By BitBrainers Editorial
Two Firms, Two Totals, Same Bug
Chainalysis put the damage at roughly $38 million as of Friday, tracing about 500 wallets swept in a tight 25-minute window. Galaxy Research and Block's own engineering team came in far higher: 1,196 addresses, 1,082.65 BTC, worth close to $70 million, across a wider 41-minute span.
The gap is not a disagreement about the bug itself. It is a disagreement about which transactions belong to the same attacker, since the two firms drew the boundary of "this event" differently and neither has finished counting.
Independent trackers were already citing a higher total by Saturday morning, unconfirmed by either firm. If you want the original entropy breakdown and the first 594 BTC sweep, our July 31 breakdown covers that from the start.
What We Know So Far
Four consolidation addresses account for most of the confirmed total. None have moved since the sweep.
| CONSOLIDATION ADDRESS | BTC | STATUS |
|---|---|---|
| bc1qq85v2c9...cu9r | 562.02 | ● unmoved |
| bc1qx76cae2...fhe3 | 398.48 | ● unmoved |
| bc1q8jy96fe...tp3q | 89.62 | ● unmoved |
| bc1qnk4zh9q...fecp0 | 32.45 | ● unmoved |
That's roughly 1,082.5 of the 1,082.65 BTC Galaxy Research attributes to the full sweep, accounted for across four wallets. Figures per Galaxy Research's on-chain mapping, corroborated by Block. Verify any balance directly on a block explorer rather than a third-party dashboard.
The Attacker Went for the Largest Wallets First
Chainalysis's timeline adds the most interesting new detail. In the first 10 minutes, the attacker had already pulled roughly $30 million, hitting the largest wallets before working down the list.
Three of the ten biggest affected wallets held at least 10 BTC each. That is not opportunistic scanning. The list was sorted by value before the first transaction was broadcast.
Sorting by balance ahead of time means the attacker had visibility into wallet holdings before touching a single signing key, which points to a reconnaissance phase that likely ran for weeks.
Numbers like this change fast.
Get the reconciled totals and the next disclosure the moment they land.
SubscribeCoinkite's Own Explanation Is the Uncomfortable Part
Coinkite has now said it has to assume "someone used AI to review previous versions of our firmware" to find the bug, since the code has been sitting in public view since 2021.
The company also disclosed it ran a leading AI model over its own codebase a few weeks before the attack happened. That review did not flag the issue either.
Set that next to the forum's own technical read: a #define versus #ifdef mismatch, invisible unless someone traced the macro logic line by line. Five years of public code, and the people paid to audit it were not the ones who found it.
A Billing Account May Be the Attacker's Only Mistake
Block's Bitkey engineering lead, Clay Garrett, said investigators confirmed "the operator used a paid account at a well-known blockchain-services provider" to query source addresses during the sweep.
The provider's internal logs reportedly matched the timing and sequence of the attack closely enough that Block is calling the finding confirmed rather than suspected. Authorities have been notified.
None of this means an arrest is close. The cryptographic work here was close to flawless, and the target list was sorted by balance before a single key was touched. What the operator did not avoid was one ordinary point of contact with a company that keeps records.
What Actually Changes If You Own One
Coinkite shipped mandatory patches: firmware 5.6.0 for Mk4 and Mk5, 1.5.0Q for the Q model. There is no patch for Mk3 or Mk2, because the fix is a new seed, not a firmware update.
Updating firmware does not make an old seed safe by itself. The actual fix is generating a brand new seed on updated hardware, verifying the receive address on-device, and testing with a small transaction before moving the rest.
If you are rebuilding anyway, this is also the moment to consider spreading the risk across manufacturers instead of trusting one vendor's firmware for everything, which is the whole case for something like a Trezor hardware wallet as a second device in a multisig setup.
The Bigger Argument This Reopens
Bitcoin Core developer instagibbs independently reproduced the vulnerability, which closes any remaining doubt that this is real. The technical story is essentially finished. The institutional one is not.
Analysts are already using the incident to argue that self-custody has quietly built up its own operational risk, the kind that nudges undecided holders toward regulated custodians and spot ETFs instead of a hardware wallet in a drawer.
Price barely moved through any of this. BTC held its key support level the whole time, which says more about how numb the market has gotten to security headlines than about how serious this particular one actually is.
CoinDesk — How Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices
Bitcoin Magazine — Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider
Cybernews — AI Might Have Helped Hackers Steal $38M in Bitcoin
AMBCrypto — Coldcard Seed Flaw Linked to $38M Bitcoin Theft as Loss Estimates Continue to Rise
CoinDesk — Coldcard's $38 Million (So Far) Exploit Shakes Faith in Self-Custody, May Push Investors to ETFs
This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.