₿ BTC Loading... via Binance

Monday, August 3, 2026

The Market Priced Everything This Week Except the $110 Million Theft

BitBrainers - Coldcard drained vs Bitcoin price

By BitBrainers Editorial

On July 30 an attacker emptied 1,196 Bitcoin addresses in 41 minutes. Four waves later the running total stands at 1,815.75 BTC across 5,294 addresses, with a fourth wave actively running on August 3. The devices holding those coins were Coldcards, the hardware wallet the most security-conscious corner of Bitcoin has recommended for a decade. Bitcoin closed July 30 around $62,800, down less than 1% from the prior session, and was back at $63,781 by August 3. A theft at that scale bought a brief dip inside an existing range.

Forty Bits Instead of One Hundred Twenty Eight

A hardware wallet generates a seed phrase from a dedicated chip built to produce true randomness. The target is 128 bits of entropy, a number large enough that guessing it is computationally impossible for anything humans can build.

A single code change on March 1, 2021 caused Coldcard firmware to silently fall back to a software pseudorandom generator instead of the STM32 hardware chip. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure. Every coin taken came from a wallet created after that March 2021 firmware release, which is the strongest on-chain evidence linking the thefts to the bug.

The gap between 128 bits and 40 bits is not a matter of degree. An attacker who could constrain the device UID, timer state and prior RNG-call history could reproduce candidate seeds offline, derive their addresses, and check them against public blockchain data. No physical access to any device was required at any point.

Coinkite CEO Rodolfo Novak apologised publicly and took full accountability, saying the company's review process had failed to catch it. Emergency firmware shipped on July 31. That firmware does not repair an existing seed. A seed created with weak entropy stays weak permanently, on any device, in any wallet software. Coinkite has since halted shipments and destroyed all remaining vulnerable inventory, an acknowledgment that the problem cannot be patched on existing hardware, only replaced.


The Coins Have Not Moved

Here is the detail that explains the muted reaction. Galaxy Research reported that the first three waves of stolen Bitcoin remain unspent in attacker-controlled addresses. Not mixed, not bridged, not sent to an exchange. A fourth wave is moving coins right now as this post publishes.

Galaxy called that unusual for a theft of this size and offered two readings: the operator is waiting for scrutiny to fade, or has no viable path to launder a sum this visible on a public ledger. A decade ago $75 million in stolen Bitcoin would have been through a mixer within hours. Today, with exchange compliance tightened and firms like Galaxy and Chainalysis watching in real time, moving it is the hard part.

What happened here was a change of ownership rather than supply hitting the market, and for price purposes those are entirely different events. Only one of them registers as flow.

That covers the mechanics. It does not explain why the drift since has been sideways rather than sharply lower, which is where the rest of the week comes in.


We read the filings so you can skip the timeline.

Weekly Bitcoin and macro analysis, built from primary sources.

Subscribe

What Was Actually Setting Price

The $116 million was competing for attention with a calendar that had far more direct claims on flows.

The FOMC voted 9-3 to hold rates at 3.50% to 3.75% on July 29, with three officials dissenting toward a hike. Fed Chair Kevin Warsh again declined to give forward guidance. The PCE print on July 31 showed continued cooling, which softened hike expectations at the margin without changing the committee's split.

Spot Bitcoin ETFs posted net outflows of $61.53 million for the week ending July 31, breaking a three-week inflow streak worth roughly $306 million. Fidelity's FBTC led redemptions at $85.19 million. BlackRock's IBIT ran the other way with $869.02 million in weekly inflows.

Senate Majority Leader John Thune confirmed the CLARITY Act would not get a floor vote before the August recess. Polymarket odds on 2026 passage sit near 28%, down from 82% in February.

Three catalysts with direct, measurable links to institutional flows. Against those, a firmware bug affecting a device with a niche installed base competes for headlines, not for order books.

Strategy's Michael Saylor flagged that Bitcoin is sitting almost exactly on its 200-week moving average, a level it has traded above 92% of the time by Strategy's own calculation. That is the company's number rather than an independent study, but the level is real and the market is respecting it.


