- About $70m of bitcoin emptied out of 1,200 wallets in under an hour. The counts have kept moving and still don’t agree: CoinDesk now reports $114m, Decrypt $130m, and Galaxy Research has said the total could top $150m.
- Nobody was hacked in the way you’d expect. A bug in Coldcard’s own code meant some devices built keys that could be worked out.
- That bug sat in published code for years and nobody spotted it. Coinkite has now shipped a fix and published the list of affected firmware versions, and anyone on that list has to create a fresh seed and move their coins across.
If you’ve ever been told to get your bitcoin off an exchange and onto a hardware wallet, you did what nearly everyone in crypto recommends. This week, about 4,500 people who took that advice found their coins gone anyway.
People who followed the standard advice still lost their money. That’s what makes this different from an exchange going under: nobody got careless, nobody clicked a dodgy link. They bought the recommended device, used it properly, and it wasn’t enough.
Changpeng Zhao, who founded Binance, put it about as plainly as anyone has: hardware wallets have bugs too, so spread your money across more than one place. Nothing is 100%.
What a hardware wallet is supposed to do
Start with the thing that makes crypto different from a bank account. Your bitcoin doesn’t sit inside a wallet the way cash sits in a purse. It sits on the , a public record anyone can look at. What you actually own is a : a very long secret number that proves the coins are yours and lets you move them.
Whoever holds that key controls the coins. That’s the entire system. There’s no bank to ring, and no password reset.
A hardware wallet is a small physical device, roughly the size of a USB stick, that stores your private key and never lets it touch a computer connected to the internet. The logic is simple enough: if the key never goes online, nobody online can take it.
What went wrong
Coldcard is one of the most trusted of these devices, the kind recommended by people who take security seriously. And nobody broke into it. That’s worth saying clearly, because it’s the part most people get wrong about this story.

The problem was how some devices created their keys in the first place. A private key is meant to be a random number so enormous that guessing it is effectively impossible. Some Coldcard devices produced keys that weren’t random enough, which meant they could be worked out.
Once someone works out your key, they don’t need your device, your PIN, or anything you own. They just move the money.
We now know where that came from. CoinDesk has traced the fault to a bug in Coldcard’s code, and the uncomfortable part is how long it was there: years, in code that was published for anyone to inspect. The whole argument for buying a device like this rests on the idea that being able to check the code means somebody has. In this case nobody did, or nobody who looked spotted it, and the fault shipped on device after device in the meantime.
Galaxy Research traced around 1,080 bitcoin (about $70m at the time) leaving roughly 1,200 wallets in under an hour. Later counts from CoinDesk put the running total nearer $89m across about 4,500 addresses, with the attacker working steadily down to smaller holdings. It has kept climbing since. CoinDesk now reports $114m, Decrypt puts the figure at $130m, and Galaxy has said the total could top $150m, so the estimates have started to diverge rather than converge, which is what happens when each analyst is deciding for themselves which emptied addresses belong to this fault and which don’t.
Galaxy also reports that the thefts have slowed. That sounds like good news and only half is. The likeliest explanations are that the people still holding vulnerable keys have moved their coins somewhere safe, or that those wallets have already been emptied, so there’s simply less left to take.
Coinkite, the company behind Coldcard, shipped new standard firmware on 20 August after three weeks of going back through its code. The main change moves part of the job onto the owner: when you create a new seed, the device now insists you supply some randomness of your own rather than trusting it to produce a good number on its own. In practice that means at least 65 key presses at unpredictable intervals, 50 rolls of a physical six-sided die, or 128 coin flips, mixed in with whatever the device generates itself. It’s deliberately tedious, and the tedium is the point: the one part of the process the buggy code couldn’t touch is the bit a human does by hand.
The same review turned up further bugs that had nothing to do with the flaw behind the losses, and those have been fixed too. Coinkite says AI tooling helped find them.
What the update cannot do is undo anything. Coinkite is clear that installing it does not make an already compromised wallet safe, and the reason is simply arithmetic: if a key was weak enough to be worked out, it stays weak whatever code the device is running afterwards. New firmware protects seeds generated from now on. It does nothing for the ones already sitting on the blockchain.
The list owners were waiting for has now appeared alongside it, and it is wider than a single model. Coinkite’s migration guidance covers Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9, Mk4 and Mk5 devices on standard firmware before 5.6.0 or Edge firmware before 6.6.0X, and Q devices on standard firmware before 1.5.0Q or Edge before 6.6.0QX. The versions it now recommends are 5.6.1 for Mk4 and Mk5, and 1.5.1Q for the Q.
Updating alone isn’t the fix, though, and this is the part that costs people an afternoon. If your seed was created on affected firmware, Coinkite’s instruction is to install the new release, generate an entirely new seed with the added randomness, and move your coins to it. The exception is anyone who originally set their wallet up using the dice-roll method, because that sidestepped the device’s own number generator in the first place. For a UK holder there’s at least no tax sting in doing it: moving coins between wallets you control isn’t a disposal in HMRC’s eyes, so the cost is the network fee and the time, not a capital gains event.
The reaction is the odd bit
There’s something else showing up in the data. After FTX collapsed in 2022, the message to ordinary holders was relentless: get your coins off exchanges and hold them yourself. Millions of people did exactly that.
This week, the analytics firm CryptoQuant recorded 39,600 bitcoin moving in small transactions, the biggest movement of that kind since FTX. A lot of it was heading back onto exchanges.
Those deposits were real, but they turn out to be the smaller half of the story. The custody firm Casa now counts roughly $15bn of bitcoin moving in the days after the exploit, and says most of it went the other way: out of single-device setups and into arrangements where more than one key is needed to move the coins, so no single failure can empty a wallet.
Casa’s chief executive, Nick Neuman, reads that as the system working, holders spotting a weak point and spreading their risk rather than giving up on holding their own coins. Worth noting that Casa sells exactly that kind of multi-key setup, so it’s a reading that suits them. The scale of the movement isn’t really in dispute, though, and it’s a long way past what a few nervous exchange deposits would account for.
So the picture is less a retreat than a reshuffle. Some people decided they’d rather someone else carried the risk. Rather more decided the answer was to stop putting everything behind one device.
What to watch
The loss figure first, and the gap between the counts. It’s gone from $70m to $89m to $114m on CoinDesk’s count, with Decrypt at $130m and Galaxy saying it could reach $150m. A spread that wide tells you nobody has a definitive list of affected addresses yet, and the slowdown Galaxy describes doesn’t settle it either: if vulnerable holders have moved their coins, the total is close to final, and if those wallets were already drained, the number keeps drifting up as more of them are counted.
Then what the industry does about code nobody reads. “Don’t trust, verify” is the line every hardware wallet is sold on, and a bug that survived years of public scrutiny is a fair test of whether anyone is actually doing the verifying. Coinkite’s three-week review is the first real answer to that, and it found more than the one fault, which says something about how thin the earlier scrutiny was. The question now is whether reviews like it become routine and funded rather than something that happens after nine figures have gone missing, and whether the other manufacturers go looking through their own code before they have to.
The migration is the other open one. A fix that depends on every affected owner installing firmware, generating a fresh seed and moving their coins only works as far as people actually do it, and hardware wallets are bought precisely so they can be put in a drawer and left alone. Nobody publishes a count of how many devices get updated, so this may be a question that never gets a clean answer.
And whether the reshuffle sticks. Moving coins in a panic week is easy; the harder question is whether people who’ve just set up multi-key custody are still running it properly in six months, or whether they quietly drift back to one device and one because it’s simpler. That’s the part that would actually change how ordinary people hold bitcoin, and it won’t show up in a single week of flow data.