Crypto World
how a build flag drained 116M in bitcoin
A single line of firmware shipped in March 2021 told every Coldcard hardware wallet to skip its dedicated randomness chip. For five years nobody noticed. Then an attacker brute-forced the weak seeds in 41 minutes, draining 1,816 BTC from more than 5,200 addresses across four attack waves. The incident is the largest hardware wallet exploit in crypto history, and it is forcing the entire bitcoin self-custody model to answer a question it has avoided since inception: who audits the code that generates your keys?
Summary
- A build configuration error in Coldcard firmware version 4.0.1, shipped in March 2021, routed seed generation to a deterministic software pseudorandom number generator instead of the device’s STM32 hardware random number generator, reducing effective entropy from 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4, Mk5, and Q models.
- An attacker began sweeping wallets on July 30, 2026, draining 1,082 BTC from 1,196 addresses in 41 minutes during the first wave, with Galaxy Research tracking total confirmed losses of 1,596 BTC across three waves and estimating the figure could reach 2,055 BTC (approximately $130 million) if a suspected fourth wave is verified.
- Coinkite released emergency firmware on July 31 but confirmed that updating does not repair seeds already generated on vulnerable firmware, meaning every affected user must generate a new seed and manually migrate funds to survive.
- The net transfer of bitcoin from self-custody wallets to exchange addresses has been positive every day since July 31, reversing a two-year outflow trend that began after the FTX collapse, with OKX reporting record exchange inflows in the days following the exploit.
- TRM Labs classified the incident as the third-largest crypto hack of 2026, bringing the year’s total past $1.2 billion across 276 incidents, while roughly 90% of stolen bitcoin remains unmoved at attacker-controlled addresses.
Nobody was phished. No device was stolen. No seed phrase was written on a sticky note. The Coldcard hardware wallet, the device that bitcoin maximalists recommended above all others for cold storage, generated weak private keys for five years because a single build flag told the firmware to skip its dedicated randomness chip. An attacker figured out how to guess the resulting seeds, and on July 30, 2026, began emptying wallets at a pace that left no time to react.
“Perhaps the hardest part about this is that I did everything right,” Canadian entrepreneur Jonathan Goodman wrote on X after losing 18.25 BTC, worth approximately C$1.6 million, from a Coldcard stored in a safety deposit box. His post has been viewed more than 7.6 million times. The sentiment captures the core of the crisis: the people who lost money were not careless. They were the most security-conscious bitcoin holders in the ecosystem, and they followed every recommended practice except one they could not have known about. The firmware that generated their keys was broken from the day it shipped.
The fallout extends far beyond the immediate losses. Bitcoin is flowing back to exchanges for the first time since FTX collapsed. Hardware wallet manufacturers face calls for independent audits of their seed generation code. ARK Invest’s director of digital asset research called the self-custodial hardware space “a disaster.” And Coinkite’s CEO suggested that artificial intelligence found the bug, raising the question of whether every open-source firmware repository is now an attack surface that AI can mine faster than human reviewers can defend.
The build flag: how one line of code broke everything
The technical failure is simple enough to explain in a single paragraph, which makes it more damaging, not less. Coldcard’s firmware defines a macro called MICROPY_HW_ENABLE_RNG and sets it to zero because Coinkite supplies its own hardware random number generator wrapper. A supporting cryptographic library called libngu checked whether the macro existed. It did not check whether the macro was enabled. Because the macro existed but was set to zero, libngu concluded that hardware randomness was unavailable and fell through to MicroPython’s Yasmarang software fallback. That fallback was initialized from the chip’s unique serial number and timer registers and collected no fresh entropy after initialization.
The consequence was a catastrophic reduction in key strength. A 12-word BIP-39 seed phrase is designed to encode 128 bits of entropy, a number so large that brute-forcing it would require more energy than the sun will produce in its lifetime. The Yasmarang fallback, seeded from a chip serial number and timer state, produced approximately 40 bits of effective entropy on the Mk3 and roughly 72 bits on the Mk4, Mk5, and Q. Block’s security research team, which published a detailed technical analysis, set conditional ceilings below 2^40.7 and 2^73.3 and warned that the latter figure is not equivalent to 73-bit cryptographic security.
Forty bits of entropy means approximately one trillion possible seeds. That is a large number by human intuition but a trivial number by computational standards. A modern GPU cluster can enumerate one trillion candidates in hours. The attacker did not need physical access to any device. The attacker did not need to intercept any communication. The attacker needed only to generate candidate seeds, derive their corresponding bitcoin addresses, and compare those addresses against the public blockchain. Every match was a wallet that could be emptied.
The flaw shipped in firmware version 4.0.1 in March 2021. It persisted through every subsequent firmware release until the emergency patch on July 31, 2026. Every Coldcard seed generated during that five-year window without the manual dice-roll option is potentially compromised. Coinkite estimates that the dice-roll option, where users physically roll dice at least 50 times and type in the results, bypasses the broken code entirely. The company also says a strong BIP-39 passphrase creates a separate wallet the seed words alone cannot reach. But as Casa CEO Nick Neuman pointed out: “You just cannot ask people to roll dice to be secure with your self-custody. It is a non-starter for 99% of people.”
The four waves: anatomy of a $116 million sweep
The attack unfolded in distinct waves, each larger than the last, suggesting either a single operator refining their approach or multiple attackers working from the same vulnerability.
Wave one hit on July 30 at approximately 2:14 a.m. UTC. The attacker swept 594 BTC from roughly 500 addresses in 25 minutes, broadcasting transactions at a uniform 30 sat/vB fee rate with no change outputs. Galaxy Research noted that no other bitcoin transactions in the previous 30 days carried the same fee-rate-plus-no-change signature, making the operator identifiable even though they remained anonymous.
