News linked to both this project and an event.
Odaily News: According to Bitcoin News monitoring, Alex Thorn of Galaxy Research stated that researchers initially identified the first wave of COLDCARD thefts through a distinctive on-chain pattern: thousands of automated asset transfer transactions used the same fixed fee rate and exhibited identical transaction behavior. This characteristic enabled analysts to trace attacker activity across Bitcoin UTXO history and map out multiple rounds of coordinated theft.
Odaily Odaily News: K33 Head of Research Vetle Lunde stated that the Coldcard attack likely drove the movement of approximately 890,000 BTC within 7 days, setting the highest 7-day active supply record for 2026. K33 estimates that around 7,300 addresses had approximately 1,596 BTC stolen at the time the report was prepared. The incident stems from a firmware flaw introduced by Coinkite in March 2021 in Coldcard hardware wallets, which may generate wallet seeds with insufficient randomness. Since July 30, coordinated transfers have removed approximately 1,600 BTC from thousands of addresses, worth over $100 million, and a possible fourth wave of attacks has pushed the total to nearly 2,000 BTC. On-chain data shows that Bitcoin's 7-day hot supply rose from 403,101.95 BTC on July 28 to 797,407.72 BTC on August 4, an increase of approximately 394,306 BTC in one week, or 98%. Sani from Timechainindex.com stated that since the Coldcard hack on Friday, exchanges have seen net inflows of 22,052 BTC. From July 30 to August 5, 39 dormant addresses moved a total of 1,486.09044782 BTC, worth over $95 million. Among them, one address created in 2010 moved 50 BTC, and five addresses created in 2013 collectively moved 620.00100547 BTC.
Bitcoin News posted on X platform, stating that Boltz has updated its PGP-signed warrant canary, a transparency measure used by privacy-related companies to publicly indicate that they have not received any secret government orders requiring them to hand over user data. The company's previous canary was dated May 31. Despite its commitment to update every 60 days, the canary expired around July 30, and its notice had asked users to "assume the worst" if it was not updated. Boltz stated that the expiration was due to negligence, as its team was dealing with an AI-assisted infrastructure attack that lasted for months, which ultimately led to the indefinite suspension of its swap services. The warrant canary has now been updated. Boltz stated that since the platform operates in a non-custodial model, user funds were never at risk.
Odaily News: The Coldcard wallet hack involves approximately $120 million. The related transactions briefly made the Bitcoin mempool highly active.
Odaily News: Swan CEO Cory Klippsten stated that the Coldcard attack has prompted Bitcoin holders to reassess their custody decisions. Cory Klippsten noted that his team has been organized to assist affected holders in moving tokens to secure locations, including those who are not Swan customers. He pointed out that affected users have not abandoned self-custody, but are instead turning to vault solutions that prevent a single compromised device from endangering funds.
CertiK 表示,其监测系统发现两笔各 200 ETH 的交易转入 Tornado Cash,相关资金与正在进行的 Coldcard Wallet 攻击事件有关。上述资金此前通过 THORChain 由 BTC 跨链转入以太坊地址,随后再被转入 Tornado Cash。
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
Odaily News: The wallet associated with the Coldcard hacker has received multiple deposits since July 30, some of which include text messages attached via Bitcoin's OP_RETURN function. The messages include requests for the return of funds, as well as opportunistic promotional content, with one message offering to help launder the stolen funds for a 10% cut.
Odaily News, Chainalysis posted on X platform stating that the Coldcard hack has been particularly devastating for Bitcoin holders in Canada. Our analysis of the attackers and victims found that Canadian BTC holders accounted for 25% of the attributable losses.According to aggregated estimates from Galaxy Research, losses have reached as high as $110 million. We analyzed the geographic distribution of this ongoing hacking campaign. Users in Australia, the United States, and Thailand have also suffered significant losses.
According to Decrypt, non-custodial Bitcoin exchange service provider Boltz announced an indefinite suspension of its Bitcoin exchange services, as the iteration speed of AI-assisted attacks has exceeded its team's vulnerability patching capability. Boltz stated that automated AI probing attacks have continued to increase over the past few months, and multiple vulnerability exploitation incidents have been handled, but recently the pace of attacks has significantly accelerated, and it is suspected that multiple well-resourced attack organizations are simultaneously launching attacks against its platform, rendering the team unable to operate safely during the patching period. Currently, Boltz's TVL is approximately $262,000. Since the platform adopts a non-custodial architecture, users retain custody of their funds throughout the process. The team confirmed that no user funds are at risk, and API refund channels and unilateral refund functions remain operational.
Odaily News: Non-custodial Bitcoin swap service Boltz has indefinitely suspended its Bitcoin swap service, stating that the service will remain offline until further notice, with no timeline for restoration provided. Boltz allows users to transfer Bitcoin between the Lightning Network and the Bitcoin base layer, without the company ever holding custody of user funds. Boltz stated that over the past few months, its infrastructure has faced a continuous increase in automated, AI-assisted probing, and the team has already handled multiple exploit incidents. The company said each incident was contained, but the speed at which attackers iterate has outpaced the team's ability to discover and patch vulnerabilities. Boltz disclosed that the pace of attacks has accelerated over the past few days, and after reviewing recent security scan results, the company concluded that it cannot responsibly re-enable the swap service. Its API remains available for processing collaborative refunds, unilateral refunds remain operational as they do not rely on Boltz infrastructure, and customer support remains accessible.
Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.
Odaily Planet Daily reported that Bitcoin News stated on the X platform that Coinkite said the vulnerability existed at the boundary between two unrelated firmware submodules, rather than in its Bitcoin or encryption code, which allowed it to evade both manual and AI-assisted code reviews for years. Coinkite stated that after the incident, the company tested cutting-edge AI models including Kimi K3, Claude Fable, and Codex 5.6, none of which identified the flaw. Coinkite is now urging security-critical projects to specifically audit build systems and submodule boundaries, and warned that AI-assisted development could leave similar blind spots in the Bitcoin ecosystem.
