These new events occurred just days after Coinkite reported that a long-undiscovered firmware vulnerability allowed attackers to recover weakly generated wallet seeds and systematically drain vulnerable single-signature wallets. According to statistics collected by the Coldcard Sweep Watch dashboard, the total loss amount has now grown to approximately 1,359.8820 $BTC, with the majority of the identified coins still residing on several addresses controlled by the attacker.
OP_RETURN Turns the Bitcoin Blockchain into a Public Bulletin Board
On August 1st, an unusual transaction containing an OP_RETURN message was sent to one of the attacker's storage addresses. OP_RETURN is a special output element of a Bitcoin transaction that stores permanent text on the blockchain, rather than transferring spendable funds.

The message openly advertised services for "laundering" Bitcoin, assisting with "Know Your Customer" (KYC) procedures, and cashing out stolen coins in exchange for a 10% fee, while also providing a Telegram contact. It was not a technical message or a plea to the victim. On the contrary, it appeared as a direct proposal addressed to the entity controlling the stolen Bitcoin. Some speculate it could be law enforcement or someone setting a trap.
Attack Leaves Most Stolen Bitcoin in Plain Sight
Although the theft resulted in over 1,300 $BTC being stolen, blockchain researchers noted that the majority of the Bitcoin remains largely untouched. The attacker consolidated the funds onto a relatively small number of addresses after draining vulnerable wallets in several coordinated attacks starting July 30th.
This visibility has become one of the most unusual aspects of this case. Bitcoin's transparent ledger allows anyone to track addresses holding large sums, meaning victims, investigators, researchers, and even speculators can all observe the same transaction developments in real-time. OP_RETURN messages demonstrate that the blockchain can also function as a permanent public messaging system during major incidents.
Several previously hacked projects have used OP_RETURN messages to discuss bounties and demands with hackers.
Emergency Firmware Update Creates New Issues
As users rushed to secure remaining funds, another problem emerged.
Coinkite released emergency firmware updates designed to patch the weak random number generation algorithm that caused the initial vulnerability. The company clearly stated that the new firmware only protects wallets created in the future and does not fix seeds already generated by vulnerable versions.

Shortly after the release, users began reporting that some devices froze on error screens, failed to boot, or appeared completely bricked after installing the update. Reports mainly concerned Mk4 and Q devices, though some Mk3 users also described similar issues. As of August 2nd, Coinkite has not publicly confirmed a widespread firmware defect, but several user reports have raised growing concern across the Bitcoin community.
Security Experts Urge Users to Move Funds First
One of the most persistent warnings circulating among seasoned Bitcoin security advocates is that owners of potentially vulnerable wallets should, if possible, move funds before applying the firmware update.
This advice reflects a crucial limitation of the emergency patch. Software updates cannot strengthen a weak seed created years ago. If the original wallet was generated with insufficient randomness, the only long-term solution is to move funds to a completely new wallet created with high entropy.
For many users, verified backups of seed phrases have become what separates hardware failure from irreversible fund loss, as a damaged device can often be replaced, and the recovery phrase allows access to funds to be restored.
Trust Faces Its Sternest Test
The ongoing Coldcard incident has evolved beyond a single firmware vulnerability into a broader test of trust in hardware wallet security. The combination of a historical entropy-related mistake, a public money laundering solicitation embedded directly in the Bitcoin blockchain, and reports that emergency updates may brick some devices has intensified the debate around wallet design, seed generation, and long-term self-custody practices.
While monitoring of the attacker's known addresses continues, users are now watching two events with equal scrutiny: whether the stolen Bitcoin will eventually move, and whether Coinkite will issue further guidance for customers experiencing firmware failures.