Wave two followed within 48 hours, lifting the cumulative total to 1,082 BTC from 1,196 addresses. The transaction construction matched Wave one closely enough for Galaxy to assess with high confidence that the same operator was responsible.
Wave three brought the confirmed total to 1,367 BTC from 4,585 addresses, worth approximately $89 million. Galaxy cautioned that Wave three should not be assumed to involve the same attacker, as the transaction patterns diverged from the first two waves. TRM Labs independently identified differences in transaction construction across waves that hint at multiple operators.
A suspected fourth wave ran throughout August 4, sweeping roughly 449 BTC from 709 addresses on Galaxy’s revised count. If confirmed, cumulative losses reach approximately 2,055 BTC, worth close to $130 million. Galaxy has reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms, and cybersecurity investigators.
The laundering has been minimal. TRM Labs found that most victim funds are pooling at a small number of attacker-controlled addresses with limited onward movement. As of August 4, the only confirmed laundering consisted of a single 64.9 BTC deposit to Wasabi Wallet’s coinjoin service and 200 ETH deposited to Tornado Cash. One opportunist posted an OP_RETURN message on the bitcoin blockchain offering to launder the stolen funds for a 7% fee. The relative inaction suggests the attackers have not yet determined how to move a sum large enough to attract attention wherever it lands.
The section a competitor could not write: what 40 bits of entropy actually means
Most coverage of the Coldcard hack describes the entropy reduction as a technical detail. It is the entire story, and the arithmetic reveals why the attack was inevitable rather than merely possible.
A 128-bit seed has 2^128 possible values, a number with 39 digits. Brute-forcing that space is not a matter of computing power or patience. It is physically impossible with any technology that obeys the laws of thermodynamics. This is why hardware wallets work at all: the security of a properly generated seed does not depend on the device remaining secret, the firmware remaining uncompromised, or the manufacturer remaining trustworthy. It depends on mathematics.
A 40-bit seed has 2^40 possible values: 1,099,511,627,776. One trillion. A single NVIDIA H100 GPU can compute roughly 10 billion SHA-256 hashes per second. Deriving a bitcoin address from a candidate seed requires several cryptographic operations beyond a single hash, but the order of magnitude holds. One trillion candidates can be exhausted in minutes to hours on a GPU cluster that costs a few thousand dollars to rent.
The Mk4, Mk5, and Q devices had roughly 72 bits of effective entropy. That is better than 40 bits but still catastrophically below 128 bits. Block’s analysis set the search space at approximately four billion possibilities under certain constraints, a number that runs on ordinary hardware. The distinction matters: Mk3 owners face near-certain compromise if their addresses are identified, while later-model owners face a probabilistic threat that depends on how much the attacker knows about their device’s unique ID, boot timing, and prior random number generator calls.
The critical insight is that the attacker does not need to know which addresses belong to Coldcard users. Every bitcoin address is public. The attacker generates candidate seeds, derives addresses, and checks them against the entire blockchain. Any match is a confirmed Coldcard wallet with a weak seed. The attack scales linearly with computing power and requires no intelligence about individual victims. Galaxy Research warned that “every vulnerable device will eventually be emptied” because the attacker can work through the entire search space at leisure.
This is fundamentally different from a phishing attack, an exchange hack, or a supply chain compromise. Those attacks require targeting specific victims. The Coldcard exploit targets mathematics. Every wallet generated on affected firmware is vulnerable regardless of how carefully the owner stored the device, protected the seed phrase, or followed security best practices. The only defense was an action the manufacturer never told users they needed to take: rolling physical dice.
The self-custody reversal: bitcoin flows back to exchanges
The Coldcard exploit is producing a behavioral shift that would have been unthinkable 18 months ago. Bitcoin is moving from self-custody wallets back to centralized exchanges, reversing a trend that began when FTX collapsed in November 2022 and accelerated through 2023 and 2024 as hardware wallet sales surged.
The net transfer of bitcoin from self-custody wallets to exchange addresses has been positive every day since July 31, according to on-chain flow data. OKX reported record exchange inflows in the days following the exploit. The exchange’s chief compliance officer Jonathan Brockmeier said customer behavior changed “noticeably” as users moved assets away from self-custody.
The flow reversal is not limited to panicking retail holders. Institutional allocators who previously cited self-custody as a risk-management advantage are reassessing. Bitcoin ETF inflows reached $211.5 million on August 5, led by BlackRock’s IBIT and Fidelity’s FBTC, suggesting that at least some capital is rotating from direct bitcoin holdings into regulated wrappers that eliminate seed-management risk entirely.
Bloomberg senior ETF analyst Eric Balchunas argued that spot bitcoin ETFs remove the seed-management problem for investors who want price exposure without operational risk. “An ETF fixes this,” he wrote. On-chain analyst Willy Woo pushed back, arguing that self-custody remains the only path to genuinely sovereign bitcoin ownership and that ETF wrappers introduce counterparty risk that the bitcoin network was designed to eliminate.
The data tells a more specific story than either side acknowledges. The addresses moving bitcoin back to exchanges skew toward single-signature wallets holding between 0.5 and 10 BTC, the range most likely to represent individual holders who used a single Coldcard as their primary storage. Multisignature wallets and addresses associated with institutional custodians have shown no comparable movement. The panic is concentrated among the exact user profile the Coldcard was designed for: technically literate individuals who chose self-custody over exchanges and relied on a single hardware device as their sole security layer. The irony is precise. The users who trusted the hardware most are the ones most exposed, while users who distributed trust across multiple devices and key generation methods are unaffected.
