S&P 5007,489.72▲0.7% Nasdaq25,373.85▲1.0% Dow52,485.03▲0.5% Russell 2K2,931.34▼0.5% 10-Yr4.75%+8bp VIX15.99−1.10 WTI$86.80▲3.8% Gold$4,098.60▼0.0% EUR/USD1.153▲0.5% BTC$62,930▼2.8% Nikkei61,867▲0.7%
At close · Fri, Jul 31, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureColdcard exploit thief used a paid blockchain services…

Coldcard exploit thief used a paid blockchain services account, report says

About $70 million in Bitcoin was stolen, and researchers said affected holders should move funds from single-signature Coldcard addresses to secure custody.

Bitcoin Magazine reports that researchers and engineers investigating the Coldcard drain say the attacker used a paid account at a well known blockchain services provider to query source addresses and support activity during the sweeps.

According to an investigation write up shared on X by Clay Garrett, an engineer at Block, investigators identified an unusual pattern in the sweeps that matched a suspected attacker workflow, and authorities were notified.

Galaxy Digital’s research arm also said the thief’s unusual coin movement pattern indicates the same attacker across the activity, while cautioning that the observed behavior can resemble normal coin owner transfers.

Coinkite said the underlying issue involved a firmware bug in Coldcard Mk3 devices, beginning with version 4.0.1 in March 2021, that caused seed generation to fall back to a weaker pseudorandom number generator instead of the hardware true random number generator, enabling private keys to be predictable enough for brute force.

Coinkite later admitted all of its Coldcard models were vulnerable after additional thefts, after which engineers warned more Bitcoin addresses could be at risk and Bitcoiners were told to move funds out of single signature Coldcard addresses.

Latest closeBitcoin $62,929.67 ▼2.8%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.