Odaily Planet Daily reported that Bitcoin News posted on X platform, stating that new evidence suggests the anonymous account "switck," who wrote the LibNgU code, may actually be Peter Gray, Co-founder and CTO of Coinkite. This code is at the center of the COLDCARD entropy failure incident. Researchers claim that Gray's GPG key signed dozens of commits by switck, and other identifiers appear to link the two identities together. Bitcoin developer James O'Beirne stated that he had warned Coinkite in May 2025 that the RNG implementation of LibNgU looked suspicious and recommended removing it, but he said the other party responded that if there were issues, they would have already been discovered. Screenshots also show that as early as April 2021, users had already raised questions about the LibNgU rewrite. If these findings are accurate, it means that the engineer who introduced the code was later linked to the theft of over 1,800 BTC, and had received direct warnings about the RNG implementation more than a year before the vulnerability was publicly disclosed.
Galaxy Digital Head of Research Alex Thorn stated that based on new victim reports received following the incident, the number of attackers exploiting the Coldcard vulnerability has reached at least 15.Thorn noted that information provided by victims helped the research team uncover previously unidentified attack activity. Unlike thefts from centralized exchanges, correlations between the attackers in this vulnerability exploit require confirmation through on-chain analysis and victim feedback.He added that a single victim reporting less than 1 BTC stolen helped the team discover a previously unknown attack, which siphoned approximately 12 BTC from 126 addresses.According to Galaxy Research's earlier estimates, the Coldcard vulnerability has led to at least three rounds of attacks, with losses amounting to approximately $100 million in BTC. Additionally, Galaxy has identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million.Meanwhile, the incident has also sparked discussions regarding the security of Bitcoin self-custody. Dragonfly Managing Partner Haseeb Qureshi stated that "AI security hardening costing around $2" could potentially have prevented this vulnerability, and noted that some AI models were able to rediscover related vulnerabilities within a relatively short timeframe. However, industry insiders pointed out that current claims about the speed of AI discovering vulnerabilities lack rigorous blind testing and verification.Researchers believe that as AI model capabilities improve, the costs of vulnerability discovery and attacks in the crypto industry may continue to decline, requiring wallet developers to further strengthen code audits and security protections. (Cointelegraph)
According to CoinDesk, the 30-day implied volatility index BVIV, which measures expected volatility in the Bitcoin options market, has continued to decline, now falling to 36%, the lowest level since May 31, significantly down from the high near 60% in early June. Recent influencing factors include the Coldcard wallet attack incident involving tens of millions of dollars, weak institutional demand, and uncertainty in the regulatory and macroeconomic environment, but there are no obvious signs of panic in the market. However, volatility has mean-reverting characteristics. When the indicator falls to historical lows, a rebound often follows. Currently, BVIV has approached levels that have previously formed support multiple times. If volatility rebounds quickly in the future, it may be accompanied by a significant directional move in Bitcoin; whether up or down, traders need to remain vigilant.
Odaily News: Hardware wallet manufacturers Trezor and Foundation have warned that following the disclosure of a Coldcard firmware vulnerability, phishing attempts targeting hardware wallet holders have increased, with attackers soliciting recovery phrases and luring victims into downloading malware. Security firm Proofpoint has detected phishing emails impersonating Coldcard, inviting users to complete a "hardware audit" with links to a cloned website. After clicking, users download a batch file hosted on GitHub that installs the remote access tool ScreenConnect. Proofpoint stated that the fraudulent website also features a customer service chat window, where real people guide victims through the installation process. This remote access tool can provide attackers with a pathway to steal data and funds, or further deploy malicious programs such as ransomware. Galaxy Research has confirmed three rounds of theft since July 30, with high-confidence losses of 1,596 BTC, exceeding $100 million; if a fourth round not yet confirmed with victims is included, total losses could reach $130 million.
According to Onchain Lens monitoring, COLDCARD users have experienced another incident of stolen funds, with over 5,200 affected addresses seeing approximately 1,816 BTC stolen, worth around $114 million. The confirmed first to third waves involve 1,367.05 BTC, valued at approximately $88.6 million. The fourth wave, matching a pattern, involves 462 potential victims, adding 388.93 BTC. Onchain Lens is currently identifying associated clusters based on on-chain data. As of now, the attacker has not yet moved the stolen funds. The cluster remains active, with the latest transaction recorded just minutes ago.
Odaily Planet Daily Report: Bitcoin hardware wallet manufacturer Coinkite disclosed in late July 2026 that a firmware build error introduced in March 2021 caused some Coldcard wallets to generate mnemonics from a smaller range, reducing the randomness of user private keys. Galaxy Research analysts stated that the Coldcard exploit occurred in multiple rounds, with observed Bitcoin losses rising from approximately $88 million to nearly $114 million within days. Researchers warned that other vulnerable addresses could still become targets, prompting many Coldcard users to move their Bitcoin. Coldcard is a Bitcoin-only wallet that supports offline signing via microSD card and optional QR codes. Launched in 2017, it has long been regarded as one of the security-focused Bitcoin hardware wallets.
Odaily News: Bitcoin News posted on X platform, stating that Boltzhq has indefinitely suspended its swap service after reporting an increase in AI-assisted attacks and multiple contained exploits. Due to its non-custodial design, user funds were never at risk, but wallets relying on Boltz for Lightning Network swaps, including AquaBitcoin and BULLBITCOIN, experienced service disruptions while alternative infrastructure is being deployed.