The tension is real but the framing is incomplete. The Coldcard hack did not expose a flaw in self-custody as a concept. It exposed a flaw in one manufacturer’s implementation of seed generation. Vincent Bouzon, a cybersecurity expert at Ledger, drew the distinction explicitly: “Every wallet ultimately depends on a root secret generated from high-quality entropy. That generation must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.” He called the alternatives worse, describing software wallets on non-secure hardware as riskier and centralized exchange custody as “not ownership, it is an IOU.”
The AI question: did a model find this bug?
Coinkite’s response to the exploit included a claim that has divided the security community. CEO Rodolfo Novak, known as NVK, suggested that the attacker used AI to discover the firmware flaw, and that Coinkite’s own AI-assisted code review of the same repository weeks earlier had found nothing.
“To every other developer: we believe this is a sober reality of the new AI paradigm,” Novak wrote. “AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts.” He added: “If your firmware is open-source or has ever been public, assume it is already being read by attackers and defenders alike.”
Security researchers have pushed back on this framing. A build flag that disables a hardware random number generator is a human engineering error, they argue, and conventional code review should have caught it years before any language model read the repository. Andrew Lazutkin, chief technology officer at Tangem, drew a different conclusion: “This incident is a good example of why open-source firmware should not automatically be equated with better security.”
The AI attribution matters less than the structural question it raises. Whether the attacker used AI, conventional static analysis, or manual review, the result is the same: a bug that sat in plain sight for five years in an open-source repository was found and weaponized. If AI tools can systematically scan firmware repositories for entropy flaws, randomness downgrade paths, and build configuration errors, then every hardware wallet manufacturer with public code faces an expanded attack surface. The question is not whether AI was involved in this specific attack. The question is whether AI makes this class of attack reproducible at scale.
The timeline supports the concern regardless of the mechanism. Coldcard’s firmware has been open source since its inception. The MICROPY_HW_ENABLE_RNG macro and its zero assignment were visible in a public GitHub repository for five years. Multiple security researchers, firmware auditors, and the broader Bitcoin development community had access to the code throughout that period. None of them caught the flaw. The Coinspect research group published its Ill Bloom findings on weak PRNG flaws in older software wallets in early July 2026, a separate but thematically identical vulnerability that drained more than $5 million from addresses across Bitcoin, Ethereum, Tron, Rootstock, and Polygon. The clustering of entropy-related exploits within a single month suggests either coordinated research or a shared analytical approach that is surfacing this class of bug faster than it has been found historically.
The opposing case at full strength
The narrative writes itself: self-custody is broken, hardware wallets cannot be trusted, move your bitcoin to an exchange or an ETF. The opposing case requires examining what the Coldcard hack actually proved and what it did not.
First, this was not a failure of self-custody. It was a failure of one company’s firmware engineering. The bitcoin protocol worked exactly as designed. The cryptography worked exactly as designed. The vulnerability existed in Coinkite’s build configuration, not in the security model of hardware wallets as a category. Ledger, Trezor, and Block have confirmed their devices are unaffected. The lesson is that seed generation must be verified independently, not that seed generation is inherently unreliable.
Second, the exchange alternative carries its own catastrophic risks. FTX lost $8 billion in customer funds. Mt. Gox lost 850,000 BTC. Celsius, Voyager, and BlockFi collectively lost billions more. The Coldcard exploit drained $116 million across 5,200 addresses over five days. FTX drained $8 billion from millions of users in a single night. The scale comparison favors self-custody even in its worst failure mode.
Third, multisignature configurations would have prevented every theft in this exploit. A multisig wallet requires multiple independent keys to authorize a transaction. If even one key was generated on a non-Coldcard device, the attacker could not have completed the sweep. Casa, Unchained, and other multisig providers have reported zero customer losses from the Coldcard exploit because their architectures distribute key generation across independently designed devices from different manufacturers. A 2-of-3 multisig wallet using one Coldcard, one Ledger, and one Trezor would have been immune to this attack even if the Coldcard key was fully compromised, because the attacker would still need to independently compromise one of the other two keys. The Coldcard hack is an argument for multisig, not an argument against self-custody.
Fourth, the bitcoin price reaction undermines the catastrophic framing. Bitcoin traded near $64,300 through all four attack waves and has not broken below $63,800 since the exploit became public. The market is pricing the Coldcard hack as a company-specific event, not a systemic threat to bitcoin’s security model. If the market believed self-custody was fundamentally broken, the price response would have been severe. It was not.
What would invalidate the self-custody thesis: if multiple hardware wallet manufacturers were found to have the same class of entropy flaw simultaneously, suggesting a systemic rather than idiosyncratic failure. If the attack surface expands to include devices with hardware random number generators that pass all existing tests but contain subtle biases. Or if the operational burden of key management proves permanently beyond the capacity of individual users, making professional custody the only viable option for most bitcoin holders regardless of the theoretical security advantages of self-custody.
What to watch
- Galaxy Research’s final loss tally after Wave four confirmation. The gap between 1,596 BTC (confirmed) and 2,055 BTC (estimated) represents roughly $30 million in unverified losses. If the fourth wave is confirmed and additional waves follow, the total could exceed $150 million and push the incident past Bybit’s 2025 blind-signing exploit in impact.
- On-chain movement of attacker-controlled bitcoin. Roughly 90% of stolen funds remain unmoved. When the attacker begins laundering, the chosen method (mixing, cross-chain bridges, OTC desks) will indicate sophistication level and potentially enable attribution. TRM Labs is monitoring in real time.
- Exchange inflow trends over the next 30 days. The post-Coldcard flow reversal could be a temporary panic response or the beginning of a structural shift. If net flows back to exchanges persist beyond August, it suggests a durable change in how bitcoin holders weigh self-custody risk against counterparty risk.
