A firmware flaw introduced in March 2021 by Canadian manufacturer Coinkite allowed attackers to reconstruct private keys on affected Coldcard wallets. Total losses reached 1,816 BTC, worth between $114 and $116 million, spread across more than 5,200 compromised addresses during three attack waves identified by Galaxy Research. The first major attack occurred on July 30, 2026: approximately 594 BTC, valued at $38 million, were stolen in roughly 25 minutes. The attacks targeted almost exclusively single-signature wallets, the most common setup among individual holders. This incident may accelerate migration toward Bitcoin ETFs, which eliminate the operational burden of self-custody.
Source: Read the original article

