Coinkite Tells Coldcard Users to Migrate as a Third Sweep Lands

Coinkite put out a public update on Sunday 2 August setting out what owners of affected Coldcard hardware wallets should do, and what they should not. The vulnerability in its seed generation had been confirmed on Friday, the company said. Holders should generate a fresh seed on patched firmware and move their coins to it, and should hold on to the affected devices, which may be needed for recovery. In the same post the company pointed users at five competing hardware wallets as reputable options. The statement landed the same morning Galaxy Research flagged a third sweep of vulnerable addresses, one that pushed the running tally close to 1,367 BTC and roughly $89 million.
Keep the device, replace the seed
The distinction Coinkite drew matters for anyone still holding an affected unit. Patched firmware "prevents this issue from affecting any new seed generated going forward", the company said. It repairs generation, not keys that already exist. A seed produced on vulnerable firmware stays weak however many updates the device receives, so the only remedy is a new seed and a transfer of funds to it. Coinkite shipped emergency firmware on 31 July, after the flaw was traced to a build flag left switched off in a 2021 firmware configuration. Only seeds generated on the device itself are at risk. Wallets set up with dice rolls, or protected by a BIP39 passphrase, an extra word supplied on top of the recovery phrase, fall outside the affected set.
Five rivals, named in public
The Sunday post named Bitkey, Ledger, Trezor, Jade and BitBox as "reputable options" for users who wanted to move to different hardware. Vendors rarely send customers to competitors by name. The list read as an acknowledgment that some holders would not put a second seed on Coldcard hardware regardless of the fix. The instruction to keep the affected devices cuts the other way: a unit that generated a compromised seed is still the device holding the record of it, and destroying one before a migration is finished risks losing access to coins that have not yet moved.
A smaller haul from smaller victims
Galaxy Research put the third sweep at roughly 208 BTC taken from 1,912 addresses between Friday and Saturday UTC. The economics of it had shifted. The first wave averaged close to a full bitcoin per victim and ran for 41 minutes; the third averaged about a tenth of a bitcoin. The attacker also changed method, sending each victim's coins to its own destination address rather than pooling them in shared collectors, using pay-to-witness-script-hash outputs, a segwit output type that commits to a script and not a single key, and scanning only default derivation paths, the account structures wallets use out of the box. Galaxy said each wave looked like the work of a single operator but could not confirm one actor across all three. It read the falling average loss as a sign that the profitable end of the vulnerable key space had already been drained. Chainalysis separately found the sweep had gone after the largest wallets first, with a $1.8 million victim early on and about $30 million taken in the first ten minutes; two of the largest losses added to a combined $4 million.
Totals that move with their as-of dates
The headline figures are not settled, and the outlets carrying them do not agree with one another. The technical write-ups put the cumulative loss across three waves at 1,367.05 BTC and about $88.6 million, while CoinDesk carried 1,367 BTC worth "nearly $89 million at recent prices". Close, but not the same accounting, and both are running tallies, not final counts. The individual waves have the same problem. The first was counted at 594 BTC when the sweep was first reported and later reconstructed at 1,082.65 BTC by some accounts and 1,083 BTC by others, across 1,196 addresses. We could not establish which reconstruction supersedes the other. Every figure in this incident needs its as-of date attached. What stays open is how much of the vulnerable key space remains reachable, and how many holders finish migrating before someone reaches their coins.
Read also: Strategy Sells 1,638 BTC in Its Second Monetization Step