- Independent audit adoption by hardware wallet manufacturers. Kraken CSO Nick Percoco called for independent testing of seed generation in production firmware. If Ledger, Trezor, and other manufacturers adopt third-party entropy audits as standard practice, it validates the systemic concern. If they do not, the industry is betting the same class of bug will not appear elsewhere.
- Regulatory response to the self-custody failure. The SEC and CFTC have not commented on the Coldcard exploit. If regulators use the incident to argue that self-custody is unsuitable for retail investors, it could accelerate the push toward mandatory custodial frameworks for digital assets.
Frequently asked questions
What is the Coldcard hardware wallet hack?
The Coldcard hack refers to a series of bitcoin thefts beginning July 30, 2026, in which an attacker exploited a firmware flaw in Coinkite’s Coldcard hardware wallet to brute-force weakly generated seed phrases and drain funds from more than 5,200 addresses without physical access to any device.
How much bitcoin was stolen in the Coldcard exploit?
Galaxy Research has confirmed 1,596 BTC stolen across three attack waves, with a suspected fourth wave that could bring the total to approximately 2,055 BTC, worth close to $130 million. TRM Labs estimated confirmed losses at 1,816 BTC, approximately $116 million.
What caused the Coldcard vulnerability?
A build configuration error in firmware version 4.0.1, shipped March 2021, set a macro called MICROPY_HW_ENABLE_RNG to zero. A supporting library checked whether the macro existed rather than whether it was enabled, causing seed generation to fall back on a weak software random number generator instead of the device’s hardware entropy source.
Does updating Coldcard firmware fix the problem?
No. Updating firmware prevents new wallets from being generated with weak randomness, but it does not repair a seed that was already generated on vulnerable firmware. Affected users must generate a new seed on patched firmware, verify the new wallet, and manually migrate their funds.
Which Coldcard models are affected?
All current models are affected to varying degrees. Mk3 devices on firmware 4.0.1 through 4.1.9 had entropy reduced to approximately 40 bits. Mk4 and Mk5 devices on firmware below 5.6.0 and Q devices on firmware below 1.5.0Q had entropy reduced to approximately 72 bits. Wallets created using the dice-roll option are considered safe.
Are other hardware wallets affected?
No. Block, Trezor, and Ledger have confirmed their devices use independent random number generation implementations and are not affected by the Coldcard-specific firmware flaw. The vulnerability is specific to Coinkite’s build configuration, not to hardware wallets as a category.
Is self-custody still safe after the Coldcard hack?
The Coldcard hack exposed a failure in one manufacturer’s implementation, not a flaw in the self-custody security model. Multisignature wallets, which require multiple independent keys from different devices, would have prevented every theft in this exploit. Security experts recommend using multisig configurations and verifying that hardware wallet manufacturers undergo independent entropy audits.
Should I move my bitcoin to an exchange after the Coldcard hack?
Exchange custody eliminates seed-management risk but introduces counterparty risk. FTX, Mt. Gox, Celsius, and other exchange failures collectively lost billions more than the Coldcard exploit. The decision depends on individual risk tolerance, technical capability, and the value of holdings. Bitcoin ETFs offer regulated price exposure without direct key management for investors who prioritize convenience over sovereignty. This is educational analysis, not investment advice.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Hardware wallet security incidents carry significant risk of permanent fund loss. Past security performance of any device does not guarantee future security. Published August 5, 2026.
Crypto World
Why Sandisk (SNDK) and Western Digital (WDC) crashed 10% and what it means for bitcoin
Sandisk (SNDK) and Western Digital (WDC), two of the biggest beneficiaries of the AI storage boom, were both 10% lower in pre-market trading Thursday, despite reporting strong quarterly results.
Sandisk posted record fourth-quarter revenue of $8.97 billion and non-GAAP EPS of $39.25, comfortably beating expectations. Western Digital also delivered a double beat, reporting revenue of $3.75 billion, up 44% year over year, while its gross margin surged to 54.4%. Despite those results, both stocks are now trading roughly 50% below their all-time highs.
The problem was guidance. Sandisk’s first-quarter outlook came in below expectations, with projected revenue of $10.7 billion versus the $11.2 billion analysts had estimated. Its EPS guidance also fell short. Western Digital’s first-quarter outlook was solid, but after a 500% run, investors were looking for another blowout beat.
Sandisk and Western Digital have gained more than 3,000% and 550%, respectively, over the past 12 months, propelled by the AI boom and leaving assets such as crypto and precious metals in the rearview mirror.
In addition, Sandisk’s board of directors has also approved an additional $14 billion share buyback program, bringing the total authorization to $15.5 billion.
Crypto World
Metronome Discloses $15.7 Million Synth Shortfall, Blames Oracle Lag in Swap Module

MetronomeDAO disclosed that roughly 6,367 msETH and 4.57 million msUSD in circulation, about $15.7 million at current prices, have no collateral behind them, after trading bots spent months exploiting delayed price data in the protocol's swap feature. The hole equals about 31% of all msETH and 16%… Read the full story at The Defiant
Crypto World
Bitget signs Bhutan agreement to pursue crypto license in GMC
Bitget has signed a cooperation agreement with Bhutan’s Gelephu Mindfulness City Authority to establish a local presence and pursue a Financial Services Licence under the city’s virtual asset framework.
Summary
- Bitget has signed an agreement to pursue a licensed presence in Bhutan’s Gelephu Mindfulness City.
- The exchange plans to establish a local entity and apply for a Financial Services Licence under GMC’s regulatory framework.
