Issue #005 · Week of August 02, 2026
This Week’s Verdict
The safest wallet in Bitcoin turned out to have shipped with a broken random number generator in March 2021, and it took five years and 41 minutes for someone to collect. The lesson is not that self-custody is dead; it is that “air-gapped” means nothing when the entropy was compromised before the device ever touched your desk. Everything else this week (Iran’s $4 billion laundry, a supply-chain clipboard swap, another DeFi oracle shortfall) was already priced into the threat model. Coldcard just made people read it.
The Breaches
The week belongs to Coldcard. On July 30 an attacker swept 1,196 Bitcoin addresses in 41 minutes, taking roughly 1,082 BTC worth about $70 million at the time, per Galaxy Research; CoinDesk and others put the running total near $89 million as the sweep expanded to some 4,500 addresses. The root cause is not glamorous: a March 2021 firmware integration error routed seed generation on the Coldcard MK3 to a deterministic software PRNG, producing low-entropy keys that were trivially guessable. The device was never touched. The seeds were doomed the day they were generated. CryptoQuant flagged the aftermath as the largest sub-1 BTC movement since FTX, as spooked holders shuffled coins in a hurry. Do not expect recovery; the stolen BTC is already a candidate for Monero and L-BTC laundering paths.
Separately, MetronomeDAO disclosed a $15.7 million synth shortfall (6,367 msETH and 4.57 million msUSD unbacked), blaming years of accumulated “unbacked float” from Chainlink price-feed latency in its swap module. The treasury staged $34 million in defensive positions to close the gap. Oracle lag is not a hack, but it drains just the same.
Vulnerabilities Worth Your Attention
- Coldcard MK3 low-entropy seeds: If you generated a seed on an affected MK3, the device is compromised as a generator. Regenerate entropy elsewhere (Sparrow, Electrum, dice) and load it on. The hardware still signs fine; it just cannot be trusted to roll the dice.
- Adform supply-chain clipboard swap: Attackers poisoned a JavaScript file served by ad-tech firm Adform, rewriting copied crypto wallet addresses client-side. Detected July 27, removed, and reported. Anyone who copied a Bitcoin address on an affected site that day should verify where their funds actually went.
- Rails Active Storage RCE: A critical flaw lets an unauthenticated attacker read arbitrary files from a Rails app, with escalation to remote code execution. Patch it; exchanges and custodians run more Rails than they admit.
- Adobe Campaign Classic (CVE-2026-48449, CVSS 10.0): Incorrect authorization enabling arbitrary code execution without user interaction. Maximum severity, minimal excuse.
Threat Actors & Campaigns
No confirmed attribution on the Coldcard sweep yet, though the speed and the immediate pivot toward privacy-chain laundering suggest a prepared, professional operation rather than an opportunist. Predictably, the timeline is already spawning conspiracy theories about the vendor; ignore them until someone shows the block explorer.
The state-actor side stayed busy. Reuters, via The Block, detailed Dubai-based Shelbit moving over $4 billion since May 2024 through a network tied to Iranian gambling sites, the central bank, and the IRGC, including $676 million to Binance in an alleged sanctions-evasion operation. Separately, OFAC sanctioned two Iranian firms, including Hormuz Safe, for accepting Bitcoin as payment for Strait of Hormuz passage. Elsewhere, Storm-2945 (an operational sub-cluster of Midnight Blizzard) ran the CaptiveCrunch campaign, pushing fake browser updates over hijacked hotel Wi-Fi to deliver the CornFlake RAT. The AI-assisted attack trend also matured: a Chinese-speaking actor wired DeepSeek to the open-source Hermes Agent for autonomous attacks on exposed servers, and ESET logged a broader rise in AI-assisted malware.
The Bigger Picture
The Coldcard fallout has a market signature: CoinDesk notes investors are sending BTC back to exchanges, and the incident is being framed as a possible tailwind for ETFs. That is the quiet story. Every self-custody catastrophe is a custody-product marketing budget. Spot Bitcoin ETFs closed July with $172.4 million in inflows but remain $5.3 billion negative year to date, so the funnel is real but not yet a flood.
Macro stayed heavy. Bitcoin slipped to two-week lows as the Fed’s fifth straight hold and 3.7% PCE shut the door on near-term cuts, and the BoJ intervened to defend the yen near 160. Tether posted a $1.5 billion Q2 operating profit even as its excess reserve buffer fell by more than $4 billion. Coinbase missed on Q2 and split Wall Street, while Base sequencer revenue fell despite record volume, a reminder that L2 throughput and L2 profit are different columns.
On the regulatory board, Circle stacked a NYDFS trust charter on top of its federal OCC approval, tightening USDC’s oversight footprint. Minnesota’s crypto ATM ban took effect after roughly $1 million in reported kiosk scam losses, largely from seniors. And the Bank of Italy poured cold water on the stablecoin remittance narrative, finding fiat conversion and payment infrastructure, not blockchain fees, drive most cost and settlement differences. The rails are still the rails, even when you tokenize them.
By the time it is news, it is already priced in. The Coldcard seeds were priced in five years ago. The rest of us just found out this week.
Resources
- https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html
- https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million
- https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices
- Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked
Related
- Multisig and Threshold Signing, Beyond Buying a Safe
- Issue #002 — Week of July 12, 2026
- Seed Phrases and Where Keys Actually Leak
More: Issues · Field Notes · RTFM
New Issue every week. Follow @ItsAlreadyPrice or subscribe via RSS so the next exploit does not surprise you.