, counterparty risk was the greater fear.

4 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID