cleartext

Independent, sourced crypto news. No paid placements.

bitcoin

Coldcard's seed flaw is still live, and an exchange is already selling the moral

Coinkite says the entropy flaw behind up to $114 million in stolen bitcoin is still live and requires manual migration, while OKX claims the theft is driving record deposits to exchanges.

Coinkite, the company behind the Coldcard hardware wallet, told users on Tuesday to move their bitcoin now. "Please treat this as urgent. Migrate your funds," the company wrote from its @COLDCARDwallet account on August 4, asking holders to warn people who are "less online" and adding that "the threat is still ongoing." CoinDesk reported the post and confirmed the exploit remains active.

The technical problem is a seed-generation defect that has been sitting in Coldcard firmware since 2021. A seed is the master secret from which every key in a wallet is derived; if it is produced with too little randomness, an attacker can guess and regenerate it and drain the wallet remotely, never touching the physical device. That is what appears to have happened, in waves.

Who is exposed

Per Coinkite's advisories as reported by CoinDesk, the risk is device- and firmware-specific:

  • Mk3 — the 2019 model — is at risk if the wallet was set up on firmware 4.0.1 or later. Move funds now.
  • Mk4, Mk5 and Q are at risk on firmware below 5.6.0 (or 1.5.0Q). Update, generate a new wallet, then move the coins.
  • Dice-roll wallets are safe. Users who physically rolled dice at least 50 times and typed the results in built their key from those numbers rather than the device's own generator. Those wallets never executed the broken code.

The remedy cannot be pushed out. A firmware update alone does not help, because a seed already generated with weak entropy stays guessable forever. Every affected holder has to update, create a new seed, and hand-move funds — which is why Coinkite is asking the online crypto population to go find the people who aren't reading Twitter.

The size of it, and the disagreement

The two accounts do not match, and the gap matters.

The Block, reporting Tuesday, cited Galaxy Research linking the vulnerability to the theft of more than 1,300 BTC worth over $80 million from thousands of addresses across multiple waves. CoinDesk, the same day, cited Galaxy's revised count: a possible fourth wave of sweeps running through Monday took roughly 449 BTC from 709 addresses, lifting cumulative losses from about $89 million to as much as $114 million.

Both trace to the same research shop. The most plausible reading is that The Block's figure predates the fourth wave and CoinDesk's does not — but The Block does not date-stamp its number, and Galaxy's own count has been revised at least once. Treat the honest range as $80 million to $114 million and rising, with the upper bound coming from a count that was still moving on Monday.

Bitcoin itself did not care. CoinDesk data put the price near $63,800 in early US hours on Tuesday, little moved after the warning.

Key facts

FactSource
Exploit confirmed still active; users told to migrate fundsCoinkite (@COLDCARDwallet), Aug 4, 2026, via CoinDesk
Flaw dormant in firmware since 2021CoinDesk, first reported Friday
>1,300 BTC / >$80M stolen across multiple wavesGalaxy Research, via The Block
Fourth wave: ~449 BTC from 709 addresses; cumulative ~$89M → up to $114MGalaxy Research revised count, via CoinDesk
At risk: Mk3 on fw 4.0.1+; Mk4/Mk5/Q below fw 5.6.0 / 1.5.0Q; dice-roll wallets safeCoinkite advisories, via CoinDesk
BTC ~$63,800, little movedCoinDesk data, Aug 4
"Record levels of inflows" to centralized exchanges post-ColdcardJonathan Brockmeier, OKX Chief Compliance Officer, to The Block
OKX says it blocked $26.3M in scam-related losses in H1 2026OKX, self-reported to The Block
>$1B lost to crypto hacks in H1 2026; record verified exploitsBlockaid, via The Block
Bybit theft of ~$1.4B in 2025 remains the largest on recordThe Block

The real-world read

The "record inflows" claim comes with no receipts. OKX Chief Compliance Officer Jonathan Brockmeier told The Block, "We're seeing record levels of inflows now to centralized exchanges post-Coldcard." There is no number, no timeframe, no baseline, and no on-chain corroboration anywhere in the reporting — not a deposit total, not a percentage, not a comparison period. It is an unfalsifiable claim about industry-wide flows, made by an executive at one exchange, about the one behaviour that exchange monetises.

