ColdCard Hack Explained - First Self-Custody Breach at Scale, Strategy Makes First STRC Buyback, Fed's Most Hawkish Dissent in Decades
News Block #151 (08/03/2026)
Listen to the latest episode of the News Block below.👇
ColdCard Hack Explained - First Self-Custody Breach at Scale
Let’s start with the story the entire Bitcoin community is talking about right now — because it affects anyone who has ever used a Coldcard hardware wallet.
This past week, an attacker drained more than a thousand Bitcoin — worth tens of millions of dollars — from thousands of wallets that all had one thing in common: their recovery phrases were originally generated on a Coldcard device. The number is still growing as Galaxy Research continues tracking additional waves of the attack.
To be clear — in dollar terms, this is not the largest theft in Bitcoin’s history. Mt. Gox, Bitfinex, and FTX were all bigger. But those were exchanges — centralized platforms where someone else held your keys. This is the first time a major self-custody device has been compromised, at this scale, and that’s what makes it so alarming.
And this is important — it doesn’t matter if you later moved your Bitcoin to a different wallet or even a multisig setup. If the seed was originally created on an affected Coldcard, you could be at risk.
Here’s what happened.
When you set up a Coldcard, you can either let the device generate your recovery phrase for you or create your own using physical dice rolls. Most people take the simpler route and let the device handle it. That recovery phrase is supposed to come from a dedicated hardware random number generator, which produces what’s called entropy — essentially randomness so complex that guessing it is mathematically impossible.
But in March 2021, a code change in a firmware update switched that process. Instead of using the device’s dedicated hardware to generate your recovery phrase, affected Coldcards started using a much weaker method — one that produced recovery phrases that were far, far easier to guess. Think of it like the difference between a combination lock with a billion possible combinations and one with a few thousand. And nobody noticed — not Coinkite, not users, not reviewers — for more than five years.
Click on the video below from the Bitcoin Policy Institute. It explains the hack well:👇
Well, this week, someone figured it out. The attacker reconstructed private keys remotely — never touching a single physical device — and swept wallets clean across thousands of users. Galaxy Research reported that the initial wave drained over a thousand addresses in ~40 minutes, and that the number has increased to more than 1,500 BTC.
Coinkite has confirmed the flaw and published an advisory. It believes that the attacker may have used AI to find the flaw — and acknowledged their own AI review of the same code missed it entirely.
Alright, so I want to say something personally about this…
Coldcard has been a sponsor of this show in the past. I have used the product myself. And I want to be transparent about that, because I owe you that transparency.
I’m sorry. I promoted a product that failed the people who trusted it. When you produce free content, sponsorships are a part of how the work gets funded. I do the best I can to partner with companies I believe in and products I trust, but no product is infallible, and this situation is a painful reminder of that.
My heart goes out to everyone who was affected. Losing Bitcoin — especially from a device you trusted to keep it safe — is devastating.
As soon as this story broke, I recorded an emergency episode with Rob Hamilton from AnchorWatch to walk through what happened, what it means for self-custody, and what steps you should take right now. That episode has no sponsor and no ads — it’s just information. Please go listen to it.
If you own a Coldcard, check Coinkite’s advisory and take the steps recommended.
Self-custody remains the most important principle in Bitcoin, but this serves as a reminder to stay vigilant, diversify your security practices, and never assume any single device is beyond failure.
No one rings a bell when a bear market ends. But when companies are closing, weak hands are selling, and the people still holding are at record conviction — those are the clues.
The News Block is powered exclusively by Ledn.
Ledn is the global leader in Bitcoin-backed loans, issuing over $9 billion in loans since 2018, and was the first to offer proof of reserves. With Ledn, you get custody loans, no credit checks, no monthly payments, and more.
Visit LEDN.io to learn more.
Strategy Makes First STRC Buyback
Now, let’s turn to Strategy, because a significant shift happened this week.
During its Q2 earnings call, Strategy confirmed that it will no longer allocate 100% of future capital raises to Bitcoin purchases. Instead, proceeds will be split between buying Bitcoin and strengthening the company’s cash reserve — with the ratio depending on market conditions.
Saylor explained it this way: “If we sell $1 billion of credit, I don’t think you’ll see 100% BTC, zero USD as the norm. I think it’ll be a ratio.”
For a company that built its entire identity around buying Bitcoin with every dollar it could raise, this is a meaningful evolution. And it drew criticism from analysts who asked why Strategy would slow down its buying when Bitcoin is trading well below its all-time high.
But here’s the context. Strategy has not stopped buying. Over the first seven months of 2026, the company purchased nearly 175,000 Bitcoin and sold about 3,600 — meaning purchases exceeded sales by roughly 48 to 1.
This is not a retreat. It’s a company managing a much larger, more complex capital structure than it had when it started buying Bitcoin in 2020.
The company also made its first STRC buyback — repurchasing roughly $25 million worth of preferred shares at a discount to their $100 par value. CEO Phong Le said buying STRC below par reduces future dividend obligations, making it an attractive use of capital. And Strategy boosted its cash reserve to $3.75 billion — enough to cover more than two years of preferred dividends and interest payments.
The company also said it is not currently considering borrowing against its Bitcoin holdings, citing counterparty and margin risks. That alone should tell you something about how seriously they’re managing risk in this environment.
Fed’s Most Hawkish Dissent in Decades
And finally, the Fed.
The Federal Reserve held rates steady at 3.5 to 3.75% at its meeting this week. That was expected. What wasn’t expected was the dissent.
Three FOMC members — Beth Hammack, Neel Kashkari, and Lorie Logan — voted for a quarter-point rate hike. That’s the most divided FOMC vote since September 2016 and the clearest signal yet that parts of the Fed believe inflation still isn’t under control. Inflation has now been above the Fed’s 2% target for more than five consecutive years.
Long-term Treasury yields moved higher on the news. The 10-year yield just hit roughly 4.7%, and the 30-year yield recently jumped to around 5.3%.
For Bitcoin, this is a headwind. Higher rates mean tighter financial conditions, which typically weigh on risk assets. And with the Fed now openly debating hikes — not cuts — the liquidity tailwind Bitcoin bulls have been hoping for isn’t arriving anytime soon.
But here’s the longer view. The fiscal math hasn’t changed. The U.S. is running structural deficits. The debt keeps growing. Public debt is approaching $40 trillion!
Eventually, the Fed will have to accommodate that reality — whether it wants to or not. It’s just math.
The question is timing, not direction.
Until next week, keep stacking.
- Nat
PS - Make sure to grab a copy of my new book, “Bitcoin is for Everyone.” I’ve written an approachable book on Bitcoin and the traditional financial system, perfect for your friends and family who are still learning about it.
If you enjoyed reading this post, you should consider subscribing to the News Block.
NEW: What Every Bitcoin Self-Custody Holder Needs to Do Right Now After ColdCard Bug Discovered
In this urgent PSA episode of Coin Stories, recorded as the ColdCard hack unfolded, Natalie Brunell sat down with Rob Hamilton, co-founder and CEO of AnchorWatch and one of the first people to analyze the ColdCard seed attack on-chain.
Note: this show is not sponsored by AnchorWatch.
We cover:
How ColdCard devices could end up with seed phrases that were guessable — terms like entropy explained simply
The one thing most people do first that doesn’t actually help: moving your seed to a different brand of device
Whether your Bitcoin is at risk, and how to tell in a few minutes
Exactly what to do, step by step — including the test transaction people skip when they’re panicking
Follow Rob Hamilton - his DMs are open.