The Part Nobody Is Pricing

Price gave this one candle. Bitcoin's security assumptions deserve considerably more than that.

The bug lived in open-source code for five years. Public review is supposed to be the defence, and the code was public the entire time. Coinkite says it suspects an attacker used an automated tool to comb old code versions, something Coinkite itself had attempted weeks earlier without finding it.

That is the uncomfortable part. Machine-assisted auditing found a five-year-old flaw before the vendor running the same class of tool did. Every open-source wallet firmware repository is now sitting in the same searchable pile, and the search cost has collapsed.

Victims are organising class-action claims over losses now exceeding $116 million. Legal opinion is split on whether a hardware manufacturer carries product liability for a firmware defect of this kind. Whatever the outcome, it sets the first real precedent for the category.

None of that is in the price. Some of it will be, eventually, in the form of slower self-custody adoption or a repricing of what a hardware wallet warranty is actually worth.


The Argument Happening Underneath

The louder claim circulating is that this marks a turning point for self custody, an assault on the be-your-own-bank position that has anchored Bitcoin culture since the beginning.

The counterargument is more persuasive. People who already cared about self custody will now care more and tighten their setup. People who never cared are still leaving coins on exchanges and were never going to be moved by a firmware advisory. The net behavioural change is probably close to zero, which is a duller conclusion than a revolution but fits how the last several custody scares actually played out.

The concrete prediction worth holding onto is narrower. Passphrases move from optional to standard practice, because a BIP-39 passphrase is the specific thing that protected people here. Dice-roll entropy sits in the same category. Both were treated as advanced-user extras for years, and both just became the difference between a working wallet and an empty one.

A paid hardware device is a convenience layer that a lot of holders quietly reclassified as a security guarantee. The device did the job it was sold to do, right up until one line of firmware meant it had never been doing it at all. Convenience and guarantee are not the same product, and the price difference between them is not what the market has been paying.


What This Sets Up

Watch whether the first three waves move. A transfer toward an exchange or mixer turns a custody story into a supply story, and that is the version that would show up on a chart. An OP_RETURN message has already appeared in one attacker address advertising laundering services and KYC bypass for a 10% fee. That is not the attacker moving coins. It is the wider illicit economy signalling it is ready when they are.

Watch the class-action filings. A ruling on manufacturer liability for a firmware defect would reprice risk across every hardware wallet vendor, not just Coinkite.

Watch the audit wave. If machine-assisted review of old firmware is now cheap enough for an attacker to run at scale, the next disclosure of this type is a question of scheduling, not probability. The vendors with the shortest patch-to-disclosure gap will be the ones that survive the next one with their reputations intact.

For the wider macro setup this week and the dates that matter: this week's Weekly Brief


Sources

Bloomberg Coldcard Bitcoin Wallets Compromised as Hackers Exploit Software Flaw

Fortune Bitcoin Owners Rocked by $116 Million Hack: What We Know About the Coldcard Exploit

The Hacker News Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

TheStreet Crypto Coldcard Hack Just Grew to $89M

CryptoTimes Coldcard Hack Enters Wave 4: 449 BTC Swept Live

Blockhead A Five-Year-Old Coldcard Bug Let Hackers Guess Bitcoin Wallet Keys

Bitcoin Magazine Coinkite Releases Fixed Firmware After Coldcard Bug

Bitcoin.com News Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC

CaptainAltcoin Bitcoin Spot ETFs End Inflow Streak

Tools We Use

Kraken — Spot and futures on BTC, ETH, and 200+ assets.

Trezor — Cold storage. No internet connection required.

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Morgan Stanley Bought More Bitcoin the Same Week Galaxy Cut the CLARITY Act to 10%

Morgan Stanley headquarters, Times Square. Photo: Ajay Suresh / Wikimedia Commons (CC BY 2.0) By BitBrainers Editorial Morgan Stanl...

Morgan Stanley Bought More Bitcoin the Same Week Galaxy Cut the CLARITY Act to 10%