Key Takeaways
- Coinkite thefts reached 1,359.8820 BTC after new attack waves through Aug. 2.
- OP_RETURN carried a 10% laundering offer to the Coldcard hacker on Aug. 1.
- Coldcard users await Coinkite guidance as firmware bricking reports continue.
The new developments come just days after Coinkite disclosed that a long-dormant firmware flaw had allowed attackers to recover weakly generated wallet seeds and systematically drain vulnerable single-signature wallets. The estimated total has now climbed to roughly 1,359.8820 BTC, according to stats collected by the Coldcard Sweep Watch dashboard, with most of the identified coins remaining in a handful of addresses under the attacker’s control.
OP_RETURN Turns the Bitcoin Blockchain Into a Public Bulletin Board
On Aug. 1, one of the attacker’s holding addresses received an unusual transaction containing an OP_RETURN message. OP_RETURN is a special Bitcoin transaction output that stores permanent text on the blockchain rather than transferring spendable funds.

The message openly advertised services to “clean” bitcoin, provide know-your-customer (KYC) assistance, and cash out the stolen coins in exchange for a 10% fee, along with a Telegram contact. It was not a technical message or a victim appeal. Instead, it appeared to be a direct solicitation aimed at whoever controls the stolen bitcoin. Some suggest it could be law enforcement or someone setting a trap.
Attack Leaves Most Stolen Bitcoin Sitting in Plain Sight
Although the theft involved more than 1,300 BTC, blockchain researchers have observed that much of the bitcoin remains largely untouched. The attacker consolidated funds into a relatively small number of addresses after sweeping vulnerable wallets during several coordinated waves beginning on July 30.
That visibility has become one of the more unusual aspects of the case. Bitcoin’s transparent ledger allows anyone to monitor high-value addresses, meaning victims, investigators, researchers, and even opportunists can all watch the same transactions unfold in real time. OP_RETURN messages demonstrate that the blockchain can also function as a permanent public messaging system during major incidents.
Several projects that have been hacked in the past use OP_RETURN messages to discuss bounties and demands with hackers.
Emergency Firmware Fix Creates New Headaches
As users rushed to secure their remaining funds, another problem emerged.
Coinkite released emergency firmware updates designed to eliminate the weak random number generation that caused the original vulnerability. The company made clear that the new firmware only protects wallets created in the future and does not repair seeds already generated on vulnerable versions.

Soon after the release, users began reporting that some devices became stuck on error screens, failed to boot or appeared completely bricked after installing the update. Reports have primarily involved Mk4 and Q devices, although some Mk3 users have also described similar problems. As of Aug. 2, Coinkite had not publicly confirmed a widespread firmware defect, but several user reports have fueled growing concern throughout the Bitcoin community.
Security Experts Push Users to Move Funds First
One of the strongest messages circulating among experienced bitcoin security advocates is that owners of potentially vulnerable wallets should migrate funds before updating firmware whenever possible.
That recommendation reflects an important limitation of the emergency patch. Updating software cannot strengthen a weak seed that was already created years ago. If the original wallet was generated with insufficient randomness, the only lasting solution is to move funds into an entirely new wallet created with strong entropy.
For many users, verified seed backups have become the difference between a hardware failure and permanent loss, since a damaged device can often be replaced while the recovery phrase restores access to the funds.
Confidence Faces Its Biggest Test Yet
The ongoing Coldcard incident has evolved beyond a single firmware flaw into a broader test of confidence in hardware wallet security. The combination of a historic entropy bug, a public laundering solicitation embedded directly on Bitcoin’s blockchain and reports that emergency updates may brick some devices has intensified debate over wallet design, seed generation, and long-term self-custody practices.
While monitoring of the known attacker addresses continues, users are now watching two developments just as closely: whether the stolen bitcoin eventually moves and whether Coinkite issues additional guidance for customers experiencing firmware failures.

