BlockBeats reported on Aug. 3 that 1,359 BTC had been stolen in the Coldcard hardware wallet incident. Some users also said their devices became stuck on an error page after installing an update, failed to boot, or appeared to be bricked.
Based on the information now public, the incident has become the biggest Bitcoin theft of the year. BlockBeats compiled a timeline of how the attack unfolded.
A flaw that sat in code for more than five years
Analysis cited by the report said the attacked Coldcard firmware code was released in March 2021, while the underlying flaw had existed in open-source code for more than five years. The issue affected the Mk3 and some Mk2 devices, as well as seed generation on the Mk4, Q, and Mk5 before the fix.
The large-scale exploitation did not arrive until July 30, 2026. Attackers then launched an automated sweep across hundreds to more than a thousand addresses within roughly 25 to 41 minutes.
On-chain estimates expanded as investigators traced the funds
Initial visible data pointed to about 500 single-signature wallets, 1,324 UTXOs, and roughly 594.5 BTC under attack. Later on-chain analysis expanded that scope to about 1,196 addresses and 1,082.65 BTC, valued in the report at about $70.2 million.
The attack reportedly prioritized addresses with larger balances. It also used a fixed high fee and no change outputs, with the stolen funds quickly consolidated into a small number of addresses.
Coinkite acknowledged a seed-generation issue
Coldcard developer Coinkite later released a security notice and said it had preliminarily confirmed a seed-generation issue affecting the Mk3, specifically firmware version 4.0.1 and later. The company advised affected users to migrate carefully.
Coinkite also said the attacker may have used AI to review the open-source code and identify the vulnerability.
Alex Thorn said the campaign is still developing
As of Aug. 2, Galaxy head of research Alex Thorn said the attacks tied to Coldcard wallets were still unfolding. He said more small-scale attackers and copycats had already emerged and were targeting remaining Coldcard mnemonic phrases.
Broader debate over self-custody risk
The incident drew wider attention. Bloomberg senior ETF analyst Eric Balchunas said the Coldcard team has only five employees, adding that the number is far too low for a company of that importance.
CZ also commented on the limits of patching in self-custody setups. He said that even if developers fix the flaw, they cannot repair wallets that were already generated before the fix. He added that developers also cannot directly contact and warn users who operate on isolated devices. Until users take action on their own, those wallets may remain exposed to attack. CZ said he supports self-custody, but that it also means users bear the security responsibility themselves.
BitGo answered with a public AI challenge
Because the incident may involve AI breaking into crypto devices, institutional custody platform BitGo moved quickly. On Aug. 1, BitGo CEO Mike Belshe deposited 100 BTC into a public Bitcoin address and invited Anthropic’s Claude model to try moving the funds.
According to the report, BitGo uses multisignature or multi-party computation technology to split signing authority across several independent keys. As of Aug. 2, Anthropic had not responded publicly to the challenge.
Bitcoin slipped from $65,000 to $63,000
The report added that Bitcoin had remained weak since July 31, possibly under pressure from the incident, falling from $65,000 to $63,000.