- Bhutan’s digital asset hub will work with Bitget on regulation, operations and ecosystem development.
- The move extends Bitget’s strategy of expanding through local regulatory approvals across selected markets.
According to Bitget, the agreement provides a framework for the exchange to establish a legal entity in Gelephu Mindfulness City (GMC), prepare an application for a Financial Services Licence under the regulatory framework administered by the Gelephu Financial Services Office (GFSO), and collaborate with the Gelephu Mindfulness City Authority (GMCA) on operational, regulatory and ecosystem development workstreams. The company said the cooperation remains subject to the required regulatory approvals.
Bitget plans legal entity and license application in Bhutan
Under the announced framework, Bitget intends to establish offices in GMC over time and hire locally as part of its long-term presence in Bhutan. The company said the local setup will support talent development, knowledge transfer and capability building alongside its exchange operations.
Gracy Chen, chief executive officer of Bitget, said Bhutan combines long-term planning, renewable energy resources and a regulatory framework that supports digital assets. She added that the company intends to contribute exchange infrastructure, operational experience and local talent development as the ecosystem develops.
The agreement also commits both parties to cooperate on regulatory processes and ecosystem-building activities tied to GMC’s financial services framework rather than limiting the relationship to licensing alone.
Gelephu Mindfulness City requires licensed virtual asset firms
Located in southern Bhutan, Gelephu Mindfulness City is being developed as a Special Administrative Region with ambitions to become an international financial and innovation hub.
Its virtual asset regime operates under the Financial Services Act 2025 and related rulebooks. Under that framework, companies providing regulated financial services or virtual asset activities in or from GMC must obtain a Financial Services Licence from the GFSO before operating.
Jigdrel Singay, board director of Gelephu Mindfulness City, said the city’s objective is to develop a digital asset ecosystem built on regulation, institutional standards and long-term economic value. He said partners such as Bitget contribute international expertise while helping strengthen local capabilities and the financial ecosystem.
The announcement also referred to Bhutan’s Bitcoin Development Pledge announced in December 2025, which presented the country’s strategy for integrating digital assets into economic development while promoting institutional participation and regulatory oversight.
Bhutan has already drawn attention within the digital asset industry for using surplus hydropower to support environmentally powered Bitcoin mining as part of efforts to diversify the economy, create employment opportunities and retain young professionals.
Bhutan agreement extends Bitget’s jurisdiction-by-jurisdiction strategy
The Bhutan announcement follows several regulatory moves by Bitget across different markets during the past few weeks.
Earlier this month, the exchange announced that it would withdraw services for residents of Japan instead of seeking local authorization. New account registrations have already been suspended, while account restrictions are scheduled to begin on Nov. 1. Bitget also said any positions that remain open on Dec. 31 will be closed automatically.
The Japan withdrawal came after repeated warnings from Japan’s Financial Services Agency in 2023 and 2024 over operating without registration. In June 2025, the Kanto Local Finance Bureau also issued a warning to BTG Technology Holdings Limited, identifying the company as operating under the Bitget name while allegedly soliciting certain online derivatives transactions without registration.
Outside Japan, the exchange has continued applying for registrations and approvals where it plans to maintain a local presence.
In July, Bitget completed registration on New Zealand’s Financial Service Providers Register across five financial service categories, including foreign exchange, client asset custody, domestic and cross-border money transfers, portfolio management, and execution of financial products. The company also joined New Zealand’s Insurance and Financial Services Ombudsman dispute resolution scheme.
New Zealand’s Companies Office has stated that registration on the FSPR does not itself constitute government approval or active regulatory supervision. Depending on the activity involved, separate authorization from the Financial Markets Authority or the Reserve Bank of New Zealand may still be required.
Local licensing remains central to Bitget’s expansion plans
Bitget has adopted a market-by-market regulatory approach rather than offering identical services across all jurisdictions.
During July, the exchange confirmed that Singapore remains a restricted jurisdiction because it is not licensed, approved, registered or supervised by the Monetary Authority of Singapore. The company said it neither offers services to nor targets residents in the country.
The exchange is also preparing for a return to the United States. As previously reported by crypto.news, Bitget plans to establish an independent U.S. entity before launching services and will first pursue money-transmitter, broker-dealer and derivatives approvals. She said the company’s U.S. expansion will proceed regardless of whether Congress ultimately passes the CLARITY Act.
Alongside its regulatory work, Bitget has continued expanding its tokenized investment products. Chen previously said tokenized traditional assets accounted for between 20% and 30% of the exchange’s spot trading volume during the previous quarter, while 52% of Bitget users held both cryptocurrencies and stocks.
Crypto World
Coldcard Hackers Send 64 BTC and 200 ETH to Crypto Mixers
Stolen funds tied to the Coldcard hardware wallet exploit are showing early signs of laundering, but blockchain security researchers say most potential copycats have not yet moved large amounts of the victimed crypto. According to CertiK, about 64 Bitcoin (worth roughly $4.17 million) and 200 Ether (worth about $380,000) linked to the attack were routed into well-known mixing services—Wasabi for BTC and Tornado Cash for ETH.
The Coldcard incident has quickly become one of the largest crypto hacks of the year. Galaxy Digital previously put confirmed losses at least at $100 million in Bitcoin across three waves, and it also flagged a possible fourth wave that could raise total losses to around $130 million.
Key takeaways
- CertiK says roughly 64 BTC linked to the Coldcard exploit were sent to Wasabi, and 200 ETH were moved to Tornado Cash.
- Mixing services typically pool funds and obscure onchain linkages, reducing the odds of recovery for victims.
- TRM Labs’ tracing suggests most victim balances remain concentrated in a small set of attacker-controlled addresses with limited mixing activity.
