₿ BTC Loading... via Binance

Saturday, August 1, 2026

Coinkite Blames AI for the Bug, and the Attacker Left a Paid Account Behind

BitBrainers - Coinkite Blames AI for the Bug, and the Attacker Left a Paid Account Behind

By BitBrainers Editorial

Three days ago, Coldcard's entropy bug was one bad number. It has since split into two disputed totals, a vendor admission about AI, and a paper trail that ends at a blockchain data provider's billing account. Here is what actually changed since the last update, and why the total will likely keep moving.

Two Firms, Two Totals, Same Bug

Chainalysis put the damage at roughly $38 million as of Friday, tracing about 500 wallets swept in a tight 25-minute window. Galaxy Research and Block's own engineering team came in far higher: 1,196 addresses, 1,082.65 BTC, worth close to $70 million, across a wider 41-minute span.

The gap is not a disagreement about the bug itself. It is a disagreement about which transactions belong to the same attacker, since the two firms drew the boundary of "this event" differently and neither has finished counting.

Independent trackers were already citing a higher total by Saturday morning, unconfirmed by either firm. If you want the original entropy breakdown and the first 594 BTC sweep, our July 31 breakdown covers that from the start.


What We Know So Far

Four consolidation addresses account for most of the confirmed total. None have moved since the sweep.

CONSOLIDATION ADDRESS BTC STATUS
bc1qq85v2c9...cu9r 562.02 ● unmoved
bc1qx76cae2...fhe3 398.48 ● unmoved
bc1q8jy96fe...tp3q 89.62 ● unmoved
bc1qnk4zh9q...fecp0 32.45 ● unmoved

That's roughly 1,082.5 of the 1,082.65 BTC Galaxy Research attributes to the full sweep, accounted for across four wallets. Figures per Galaxy Research's on-chain mapping, corroborated by Block. Verify any balance directly on a block explorer rather than a third-party dashboard.

The Attacker Went for the Largest Wallets First

Chainalysis's timeline adds the most interesting new detail. In the first 10 minutes, the attacker had already pulled roughly $30 million, hitting the largest wallets before working down the list.

Three of the ten biggest affected wallets held at least 10 BTC each. That is not opportunistic scanning. The list was sorted by value before the first transaction was broadcast.

Sorting by balance ahead of time means the attacker had visibility into wallet holdings before touching a single signing key, which points to a reconnaissance phase that likely ran for weeks.

Numbers like this change fast.

Get the reconciled totals and the next disclosure the moment they land.

Subscribe

Coinkite's Own Explanation Is the Uncomfortable Part

Coinkite has now said it has to assume "someone used AI to review previous versions of our firmware" to find the bug, since the code has been sitting in public view since 2021.

The company also disclosed it ran a leading AI model over its own codebase a few weeks before the attack happened. That review did not flag the issue either.

Set that next to the forum's own technical read: a #define versus #ifdef mismatch, invisible unless someone traced the macro logic line by line. Five years of public code, and the people paid to audit it were not the ones who found it.


A Billing Account May Be the Attacker's Only Mistake

Block's Bitkey engineering lead, Clay Garrett, said investigators confirmed "the operator used a paid account at a well-known blockchain-services provider" to query source addresses during the sweep.

The provider's internal logs reportedly matched the timing and sequence of the attack closely enough that Block is calling the finding confirmed rather than suspected. Authorities have been notified.

None of this means an arrest is close. The cryptographic work here was close to flawless, and the target list was sorted by balance before a single key was touched. What the operator did not avoid was one ordinary point of contact with a company that keeps records.


What Actually Changes If You Own One

Coinkite shipped mandatory patches: firmware 5.6.0 for Mk4 and Mk5, 1.5.0Q for the Q model. There is no patch for Mk3 or Mk2, because the fix is a new seed, not a firmware update.

Updating firmware does not make an old seed safe by itself. The actual fix is generating a brand new seed on updated hardware, verifying the receive address on-device, and testing with a small transaction before moving the rest.

If you are rebuilding anyway, this is also the moment to consider spreading the risk across manufacturers instead of trusting one vendor's firmware for everything, which is the whole case for something like a Trezor hardware wallet as a second device in a multisig setup.


The Bigger Argument This Reopens

Bitcoin Core developer instagibbs independently reproduced the vulnerability, which closes any remaining doubt that this is real. The technical story is essentially finished. The institutional one is not.

Analysts are already using the incident to argue that self-custody has quietly built up its own operational risk, the kind that nudges undecided holders toward regulated custodians and spot ETFs instead of a hardware wallet in a drawer.

Price barely moved through any of this. BTC held its key support level the whole time, which says more about how numb the market has gotten to security headlines than about how serious this particular one actually is.


CoinDeskHow Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices

Bitcoin MagazineColdcard Bitcoin Thief Likely Used Top Blockchain Services Provider

CybernewsAI Might Have Helped Hackers Steal $38M in Bitcoin

AMBCryptoColdcard Seed Flaw Linked to $38M Bitcoin Theft as Loss Estimates Continue to Rise

CoinDeskColdcard's $38 Million (So Far) Exploit Shakes Faith in Self-Custody, May Push Investors to ETFs

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

The CLARITY Act Is Not Stalling Over Crypto

By BitBrainers Editorial The Senate leaves for its August recess in under a week and the most consequential crypto bill in US history...

The CLARITY Act Is Not Stalling Over Crypto