
OKX has reported record inflows to its centralized exchange following the Coldcard hardware wallet exploit, as users increasingly prioritize managed custody after one of the largest known Bitcoin wallet security incidents. According to The Block, OKX Chief Compliance Officer Jonathan Brockmeier said customer behavior has changed noticeably, with the exchange recording unusually high inflows as users move assets away from self-custody. "We're seeing record levels of inflows now to centralized exchanges post-Coldcard," Brockmeier told The Block. "It's interesting — it's sort of the flip side of FTX. FTX happens, and everybody moves their money into self-custody, and it's coming back now." He explained that managing private keys requires users to take responsibility for their own security, while exchanges can offer dedicated security teams and automated monitoring systems.
The Coldcard Bitcoin theft has escalated to a fourth wave, with attackers now targeting smaller wallet balances and implementing more sophisticated techniques. According to Galaxy Research head Alex Thorn, the fourth wave moved 448.7 BTC from 709 addresses during a suspected coordinated attack on August 3, 2026. Thorn described the addresses as "LIKELY Coldcard victims," saying their unspent outputs and transaction behavior matched the vulnerable-wallet pattern. Galaxy measured 13.8 sweeps per block during the latest activity, compared with just 0.3 sweeps per block during a pre-incident control period, representing a 45-fold increase above baseline levels. The attack pattern shows most transactions sent each victim's funds to a fresh destination rather than a shared collection wallet, with some funds already moved to second-hop addresses, making the flow harder to follow. As per Galaxy Research, the fourth wave brings the total observed losses to approximately 1,816 BTC across 5,294 addresses, assuming the groups do not overlap with previous waves. However, Galaxy Research has now narrowed confirmed losses to 1,596 BTC across three confirmed waves, with the latest estimate excluding the fourth wave due to pending victim confirmation. Galaxy Research also identified 14 smaller related incidents, pushing suspected losses toward 2,005 BTC, or nearly $130 million. Galaxy also reported that roughly 90% of the stolen Bitcoin has not moved since the attacks, giving investigators additional time to monitor the funds if they begin moving through exchanges or other services.
Alongside the change in customer behavior, OKX has expanded its fraud prevention capabilities as digital asset scams continue affecting users. According to figures shared by OKX, the exchange prevented $26.3 million in scam-related losses during the first half of 2026 by stopping suspicious transfers before they were completed. The company also protected more than $1.1 billion in customer assets belonging to over 500,000 users during the same period. OKX uses layered security controls supported by artificial intelligence to identify suspicious behavior before customers are affected, while still allowing users to choose self-custody if they prefer. Brockmeier explained that the exchange has expanded its use of artificial intelligence to monitor blockchain activity for patterns associated with compromised devices, account takeovers and social engineering attacks before customer funds leave the platform. He added that security preferences should vary depending on each customer's needs, with users who want additional protection able to choose stricter account controls even when the exchange's internal systems do not classify their accounts as high risk.
Coinkite issued a security advisory on July 30, 2026 warning Coldcard Mk3 users to move Bitcoin from wallets whose seed phrases were generated on affected firmware versions. According to the company's official advisory, seeds created on firmware 4.0.1 through 4.1.9 or any later Mk3 release through version 5.0.3 may put funds at risk. The Canadian hardware maker emphasized that the Coldcard Mk4, Q and Mk5 are not affected based on early analysis, and wallets using an affected seed with a BIP-39 passphrase face minimal risk. Coinkite CEO Rodolfo Novak, known in the industry as NVK, confirmed the company is treating the reports with urgency, stating "We are all hands on deck doing a deep dive on everything, technical post soon." The company's advisory report noted that other Coinkite hardware signers, such as TAPSIGNER, OPENDIME, and SATSCARD, remained unaffected, while seedphrases generated on Mk4, Q, and Mk5 before the fixed firmware release were also affected. In a recent open letter, NVK urged affected users to "move your funds now, using our updated best practices, before reading further," emphasizing that while the fix protects new seeds going forward, it does not eliminate risk for seeds already generated on vulnerable firmware. Coinkite released hotfixes for every affected model and said it takes "full accountability" for the bug, but installing new firmware only corrects future seed generation - it cannot add entropy to existing recovery phrases. The company has also destroyed all remaining inventory containing vulnerable firmware and released emergency firmware updates for every affected product.
According to a report published by Block's Bitcoin engineering and security teams, the vulnerability stems from a build setting that caused Coldcard devices to skip their own hardware randomness generator and fall back to predictable software-based key generation. The flaw was introduced in firmware 4.0.0 released in March 2021, with a check in a supporting library testing only whether the setting existed rather than whether it was actually switched on. Key generation quietly fell through to a basic software substitute seeded from the chip's serial number and clock registers, where the serial number is fixed factory metadata and clock values are timing state that an attacker can narrow down or measure. As per AMBCrypto, the bug made some Mk3 recovery phrases predictable due to weak entropy, reducing the number of guesses a hacker needed to make by altering how the system selected the words. Normally, a hardware wallet generates the seed phrase using true randomness from 340 undecillion combinations, but the flaw reduced this to a few billion combinations, making the search space extremely smaller for attackers. According to Coinkite's technical analysis, the issue stemmed from a firmware integration error that prevented the intended hardware random number generator from contributing to seed creation. Instead, the affected process relied on a deterministic software fallback in MicroPython, which generated entropy from device information and timing data rather than from a cryptographically secure hardware source. Coinkite estimated that affected Coldcard Mk3 devices generated seeds with roughly 40 bits of effective entropy, while later Mk4, Mk5, and Q devices incorporated additional entropy from their secure elements, increasing the effective search space to approximately 72 bits. Coinkite's investigation remains open, and the company has promised a formal technical review.
The latest Coldcard incident has renewed discussion around how hardware wallets are tested before reaching customers. Kraken Chief Security Officer Nick Percoco has argued that manufacturers should not be the only parties validating how production firmware generates wallet seed phrases. Writing on X earlier this week, Percoco argued that independent testing should confirm that approved hardware entropy sources are actually used during wallet creation instead of relying primarily on code reviews or vendor audits. To support that argument, Percoco pointed to NIST SP 800-90B, which governs validation of true random-number generators used in cryptographic systems, and Germany's BSI AIS-31 framework. According to him, comparable end-to-end verification is not routinely performed for hardware wallet firmware despite the importance of secure seed generation. The latest Coldcard incident has unfolded against a year of continued security breaches across the cryptocurrency industry, with last year's Dubai-based exchange Bybit losing approximately $1.4 billion in the largest recorded cryptocurrency theft, while blockchain security firm Blockaid reported that crypto projects lost more than $1 billion to hacks during the first half of 2026 as the number of verified exploits reached a record level.