- Analysis of transaction patterns across attack waves indicates the exploit may involve more than one actor.
Mixing services enter the Coldcard laundering picture
CertiK’s blockchain monitoring connected specific transfer activity to the Coldcard exploit and mapped part of the flow into privacy and obfuscation tooling. In its reporting, CertiK indicated that the Bitcoin transfer—sourced from address bc1q0—was sent to the Wasabi mixing protocol on Tuesday, using CertiK’s address data shared with Cointelegraph.
On the Ethereum side, CertiK stated that 200 ETH were sent to Tornado Cash on Wednesday, pointing to an X post from its account as the basis for the observation.
Crypto mixers like Tornado Cash operate by pooling deposits from multiple users and then releasing funds in a way that breaks straightforward onchain tracking from original sender to final recipient. That feature is precisely what makes tracing more difficult and asset recovery less likely—especially when attackers move quickly and fragment funds across multiple addresses and services.
Why this matters: laundering momentum vs. copycat behavior
CertiK’s spokesperson told Cointelegraph that the activity could be linked to a smaller exploiter, adding that “there’s likely a few copycats after the initial exploit.” The implication is straightforward: if additional parties used the same weakness, their onchain movement could help or hinder investigators depending on whether they follow up with laundering at scale.
That’s where TRM Labs’ findings become important. In a Thursday report titled “The largest hardware wallet exploit of 2026: inside the $116 million Coldcard hack”, TRM Labs said its onchain tracing indicates most victim funds were still pooled in a limited number of attacker-controlled addresses and that mixing attempts appeared restrained.
TRM Labs also highlighted that “differences in transaction construction” between each wave suggest multiple attackers. In other words, even if the underlying vulnerability was shared, the operational playbook may not be identical—an asymmetry that can be useful for investigators trying to separate participant identities, funding sources, and laundering pathways.
Coldcard hack scale and the “waves” pattern
Galaxy Digital previously characterized the Coldcard exploit as the third-largest cryptocurrency hack of 2026 so far, based on confirmed activity. In its assessment, Galaxy put drained losses at at least $100 million in Bitcoin across three verified attack waves involving 7,300 victim wallets. Galaxy also pointed to a suspected fourth wave that could lift total losses to roughly $130 million in BTC, according to earlier coverage from Cointelegraph.
Those wave-based findings matter for how analysts interpret laundering. If attackers are not distributing funds aggressively—or if only one portion of the stolen assets has been moved into mixers—then the time dimension becomes critical: investigators may still be waiting for broader follow-through as additional actors or additional batches of stolen funds begin to move.
Galaxy’s earlier analysis, also cited by Cointelegraph, suggested at least 15 different attackers exploited the vulnerability. This lines up with TRM Labs’ point about differences in transaction construction between waves, reinforcing the idea that what may look like a single incident could actually be a coordinated (or at least parallel) operation with distinct participants.
The technical weakness behind the exploit
TRM Labs’ report attributed part of the vulnerability to a firmware bug from March 2021 that weakened seed randomness on some Coldcard wallets. According to TRM Labs, the bug effectively reduced key strength to 40 bits from 128 bits, making it “brute-forceable without physical access.”
Other commentary around the fix has emphasized the low cost of better security hygiene. Dragonfly managing partner Haseeb Qureshi wrote that approximately “$2 of AI hardening” could have prevented the Coldcard exploit, referencing social media reports that some AI models rediscovered the vulnerability quickly—though those claims are framed as commentary rather than formal technical findings.
For investors and builders, the core takeaway is less about any single price tag and more about how quickly weaknesses can be weaponized once public knowledge spreads. When a vulnerability can be exploited remotely and at scale, incident response needs to account for both immediate attackers and longer-tail copycats.
Going forward, readers should watch whether additional attacker-controlled addresses begin pushing larger portions of stolen balances into mixing services, and whether the “suspected” fourth wave confirmed by Galaxy develops further. As more funds move—or fail to move—onchain, investigators will gain clearer signals about how many actors are involved and how successfully they’re managing to break traceability.
Crypto World
Putin Signs Russia’s Crypto Law; Key Rules Begin in 2026
Russian President Vladimir Putin has signed legislation that lays out a regulated framework for cryptocurrency markets in Russia, marking a significant shift from the country’s largely restrictive posture toward a formal rules-based approach for licensed crypto activity.
The law, identified as bill No. 1194918-8 and titled “On Digital Currencies and Digital Rights,” was signed on Tuesday, according to official records from the State Duma, Russia’s lower house of parliament. It sets out requirements for major categories of crypto market participants, including exchanges, brokers, custodians, and other service providers.
Key takeaways
- Russia has moved toward a regulated crypto market through bill No. 1194918-8 (“On Digital Currencies and Digital Rights”).
- Crypto exchanges must meet regulatory conditions and join a financial market self-regulatory organization.
- Retail investors will be limited to purchasing only approved digital assets via intermediaries, with a 300,000 ruble annual cap per intermediary.
- Qualified investors are expected to face fewer restrictions and be able to buy any cryptocurrency.
- The law keeps Russia’s ban on using crypto assets to pay for goods and services domestically.
What the law changes for Russian crypto activity
At the center of the new bill is a licensing and oversight model intended to bring Russia’s crypto market into a clearer regulatory structure. The legislation defines rules for key participants across the crypto ecosystem, including trading venues (exchanges) and intermediary services such as brokerage and custody.
Under the framework, operators of crypto exchanges are required to comply with regulatory requirements and become members of a financial market self-regulatory organization. That combination suggests that, beyond direct supervision, exchanges will likely be subject to additional industry-level governance through the self-regulatory body.