Note who is making it, and what they're selling. The same article records that OKX launched in the US in 2025 and is pushing into Europe on its MiCA authorization — while noting Binance missed the July 1 licensing deadline — and that ICE, the NYSE's parent, invested at a $25 billion valuation. A hardware-wallet failure that pushes retail back to custodial venues is, for OKX, a sales narrative. Brockmeier's framing — "self-custody puts a lot on the user and asks them to be their own security engineer" — is the pitch, dressed as observation.

The $26.3 million is a counterfactual. OKX's claim that it "prevented" that much in scam losses in H1 by stopping suspicious transfers is self-reported, self-defined, and structurally unauditable: nobody can verify losses that didn't happen. Report it as OKX's number, not as a fact about the world.

The "flip side of FTX" line is rhetoric, not data. Brockmeier's neat inversion — FTX drove people to self-custody, Coldcard drives them back — is a good soundbite standing on the same absent evidence as the inflow claim.

The counter-quote is interested too. CoinDesk quotes a source identified only by the surname Bouzon — no first name, no employer given in the report — saying custodial holdings are "not ownership, it's an IOU," and that entropy "must be anchored in secure hardware." That is a hardware-security argument advanced by someone whose stake in it the reader cannot assess.

What nobody is saying. There is no statement in either report on compensation or restitution for drained users, no published count of how many devices were shipped with the defect, and no root-cause postmortem explaining how an entropy bug survived five years in a product sold specifically on its security. Also unaddressed: the device's own randomness was the weak link, and the safe path — dice — was the one that bypassed it.

One outlet, two framings. CoinDesk's news story says the threat is live and urgent; its own front-page headline list the same morning reads "Bitcoin rises toward $64,000 as Coldcard exploit, Strategy sales recede." Both can't be right.

Opinion, and whose

  • Brockmeier (OKX) — that exchanges are seeing record post-Coldcard inflows, that self-custody offloads security onto users, and that "if the friction's low, the fraud will flood in." Opinion and unverified claim from a party that profits if readers agree.
  • Bouzon (via CoinDesk) — that software wallets on non-secure hardware are riskier still, and custody at an exchange "isn't ownership, it's an IOU." Opinion; affiliation undisclosed.
  • Galaxy Research — the loss totals are its estimates and have been revised. Estimates, not audited figures.

Nothing here is a forecast anyone has put a number on, and no one quoted has said what happens next.

Sources

  • CoinDesk (Aug 4, 2026), "Coldcard urges users to move bitcoin as active wallet exploit continues" — Coinkite's August 4 advisory and tweet text, affected model/firmware list, the dice-roll exception, the 2021 dormancy, Galaxy's revised fourth-wave count (449 BTC / 709 addresses; ~$89M → up to $114M), the Bouzon quotes, and the ~$63,800 price. The same page carried a promotional Binance "case study" — exchange marketing, not reporting, and unrelated to the story.
  • The Block (Aug 4, 2026), RT Watson, "OKX says Coldcard exploit triggers 'record' inflows to centralized exchanges" — the Brockmeier interview, OKX's $26.3M self-reported figure, Galaxy's earlier >1,300 BTC / >$80M count, Blockaid's >$1B H1 hack total, the Bybit comparison, and OKX's regulatory and ICE-valuation context. The Block discloses that Foresight Ventures is its majority investor and that exchange Bitget is an anchor LP of Foresight — relevant when the story is about exchanges. The page also carried sponsored placements (LMAX Digital, Polymarket) unconnected to the reporting.
  • Primary material referenced within both: Coinkite's public advisories and its @COLDCARDwallet post of August 4, 2026; Galaxy Research's loss estimates, seen here only secondhand.

Not financial advice. If you hold an affected Coldcard, read Coinkite's advisory for your model.