Bitcoin absorbed a $116 million hardware-wallet hack, fresh corporate selling and a stalled US crypto bill in a single week — and still held near $64,000.
Bitcoin absorbed a $116 million hardware-wallet hack, fresh corporate selling and a stalled US crypto bill in a single week — and still held near $64,000.

Bitcoin absorbed a $116 million hardware-wallet hack, fresh corporate selling and a stalled US crypto bill in a single week — and still held near $64,000.
Bitcoin held near $64,000 on Aug. 5 after a $116 million Coldcard wallet hack, fresh Strategy selling and a stalled Clarity Act in Congress.
Attackers drained 1,816 bitcoin, worth about $116 million, from more than 5,200 addresses generated on Coldcard devices, according to blockchain intelligence firm Galaxy Research.
Galaxy Research counted the largest sweep at 1,082 bitcoin from 1,196 wallets, broadcast inside 41 minutes on July 30. A fourth wave emptied another 709 addresses on Monday, bringing total losses to 1,816 bitcoin. Bitcoin traded near $64,300 through all of it.
The hack, which Coinkite chief executive Rodolfo Novak called "some of the hardest in this company's history," has reignited a debate over self-custody and pushed institutional custodians to pitch their services, even as bitcoin's resilience near $64,000 suggests underlying support.
The vulnerability dates to Coldcard firmware version 4.0.0, shipped in March 2021. A build setting told the device to skip its dedicated hardware randomness chip during key generation, falling back to a software substitute seeded from the chip's serial number and clock registers. On Mk4, Mk5 and Q devices, researchers put the reproducible search space at roughly four billion possibilities, which runs on ordinary hardware. On the older Mk3, effective randomness dropped from 128 bits to about 40.
Nobody was phished and no device was stolen. "A hardware wallet's security ultimately comes down to the firmware and systems users interact with but never see," said Ido Ben-Natan, co-founder and chief executive of Blockaid.
Coinkite urged users who generated a seed on a Coldcard to move funds immediately. Novak suggested AI-assisted code review may have found the bug, a claim security specialists rejected as a human engineering failure. Andrew Lazutkin, chief technology officer at Tangem, drew a different lesson: "This incident is a good example of why open-source firmware should not automatically be equated with better security."
The hack is the latest in a year of escalating crypto theft. Over the past six months, attackers launched 207 separate incidents — the most ever recorded in any half-year period by blockchain analytics platform TRM Labs — though total losses of about $972 million were less than half the $2.3 billion stolen in the first half of 2025.
The incident has reignited a long-running debate among bitcoin holders over where to keep their coins. Binance founder Changpeng Zhao cited a precedent: "You may or may not know, @TrustWallet faced this exact same bug years ago, a pseudo-random number generator, ie, not truly random, $12m in losses. They covered every user."
Strategy, the largest corporate holder, sold 1,638 bitcoin for $104.7 million between July 27 and August 2 to fund preferred dividends and buybacks, adding supply pressure. The Clarity Act, which would set a federal framework for digital assets, has stalled in Congress, delaying regulatory clarity.
Bitcoin's resilience near $64,000 despite the week's negative news flow suggests strong underlying support. A breakout could come if sentiment shifts, but the Coldcard hack has eroded trust in hardware-wallet security, potentially slowing cold-storage adoption among retail holders.
This article is for informational purposes only and does not constitute investment advice.