Limits for retail investors, flexibility for qualified investors
A major practical feature of the law is how it differentiates between types of market participants. The bill limits retail investors’ access to cryptocurrencies by requiring intermediaries to sell only approved crypto assets and by imposing a quantitative ceiling on purchasing activity.
Specifically, the law sets an annual cap of 300,000 rubles (about $3,700) per intermediary for retail investors. Qualified investors, by contrast, will be allowed to purchase any cryptocurrency without the same restrictions.
For everyday users and smaller investors, the implication is straightforward: access to the broader crypto market could become more fragmented and filtered through intermediaries—while larger or more formally designated investors may be able to maintain wider exposure.
Regulatory oversight and the approval process
According to the law as reported through official parliamentary records, the Bank of Russia will be responsible for overseeing the regulated crypto market. That includes issuing related regulatory rules and determining which crypto assets licensed intermediaries can offer to investors.
In late July, the State Duma approved the legislation after final readings, an earlier step referenced in separate coverage at Cointelegraph. With the signing now completed, implementation becomes the next critical phase—particularly because different parts of the law take effect at different times.
When rules take effect—and what stays prohibited
Timing matters for investors, exchanges, and service providers because regulatory obligations rarely arrive all at once. The core provisions of the law take effect on Sept. 1, 2026. Some elements—including rules covering non-resident digital depositories—are scheduled to begin on July 1, 2027.
The law also preserves an existing prohibition on using crypto assets to pay for goods and services within Russia. That means the new regulatory structure is aimed at governance of crypto market participants and investor access, rather than enabling everyday crypto spending domestically.
Why this framework could reshape Russia’s crypto market
This legislation matters beyond legal formality because it defines who can participate, what assets can be offered through licensed channels, and how investors access those markets. By placing responsibility on the Bank of Russia to issue rules and approve which assets intermediaries may provide, the law effectively creates a gatekeeping mechanism—one that could influence liquidity, available trading pairs, and the list of cryptocurrencies that reach retail customers.
The retail investment cap per intermediary may also affect product design for brokers and custodians, since their compliance exposure would be linked to both approved asset lists and distribution limits. Meanwhile, the distinction between retail and qualified investors suggests that market access will not be uniform: segments of the investor base could experience different levels of flexibility and risk exposure depending on their classification.
As the implementation dates draw closer, market participants will likely focus on how the Bank of Russia translates the law into operational guidance—especially around licensing conditions, asset approval procedures, and the treatment of non-resident digital depositories.
Investors and builders should watch closely for the Bank of Russia’s rulemaking and for how “approved” crypto assets are selected, since those decisions will determine what retail users can realistically access before the Sept. 1, 2026 start date.
Crypto World
Bitcoin’s (BTC) low price volatility doesn’t necessarily mean low risk: Crypto Daily
“When volatility is cheap, traders can build directional positions and hedges at relatively low cost. If the market then moves through a level with concentrated positioning, dealer hedging can accelerate the move,” Adam Haeems, head of asset management at Tesseract Group, which manages $500 million in client assets, said in an email.
“The practical implication is that low volatility should not be mistaken for low risk. It is a reason to be careful with leverage, particularly when trading volumes and market depth are subdued.”
For now, BTC remains choppy below $65,000 with some green shoots.
According to Paul Howard, a senior director at market-making firm Wincent, demand for puts, or downside protection, has weakened. At the same time, there is a lack of strong bids for upside exposure.
“It indicates that the bear market is close to trading at its lowest price range for this cycle, arguably over the coming weeks,” he said in an email.
“The asymmetry is not a bid for puts; it is the disappearance of the call bid. Nobody is paying for upside, and nobody is paying much for downside,” Glassnode said.
According to Howard, the next big catalyst would be “some positive regulatory news such as with the Clarity Act, which would likely manifest as institutional ETF inflows.”
Crypto World
Free Markets and Innovation, Sort Of
What Clarity declines to do is impose customer identification duties on software that has no customers. Software that takes no custody and controls no transactions is in no position to identify anyone. Requiring KYC on code does not create a compliance obligation on intermediaries; it creates a prohibition on publishing code.
Tokenized securities
The last worry is that stocks will migrate to decentralized shadow markets with few investor protections. As clearly stated in section 10505, a security does not cease to be a security simply because it settles on a blockchain. Securities remain under SEC authority, and Section 10301 is the provision that reaches whoever exercises control over the venue where that trading happens.
But notice what the editorial does with tokenization across four paragraphs. When banks issue and settle tokenized stocks and bonds, it removes friction, lowers costs, and merits support. When the same instruments trade somewhere else, it is a shadow market inviting regulatory evasion. The technology did not change between those two passages. The identity of the firm using it did.
That pattern runs through the piece: nobody needs to explain to the Journal’s editorial page what it looks like when an established industry asks Washington to slow down a competitor. That is usually the argument it makes in the spirit of free and open markets, which is why this latest editorial is so disappointing. The editorial suggests Republicans are rushing this bill through before leaving town. It ignores that market structure legislation has been in the works for years. The House passed it a year ago with overwhelming bipartisan support. Senate Banking reported it in May. It has been on the Senate calendar since June and is not yet on the floor schedule this week. Haste is not the problem.
Crypto World
YGG Play Shuts Down Services as Yield Guild Pivots to AI Data

Yield Guild Games co-founder Gabby Dizon said its web3 game publishing arm went dark on Friday. "@YGG_Play services will shut down as of today," Dizon wrote on his verified X account on Friday, adding that "our @YieldGuild story continues – more on this starting next week!" The unit posted its own… Read the full story at The Defiant
Crypto World
Ethereum Price Prediction: ETH Is Boxed In at $1,91 With No Conviction From Either Side
In the latest Ethereum price prediction, ETH is trading at $1,912, down 0.41% over the past 24 hours, holding within a tight intraday range of $1,895.10 to $1,917.74. The consolidation is real, but what happens next depends almost entirely on catalysts ETH does not control yet.
