Two Forks and a Security Flaw: Bitcoin Enters a Turbulent Zone

By: rootdata|2026/08/02 07:15:00

Cold storage, long touted as the ultimate defense against hacking, has just suffered one of its most significant setbacks. A critical software vulnerability affecting Coldcard wallets has allowed the theft of tens of millions of dollars in bitcoin, reigniting questions about the limits of self-custody. This incident comes as the market emerges from a July that saw a 7.36% increase, under pressure from massive institutional withdrawals and with two major protocol developments expected in August.

In Brief

  • A 5-year-old security flaw enabled the siphoning of 1,082.65 BTC (~$70 million) from 1,196 addresses in just 41 minutes.
  • Updating the Coinkite firmware is not enough. Affected users must generate a new recovery phrase and migrate their funds.
  • The founder of Binance recommends diversifying physical wallets while reminding that no storage tool is 100% foolproof.
  • The market is set to face two key deadlines: the miners' vote on the BIP-110 soft fork (August 7) and the potential split towards eCash (August 21).

A Coordinated Attack Targeting a Five-Year Vulnerability

On July 30, as the crypto market entered an unprecedented consolidation phase, the self-custody ecosystem was hit by a malicious operation. A critical vulnerability located in the pseudo-random entropy generator of the Coldcard hardware wallet firmware, particularly in the Mk3 models whose code dates back to March 2021, was exploited on a large scale. The factual elements of this attack are as follows:

  • The stolen volume: siphoning of 1,082.65 BTC from 1,196 distinct addresses according to Galaxy Research's analysis;
  • The execution speed: the entire diversion took place in just 41 minutes;
  • An on-chain footprint: the use of fixed fees of 30 sat/vB without a change address, targeting exclusively single-signature wallets;
  • The technical origin: the flaw allowed for offline reconstruction of private keys from the component's serial number and predictable timestamp data.

In light of the magnitude of the revelations and the increasing number of suspicious transfers to exchange platforms, the publisher Coinkite urgently deployed a software patch to fix the firmware of its devices. However, the company issued a strict warning to its users, emphasizing that a simple firmware update is completely ineffective in sanitizing a recovery phrase created before the patch.

Indeed, once a mnemonic phrase has been generated by a faulty algorithm, its structure remains readable and vulnerable regardless of the subsequent state of the hardware. Technical teams therefore instruct affected users to generate an entirely new mnemonic sequence on a previously updated device, and then to perform a full transfer of their assets to these new addresses, implementing the only operational measure that can definitively neutralize the risk of theft.

Changpeng Zhao's Warning and the Redesign of Bitcoin Storage Strategies

This vulnerability has quickly prompted reactions from major figures in the crypto industry, starting with Binance founder Changpeng Zhao (CZ). Speaking on the social network X to comment on this significant incident, the former executive called for a deep reevaluation of storage methods. He stated: "Even hardware wallets can have bugs. Even older wallets (that have been used for a long time) are not immune. How can we reduce risks? Perhaps by spreading your funds across multiple wallets? This involves another set of risks. Nothing is 100% safe. Stay informed, stay secure!".

This intervention brings back to the forefront discussions about the strategy of diversifying hardware supports, encouraging capital holders to distribute their assets among various manufacturers and distinct architectures. While this approach allows for fragmenting exposure to software risks from a single manufacturer, it conversely introduces increased complexity in the operational management of keys and enhances interest in complex multi-signature structures combined with physically generated entropy.

The discovery of these structural flaws forces both individual and institutional investors to rethink the architecture of their storage systems. Thus, the use of single-signature wallets now appears as a major vulnerability in the event of a failure from a single manufacturer. The industry is gradually moving towards the generalization of multi-signature configurations that combine devices from different brands, thereby reducing the risk of a single point of failure. Moreover, procedures for generating entropy based on physical draws (such as dice rolls) are emerging as an essential best practice to circumvent potential future algorithmic biases in firmware.

Institutional Withdrawals and Price Compression

This crisis of confidence regarding storage comes in a market context already weakened by deteriorating financial indicators. The price of Bitcoin fluctuates in an area of uncertainty between $62,300 and $63,100, testing the critical support of $62,000 while the Crypto Fear and Greed Index sinks into the "fear" zone at 27 points. This weakness is exacerbated by net outflows of $265 million recorded on July 31 from U.S. Spot ETFs, driven by disengagement movements from BlackRock's IBIT funds, Fidelity's FBTC, and Grayscale's GBTC, even as open interest in derivatives remains stable around $48 billion.

At the same time, two distinct events are polarizing investor attention for this August. On one hand, the start of reporting by mining companies is expected around August 7 (near block 961,632) for the soft fork BIP-110 aimed at restricting non-financial data recorded on the chain. The lack of massive support from mining players raises fears of chain split risks. On the other hand, preparations for a hard fork initiated by Paul Sztorc around August 21 to create the eCash chain, a mirror network allocating new tokens to Bitcoin holders subject to the support of centralized platforms and custodians.

The intertwining of a major hardware vulnerability and contested technical deadlines marks a critical turning point for the maturity of the Bitcoin network. In the short term, the market's ability to absorb the repercussions of this exploit will depend on the speed with which investors secure their keys and the potential return of institutional buying flows into ETFs.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com