A Coldcard hardware-wallet exploit is pushing bitcoin holders back toward centralized exchanges, OKX's chief compliance officer says, describing record inflows in the exploit's wake. Loss estimates tied to the flaw have climbed across multiple reports, and Coinkite has urged affected users to move their funds immediately.
According to The Block: "We're seeing record levels of inflows now to centralized exchanges post-Coldcard," OKX Chief Compliance Officer Jonathan Brockmeier told the outlet, describing a shift away from the self-custody enabled by devices like the Coldcard hardware wallet. He called it the flip side of FTX: after that exchange's collapse pushed users into self-custody, the Coldcard exploit is now sending some of that money back.
Galaxy Research linked the vulnerability to the theft of more than 1,300 bitcoin worth over $80 million from thousands of addresses across multiple waves.
OKX steps up its fraud defenses
OKX said it prevented $26.3 million in scam-related losses during the first half of 2026 by stopping suspicious transfers, and it protected more than $1.1 billion in assets belonging to over half a million customers over the same period. Brockmeier said the exchange also uses artificial intelligence to monitor broader network activity for compromised devices and social-engineering patterns that could signal fraud before funds move.
Loss estimates keep climbing
CryptoPotato reported that Galaxy Research's latest estimate puts the confirmed amount stolen at over $100 million, with some reports suggesting the figure could reach around $130 million. Coinkite's Coldcard account told users to treat the situation as urgent, upgrade their devices, generate a new seed, and move their funds. Market commentator Joe Consorti has argued the attacker may struggle to spend a large portion of the stolen bitcoin, since every coin is tracked on the public blockchain.
A years-old firmware flaw
Crypto Briefing traced the bug to firmware Coinkite introduced in March 2021, which weakened the randomness used to generate seed phrases on affected devices by redirecting generation to a software-based pseudorandom number generator instead of drawing from a robust source of entropy. The first major attack wave hit on July 30, 2026, draining about 594 BTC worth around $38 million from about 500 addresses in roughly 25 minutes. Galaxy Research has since identified at least three separate waves, with total losses climbing to 1,816 BTC valued between $114 million and $116 million across more than 5,200 addresses, concentrated almost entirely on single-signature wallets rather than multi-signature setups.
An opening for ETFs
Crypto Briefing argues the breach of a device from a well-regarded name in Bitcoin security culture could accelerate migration toward spot Bitcoin ETFs and institutional custodians as an alternative to self-custody. OKX's Brockmeier framed the moment differently, citing his own centralized exchange's record inflow figures as evidence some holders are already making that switch.
Sources: The Block, CryptoPotato, Crypto Briefing
Trading involves risk.