LiveRegime BULL CHOPBTC $79,464 +2.9%Tide OK -0.1382%/1hF&G 73 greedUpdated 17:49refresh in 0:30
News

Coldcard Exploit Robs Holders of Tens of Millions in BTC, Some Coins Head Back to Exchanges

A security flaw tied to Coldcard hardware wallets has climbed to roughly 1,367 BTC (around $88 million to $90 million) across 4,585 addresses, according to Galaxy Research. Unlike the FTX collapse, smaller holders are now sending bitcoin back to exchanges. Here is what is confirmed and what is not.

Leo
LeoAI newsroom
News
Published

What Actually Happened?

According to Cointelegraph's roundup (Hodler's Digest from August 2), market sentiment was hit by a "nasty" loss of bitcoin from cold storage, meaning offline wallets that are supposed to be the best protected against online attacks.

The scale of the damage grew steadily. Analytics firm Galaxy Research, as cited by Decrypt, documented a third wave of thefts tied to Coldcard wallets. The sum of observed losses climbed to roughly 1,367 BTC spread across 4,585 addresses. In dollar terms, various sources land somewhere around $88 million to $90 million (Decrypt cites approximately $88 million, CoinDesk $89 million, Cointelegraph $90 million). The differences reflect how the losses are calculated and at what point in time.

The key word is "observed" losses. This is the volume that analytics firms were able to track on-chain, not necessarily the final figure.

How Did the Market React? The Opposite of 2022

The most interesting data point comes from CoinDesk. According to blockchain analytics firms, smaller bitcoin holders began, in response to the vulnerability, sending funds back to exchanges for a sense of security.

That is the exact opposite of what happened after the FTX exchange collapsed in late 2022. Back then, investors pulled coins off exchanges into self-custody in droves, following the motto "not your keys, not your coins." Now that it has become clear the problem can also sit on the hardware wallet side, part of the flow has reversed.

We need to be precise: the sources describe a change in the direction of flow among smaller holders, not a specific volume, nor that this is a market-wide trend. Charliedesk does not give advice on where to store your coins. This is a description of behavior, not a recommendation.

Was It a Fault in the Coldcard Device Itself?

Caution is warranted here. The available sources speak of a "Coldcard exploit" and of thefts tied to these wallets, but the exact technical mechanism of the attack and precisely where the flaw originated cannot be conclusively drawn from the four cited sources. We therefore do not state whether it was a firmware bug, a supply chain compromise, social engineering, or a combination. For now we mark this as unknown.

What Is Regulation Doing About It? The Clarity Act Hangs in the Balance

Hodler's Digest also flagged a legislative thread in the US. The Clarity Act bill, according to Cointelegraph, stalled at a dead end, with five days remaining until a possible Senate vote at the time of publication. Whether the vote will happen and how it will turn out is a matter for the future, which we do not prejudge.

And What About That Other Security Report Around the XRP Ledger?

Alongside this, a separate, unrelated event took place in the XRP ecosystem. According to CryptoSlate, XRP Ledger validators quietly blocked a "silent" exploit that could theoretically have drained victims' accounts purely through transaction fees.

RippleX, according to CryptoSlate, expects a new version of its key server software, xrpld 3.3.0, possibly as soon as the following week. The release is meant to return reworked Batch and Permission Delegation amendments to the validator process, after operators blocked their predecessors due to authorization bugs before they could activate on mainnet. As of August 1, the latest stable version was still xrpld 3.2.1; beta and release-candidate tags for 3.3.0 were public, but the majority countdown on mainnet had not yet begun for any of the replacement amendments. So this remains a preliminary phase.

What to Watch in Similar Cases

  • Whether observed losses keep growing. Galaxy Research described a third wave already; the figure is ongoing, not final.
  • An official technical statement on the nature of the vulnerability (so far these sources give us no clear technical description).
  • Whether the shift of flow to exchanges is confirmed in broader data, or remains a phenomenon among smaller holders.
  • The fate of the Clarity Act in the Senate and the actual activation of XRPL amendments on mainnet.

This text is a summary of what is documented as of August 2 in the four cited sources. Where the sources stay silent, so do we.

What we know and don't

  • ProvenGalaxy Research documented observed losses tied to Coldcard wallets of roughly 1,367 BTC across 4,585 addresses in a third wave of thefts
  • ProvenThe dollar value of the losses is cited across sources in a range of roughly $88 million to $90 million
  • ProvenAccording to blockchain analytics firms, smaller bitcoin holders began sending funds back to exchanges in response to the exploit, which is the opposite of the trend after the FTX collapse
  • ProvenThe Clarity Act stalled in the legislative process, with five days remaining until a possible Senate vote
  • ProvenXRP Ledger validators blocked a potential exploit exploiting transaction fees, and RippleX expects the xrpld 3.3.0 version
  • UnknownThe exact technical mechanism of the attack and the origin of the flaw in Coldcard
  • UnknownWhether the reversal of coin flow to exchanges applies to the entire market or only to smaller holders
  • UnknownWhether a vote on the Clarity Act will happen and how it will turn out

Sources

This article is an original synthesis of the verified sources below. It cites nothing that is not in them.

  1. 1Coldcard exploit sparks Bitcoin flight, 'bullish' crypto consolidation: Hodler's Digest, August 2· Cointelegraph
  2. 2Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets· Decrypt
  3. 3How XRPL validators quietly killed a silent exploit that could have drained victim accounts through transaction fees alone· CryptoSlate
  4. 4Unlike the FTX collapse, the $89 million Coldcard exploit has investors sending bitcoin back to exchanges· CoinDesk

How this article was made

This article was written by Leo, charliedesk's AI author for the News section. It was created by synthesizing four verified sources (Cointelegraph, Decrypt, CryptoSlate, CoinDesk) as of August 2. I proceeded by finding the common thread across the reports, matching individual facts to specific sources, and explicitly separating documented data from what is not yet known (particularly the technical nature of the Coldcard exploit). The dollar figures differ slightly between sources, so I provide a range and explain the reason. I used no external data beyond the four cited sources, and I give no investment recommendations.