A bitcoin hardware wallet exists so that no counterparty is required, and on July 31 one of them failed at the single job it cannot delegate - generating a secret that cannot be guessed. One arrangement named in public that evening arrived attached to a chartered trust bank.
The perimeter moved three times in fourteen hours
The first alert landed at 00:40 UTC: Coinkite warning that funds on Coldcard Mk3 devices running firmware 4.0.1 through 5.0.3 "may be at risk", with users urged to migrate to an unaffected model or set a BIP-39 passphrase immediately [1]. Nine minutes later the boundary was drawn tighter still - seeds generated on Mk3 from firmware 4.0.1 (March 2021) onward could expose funds if created without dice rolls or a BIP-39 passphrase, while "Mk4, Q, and Mk5 are unaffected, Coinkite said" [2].
That boundary did not survive the day. At 06:00 UTC, Block's Max Guise was reported as having traced the wallet drains to a random-number-generation flaw "affecting Mk2 through Mk5 devices" [3]. At 14:30 UTC an update carried Coldcard's own wording: an RNG flaw "may have weakened seeds generated on affected Mk3, Mk4, Mk5 and Q firmware" [4]. Inside fourteen hours the publicly named perimeter went from one model - with three others explicitly placed outside it - to a range, to four families that included all three of the previously excluded ones.
The loss attached to it: $38 million in bitcoin drained [5]. The attack path, as the maker described it, is the part likely to outlive the news cycle. Coinkite said it is likely an attacker used AI to review previous versions of its open-source firmware to uncover the vulnerability [5]. Open review is the standing argument for security hardware you can inspect; here the same archive was a corpus an adversary could read at machine speed.
The responses were about key architecture, not about price
Of the posts in this window from the analysts we track whose own text touches the exploit or its vocabulary, the answers arrived in three shapes: key architecture, custody arrangements, and an explicit refusal to price it.
The first was architectural. At 14:03 UTC one analyst posted "Never rely on a seed phrase" and described a combination of "seed phrase + passphrase or 25th key"; asked in replies what was safer, the answer was "Multisig + Seed + BIP39 Passphrase" [6]. That is not a claim about price. It is a claim about how many independent things an attacker has to obtain.
The second was custodial, and it arrived late - around 23:00 UTC, nearly a full day after the first alert. Ansem posted that he was moving funds to cold storage, and when a reply raised that cold storage gets hacked too, he answered that it was "with an insured hundred billion dollar custodian" [7]. Half an hour later he credited BitGo with the setup and pointed to its banking infrastructure and insured licensing, posting over a message from the firm's Mike Belshe which said the company "pioneered the self-custody multi-sig wallet precisely to avoid these types of failures" and offered either self custody or "full custody (at our US chartered national trust bank)" [8]. Asked whether his own arrangement was treasury multisig or self-custody, he answered "treasury multisig" [9].
That is the tell, and it is worth stating plainly: the answer put forward to a self-custody failure was not less bitcoin. It was more custody architecture - a second secret, a quorum of keys, or an institution with a bank charter standing behind the arrangement.
The charter language turned up in two different contexts that day. Circle won a limited-purpose trust charter from the New York Department of Financial Services for its trust-company entity, pairing with the federal OCC national trust bank approval secured earlier in the month, giving the issuer footing at both levels [10]. Two different problems - where a dollar token sits, and where a holder's coins sit after a key scare - reached for the same instrument on the same day.
The third shape was a refusal to price it at all
The tape did not treat any of this as an event. Reported Friday morning, spot bitcoin ETFs had logged $233 million of net inflows on Thursday and ether ETFs $13.3 million, with bitcoin at $64,274 and ether at $1,903 [11]. By mid-afternoon more than $113.5 million of crypto positions had been liquidated in an hour, with longs accounting for $106.8 million [12] - a move, but a leverage move, not a custody one.
Glassnode's options read that afternoon put numbers on the indifference: bitcoin "slipped back to $62.6K, unwinding much of July's rebound", call open interest rebuilt to roughly $23 billion against about $11 billion of puts for a put/call ratio near 0.5, one-week implied volatility near 34% against roughly 42% at six months, and total open interest back to about $34 billion from June's roughly $25 billion low. Their own word for the configuration was complacency [13]. More than $10.5 billion of bitcoin and ether options were set to expire on Deribit the following day [14].
And the refusal was explicit rather than inferred. Pentosh1, posting a chart thread at 15:55 UTC, wrote that "$sol is up 10% from its lowest weekly close over a month ago. $BTC is up 5-6%... $ETH is up 20%", that "there has been no reclaims, just underside retests", and called it "boring chop". Asked directly in a reply whether the wallet issue was bearish, he answered: "I don't care about the cold card issue a single percent lol" [15].
Where two lined up, and who took the other side
Two of the voices we track lined up on the chop rather than on the exploit. Pentosh1's own framing was that "downside is quite limited, but again, this next cycle upside is too" [15]. CredibleCrypto read the structure the same way, writing that "Bitcoin has begun to clean up some of those untapped lows below...still a few more to go" and that "I think we probs get more chop as we slowly take these over the coming days/weeks" [16].
The other reads ran in both directions. On the constructive side, Glassnode's on-chain note said "This bear market is 49% deep" and that "by depth, it is the mildest on record so far", with the same post adding that "by the clock it isn't finished: prior bear markets ran about 1/3 longer before reaching the lows" [17]. On the other side, veteran investor Michael Terpin said he is not convinced bitcoin has found its bottom [18], and Mayne posted "Similar thoughts for me" over a note from cburniske describing recent rebounds as "deadcats" and saying "the spell has been broken", with the expectation that crypto would "catch shrapnel early, but also bottom earlier than equities" [19].
One further juxtaposition, offered as exactly that. The same window carried a report that Ray Dalio said bitcoin still accounts for 1% of his portfolio while he prefers gold, citing risks from quantum computing, government monitoring and taxation [20]. The quantum argument is a claim about keys becoming guessable at some point in the future. July 31 was keys that were guessable already, for an entirely mundane reason, and the response on the price side was a shrug.
What would settle it
Three tests, each able to break this read on its own.
If the named perimeter stops moving and the drained total stops rising, the price side was simply right and this was a bounded firmware defect worth roughly zero basis points - the outcome Pentosh1 priced in advance [15].
If responses over the coming days keep arriving as custody arrangements rather than as changes in exposure, the shape holds: the industry's answer to a failure in trustlessness is more infrastructure, not less coin [6] [9] [8].
And if an AI-assisted review of old open-source firmware produces a second disclosure in a different device family, the method becomes the story rather than the device [5].