Price action has been characteristically choppy, with muted 24-hour volatility alongside a modest weekly recovery. Trading volume clocked in around $8.7 billion, respectable but not the kind of number that signals conviction from either bulls or bears.
ETH remains range-bound, with directional bias dependent on incoming macro data and any regulatory signals touching major smart-contract platforms.
ETH’s underperformance relative to select altcoins, particularly in AI, restaking, and L2 narratives, has rotation-watchers paying close attention. The broader setup will define whether the recent weekly rebound has legs or fades back into the prior consolidation zone.
Discover: Everyone’s Got a Take. Get Free $25 to Actually Trade Yours
Ethereum Price Prediction: Can Ethereum Break $1,950 Resistance and Sustain a Breakout This Week?
ETH is trading at $1,912, pressing into the upper half of its recent range but has yet to clear the resistance cluster that matters. The $1,950 to $1,970 zone is the next meaningful ceiling, roughly aligned with prior distribution levels where sellers have consistently emerged. Below, $1,880 to $1,895 is the immediate support shelf.
The current intraday low at $1,895.10 is already brushing that band.
Volume context matters here. An $8.7 billion daily print is not weak, but it is not the kind of expansion that typically precedes a clean breakout either. Spot demand appears balanced against profit-taking from the weekly recovery, keeping momentum neutral.

ETH holding $1,895 support, macro data printing risk-on, and expanding volume push price through $1,950 toward the $2,000 to $2,050 psychological zone.
Consolidation continues within the $1,880 to $1,950 channel, with no decisive breakout or breakdown until a macro or regulatory catalyst forces direction; this is the base case. A close below $1,860 invites a retest of mid $1,700s structural support, the range ETH was parked in just days ago, and resets the short-term technical picture.
Regulatory treatment of smart-contract platforms remains the wildcard. Any clarity or ambiguity from US regulators on ETH’s classification could trigger institutional flows in either direction. Key supply dynamics suggest ETH needs sustained buying pressure, not just a relief bounce, to confirm a structural shift.
Discover: Your Market Calls Are Worth Something. Start With Free $25 on Kalshi
Maxi Doge Targets Early Mover Upside as Ethereum Tests Key Levels
ETH at $1,909 is a recovery — but at this market cap, the asymmetric upside traders dream about simply isn’t on the table. That’s the tradeoff when positioning in large-cap assets during consolidation phases: stability, yes; 10x potential, no. For traders whose risk appetite runs hotter, the presale market is where that math still exists.
Maxi Doge ($MAXI) is a meme token on Ethereum (ERC-20) built around what it calls the “Leverage King” culture, a 240-lb canine mascot embodying 1000x trading mentality, complete with holder-only trading competitions, leaderboard rewards, and a Maxi Fund treasury earmarked for liquidity and partnerships.
The tagline is blunt: Never skip leg day, never skip a pump. Current presale price sits at $0.0002832, with $4,836,932.30 raised to date, a number that signals genuine community traction rather than a ghost project.
Dynamic staking APY is live for participants. As with any presale, execution risk is real, meme tokens live and die by community momentum, and there are no guarantees of exchange listings or sustained volume post-launch.
For traders already watching ETH’s consolidation play out, research Maxi Doge as a speculative complement rather than a replacement for your core book.
Discover: Get Paid to Be Right, $25 to Start on Kalshi
Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit
The post Ethereum Price Prediction: ETH Is Boxed In at $1,91 With No Conviction From Either Side appeared first on Cryptonews.
Crypto World
Situational Awareness Returns with $400M Investment after Nearly Collapsing: Report
Cointelegraph is committed to providing independent, high-quality journalism across the crypto, blockchain, AI, and fintech industries.
All news, reviews, and analyses are produced with full journalistic independence and integrity. For more details on our standards and processes, please read our Editorial Policy.
-
Fashion6 days agoWeekend Open Thread: Wit & Wisdom
-
Politics6 days agoMeta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
-
Politics4 days agoZack Polanski: an incitement to murder Nigel Farage?
-
Crypto World5 days agoMicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
-
Crypto World5 days agoXRP Ledger v3.3.0 brings five institutional features
-
Politics7 days agoLuke Littler’s dominance sparks GOAT debate
-
Sports6 days agoSeema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
-
Crypto World5 days agoNew York sues Kalshi over prediction market gambling
-
Crypto World4 days agoCrypto PAC spending tops $2M in Michigan House race
-
Business3 days agoDTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
-
Business6 days agoTrump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
-
Crypto World6 days ago3 Fed Officials Just Explained Their Rate Hike Vote: Is Inflation Winning?
-
Tech6 days agoGemini Spark can now use Chrome logins and saved passwords to run errands on your behalf
-
Tech4 days agoESET tracks rise in malicious AI skills and adaptable malware
-
Sports5 days agoFrance Cricket implodes: letters hidden in a drawer and a board at war
-
Tech6 days agoBuilding A Reproduction PlayStation Motherboard
-
Crypto World4 days agoXRP Ledger urges node upgrade after manifest flood
-
Crypto World5 days agoMoneyflip CEO charged in $40K murder-for-hire plot
-
Sports5 days agoBruno Fernandes decision made as Man United ‘discuss’ striker transfer option
-
News Videos5 days agoFinancial Crash Expert: The 90-Day Collapse Timeline They Are Desperately Hiding.

You must be logged in to post a comment Login