BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

After $89M Coldcard hack, Bitcoin breaks from the FTX pattern

The lesson from the FTX fiasco in November 2022 was simple and brutal. Keep your Bitcoin on an exchange and you can lose everything when the exchange fails. Move it to a hardware wallet and o

AnonymousCryptoCompass newsroom
August 3, 2026
2 min read
NEWS
After $89M Coldcard hack, Bitcoin breaks from the FTX pattern
CryptoCompass editorial visual for policy coverage.

The lesson from the FTX fiasco in November 2022 was simple and brutal. Keep your Bitcoin on an exchange and you can lose everything when the exchange fails. Move it to a hardware wallet and only you control it.

Sales of Coldcard devices, made by Canadian firm Coinkite, surged in the weeks after FTX's collapse. The phrase "not your keys, not your coins" became the most repeated line in Bitcoin.

Three and a half years later, on-chain data from CryptoQuant shows the biggest sub-1 BTC movement back to exchanges since that FTX panic.

The flow is running in reverse. People are sending their Bitcoin back to the platforms they left in 2022.

The Coldcard hack did that.

Related: Update: Coldcard hack just grew to $89M, call your friends

What the numbers say

Between July 30 and Aug. 1, an attacker drained 1,367 BTC worth approximately $89 million from 4,585 addresses across three separate waves.

The vulnerability was a five-year-old firmware bug from a March 2021 update that silently routed seed generation through a weak deterministic fallback rather than the device's hardware random number generator. 

That cut possible seed values from an astronomically large number down to roughly 4 billion, small enough to reproduce from publicly available data like device serial numbers and clock readings.

The attacker never touched a single device. They did it remotely in three sessions. The first wave alone, 25 minutes on the night of July 30, drained over 1,082 BTC from 1,196 addresses.

Two lessons fighting each other

Casa CEO Nick Neuman made a point worth sitting with. He estimated that 10 times more Bitcoin was protected through self-custody than was stolen in this attack.

The Coldcard hack is a Coldcard failure, not a self-custody failure, those are different arguments.

Bloomberg's Eric Balchunas landed on the other side. His take was direct, for investors who just want price exposure and do not need to actually move Bitcoin around, an ETF, where Coinbase Custody holds keys in segregated cold storage under regulatory oversight, removes every risk this hack represents.

Both arguments are correct for different people. That is the uncomfortable part.

Related: Bitcoin has never broken this line in 15 years, it is on it right now