4 hours ago

Coldcard Incident Losses Rise to 1,359.882 BTC as Coinkite Issues Firmware Fix

Coldcard security incident loses 1,359.882 BTC, attacker address receives 10% coin-mixing offer

Odaily

Key Point

The Coldcard security incident involving Coinkite has lost approximately 1,359.882 BTC. Coldcard Sweep Watch dashboard statistics show most identified bitcoin remains in a small number of attacker-controlled addresses. On August 1, one attacker holding address received an OP_RETURN message offering a 10% fee for washing bitcoin, KYC assistance, and withdrawal services. Coinkite released urgent firmware to fix the weak random number generation issue that caused the original vulnerability. Some users reported that Mk4, Q, and some Mk3 devices remain stuck on an error screen, fail to boot, or appear bricked after the update.

Why it matters: A custody-device vulnerability can force users to reassess seed safety and may reduce confidence in affected wallet infrastructure.

Market Sentiment

Bearish, Stress-on, Tech-driven, De-risking.

Reason: The reported loss of approximately 1,359.882 BTC creates custody-security stress for users of the affected hardware wallet.

Similar Past Cases

In the 2022 Slope wallet incident, a malicious attacker drained 9,231 wallets of approximately $4.1 million over about four hours after private keys for affected wallets were leaked or compromised. Solana Foundation said affected users should create a new and unique seed phrase wallet and transfer assets to the new wallet. (Solana Foundation) The key difference is that the Slope case involved a software wallet in the Solana ecosystem, while the Coldcard incident involves a hardware wallet and a much larger bitcoin-denominated loss.

Ripple Effect

The main channel is custody confidence because compromised seed generation can make users question whether older wallets remain safe. If affected users move funds to fresh wallets after the firmware warning, then on-chain consolidation and exchange deposits may show whether risk remains contained. If firmware issues persist, then operational risk may spread from theft response into device recovery and user access.

Opportunities & Risks

Opportunities: If Coinkite confirms stable firmware and users can verify new wallet generation, then waiting for successful migration before adding custody exposure reduces operational risk.

Risks: If more Mk4, Q, or Mk3 devices remain stuck after the update, then reducing reliance on affected devices limits custody risk until Coinkite provides a verified fix.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.