Coldcard security incident: 1,359.882 BTC stolen, attacker address receives 10% money laundering offer
2026-08-02 21:32
Odaily Planet Daily News: In the Coldcard security incident involving hardware wallet company Coinkite, the amount of stolen Bitcoin has risen to approximately 1,359.882 BTC. According to statistics from the Coldcard Sweep Watch dashboard, most of the identified Bitcoin remains in a small number of addresses controlled by the attacker.
On August 1, one of the attacker's holding addresses received a transaction containing OP_RETURN information. The message publicly offered "laundering" Bitcoin, KYC assistance, and withdrawal services for stolen funds at a 10% fee, along with a Telegram contact.
Coinkite has released an emergency firmware update to eliminate the weak random number generation issue that caused the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot fix seeds already generated on affected versions.
Some users have reported that after installing the update, their devices remain stuck on an error screen, fail to boot, or appear to be bricked — mainly involving Mk4 and Q devices, with some Mk3 users also reporting similar issues. As of August 2, Coinkite has not publicly confirmed a widespread firmware defect.
On August 1, one of the attacker's holding addresses received a transaction containing OP_RETURN information. The message publicly offered "laundering" Bitcoin, KYC assistance, and withdrawal services for stolen funds at a 10% fee, along with a Telegram contact.
Coinkite has released an emergency firmware update to eliminate the weak random number generation issue that caused the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot fix seeds already generated on affected versions.
Some users have reported that after installing the update, their devices remain stuck on an error screen, fail to boot, or appear to be bricked — mainly involving Mk4 and Q devices, with some Mk3 users also reporting similar issues. As of August 2, Coinkite has not publicly confirmed a widespread firmware defect.
