What Actually Happened?
According to Cointelegraph's roundup (Hodler's Digest from August 2), market sentiment was hit by a "nasty" loss of bitcoin from cold storage, meaning offline wallets that are supposed to be the best protected against online attacks.
The scale of the damage grew steadily. Analytics firm Galaxy Research, as cited by Decrypt, documented a third wave of thefts tied to Coldcard wallets. The sum of observed losses climbed to roughly 1,367 BTC spread across 4,585 addresses. In dollar terms, various sources land somewhere around $88 million to $90 million (Decrypt cites approximately $88 million, CoinDesk $89 million, Cointelegraph $90 million). The differences reflect how the losses are calculated and at what point in time.
The key word is "observed" losses. This is the volume that analytics firms were able to track on-chain, not necessarily the final figure.
How Did the Market React? The Opposite of 2022
The most interesting data point comes from CoinDesk. According to blockchain analytics firms, smaller bitcoin holders began, in response to the vulnerability, sending funds back to exchanges for a sense of security.
That is the exact opposite of what happened after the FTX exchange collapsed in late 2022. Back then, investors pulled coins off exchanges into self-custody in droves, following the motto "not your keys, not your coins." Now that it has become clear the problem can also sit on the hardware wallet side, part of the flow has reversed.
We need to be precise: the sources describe a change in the direction of flow among smaller holders, not a specific volume, nor that this is a market-wide trend. Charliedesk does not give advice on where to store your coins. This is a description of behavior, not a recommendation.
Was It a Fault in the Coldcard Device Itself?
Caution is warranted here. The available sources speak of a "Coldcard exploit" and of thefts tied to these wallets, but the exact technical mechanism of the attack and precisely where the flaw originated cannot be conclusively drawn from the four cited sources. We therefore do not state whether it was a firmware bug, a supply chain compromise, social engineering, or a combination. For now we mark this as unknown.
What Is Regulation Doing About It? The Clarity Act Hangs in the Balance
Hodler's Digest also flagged a legislative thread in the US. The Clarity Act bill, according to Cointelegraph, stalled at a dead end, with five days remaining until a possible Senate vote at the time of publication. Whether the vote will happen and how it will turn out is a matter for the future, which we do not prejudge.
And What About That Other Security Report Around the XRP Ledger?
Alongside this, a separate, unrelated event took place in the XRP ecosystem. According to CryptoSlate, XRP Ledger validators quietly blocked a "silent" exploit that could theoretically have drained victims' accounts purely through transaction fees.
RippleX, according to CryptoSlate, expects a new version of its key server software, xrpld 3.3.0, possibly as soon as the following week. The release is meant to return reworked Batch and Permission Delegation amendments to the validator process, after operators blocked their predecessors due to authorization bugs before they could activate on mainnet. As of August 1, the latest stable version was still xrpld 3.2.1; beta and release-candidate tags for 3.3.0 were public, but the majority countdown on mainnet had not yet begun for any of the replacement amendments. So this remains a preliminary phase.
What to Watch in Similar Cases
- Whether observed losses keep growing. Galaxy Research described a third wave already; the figure is ongoing, not final.
- An official technical statement on the nature of the vulnerability (so far these sources give us no clear technical description).
- Whether the shift of flow to exchanges is confirmed in broader data, or remains a phenomenon among smaller holders.
- The fate of the Clarity Act in the Senate and the actual activation of XRPL amendments on mainnet.
This text is a summary of what is documented as of August 2 in the four cited sources. Where the sources stay silent, so do we.

