{"id":76284,"date":"2026-08-02T22:11:42","date_gmt":"2026-08-02T22:11:42","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/coldcard-hacker-gets-brazen-bitcoin-laundering-offer-onchain-bitcoin-news\/"},"modified":"2026-08-02T22:11:42","modified_gmt":"2026-08-02T22:11:42","slug":"coldcard-hacker-gets-brazen-bitcoin-laundering-offer-onchain-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/coldcard-hacker-gets-brazen-bitcoin-laundering-offer-onchain-bitcoin-news\/","title":{"rendered":"Coldcard Hacker Gets Brazen Bitcoin Laundering Offer Onchain \u2013 Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Coinkite thefts reached 1,359.8820 BTC after new attack waves through Aug. 2.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">OP_RETURN carried a 10% laundering offer to the Coldcard hacker on Aug. 1.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Coldcard users await Coinkite guidance as firmware bricking reports continue.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>The new developments come just days after Coinkite <a href=\"https:\/\/news.bitcoin.com\/featured\/the-coldcard-exploit-explained-who-lost-bitcoin-and-whos-at-risk\/\">disclosed that a long-dormant firmware flaw<\/a> had allowed attackers to recover weakly generated wallet seeds and systematically drain vulnerable single-signature wallets. The estimated total has now climbed to roughly 1,359.8820 BTC, according to stats collected by the <a href=\"https:\/\/coldcard-watch.vercel.app\" target=\"_blank\" rel=\"noopener noreferrer\">Coldcard Sweep Watch dashboard<\/a>, with most of the identified coins remaining in a handful of addresses under the attacker\u2019s control.<\/p>\n<h2>OP_RETURN Turns the Bitcoin Blockchain Into a Public Bulletin Board<\/h2>\n<p>On Aug. 1, one of the attacker\u2019s holding addresses received an <a href=\"https:\/\/mempool.space\/tx\/725765943699e82b583b7083bf5f76fefa7576503e603826ab288ecb16b6b2ac\" target=\"_blank\" rel=\"noopener noreferrer\">unusual transaction containing an OP_RETURN message<\/a>. OP_RETURN is a special Bitcoin transaction output that stores permanent text on the blockchain rather than transferring spendable funds.<\/p>\n<figure id=\"attachment_836215\" aria-describedby=\"caption-attachment-836215\" style=\"width:2312px\" class=\"wp-caption aligncenter\"><figcaption id=\"caption-attachment-836215\" class=\"wp-caption-text\">Onchain message sent to the hacker\u2019s wallets. Speculators wonder if it is a serious offer or a honeypot. Image source: mempool.space.<\/figcaption><\/figure>\n<p>The message openly advertised services to \u201cclean\u201d bitcoin, provide know-your-customer (KYC) assistance, and cash out the stolen coins in exchange for a 10% fee, along with a Telegram contact. It was not a technical message or a victim appeal. Instead, it appeared to be a direct solicitation aimed at whoever controls the stolen bitcoin. Some suggest it could be law enforcement or someone setting a trap.<\/p>\n<h2>Attack Leaves Most Stolen Bitcoin Sitting in Plain Sight<\/h2>\n<p>Although the theft involved more than 1,300 BTC, blockchain researchers have observed that much of the bitcoin remains largely untouched. The attacker consolidated funds into a relatively small number of addresses after sweeping vulnerable wallets during several coordinated waves beginning on July 30.<\/p>\n<p>That visibility has become one of the more unusual aspects of the case. Bitcoin\u2019s transparent ledger allows anyone to monitor high-value addresses, meaning victims, investigators, researchers, and even opportunists can all watch the same transactions unfold in real time. OP_RETURN messages demonstrate that the blockchain can also function as a permanent public messaging system during major incidents.<\/p>\n<p>Several projects that have been hacked in the past use OP_RETURN messages to discuss bounties and demands with hackers.<\/p>\n<h2>Emergency Firmware Fix Creates New Headaches<\/h2>\n<p>As users rushed to secure their remaining funds, another problem emerged.<\/p>\n<p>Coinkite <a href=\"https:\/\/x.com\/COLDCARDwallet\/status\/2083186689246208474?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">released emergency firmware updates<\/a> designed to eliminate the weak random number generation that caused the original vulnerability. The company made clear that the new firmware only protects wallets created in the future and does not repair seeds already generated on vulnerable versions.<\/p>\n<figure id=\"attachment_836235\" aria-describedby=\"caption-attachment-836235\" style=\"width:1410px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-836235 size-full\" title=\"Coldcard Hacker Gets Brazen Bitcoin Laundering Offer Onchain\" src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2026\/08\/nothern.png\" alt=\"X screenshot. \" width=\"1410\" height=\"1220\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2026\/08\/nothern-300x260.png 300w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2026\/08\/nothern-1024x886.png 1024w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2026\/08\/nothern-768x665.png 768w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2026\/08\/nothern.png 1410w\" sizes=\"auto, (max-width: 1410px) 100vw, 1410px\"\/><figcaption id=\"caption-attachment-836235\" class=\"wp-caption-text\">Image source: X<\/figcaption><\/figure>\n<p>Soon after the release, <a href=\"https:\/\/x.com\/northernH0DL\/status\/2083633778572787862?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">users began reporting that some devices<\/a> became stuck on error screens, failed to boot or <a href=\"https:\/\/x.com\/TeddyBitcoins\/status\/2083957827136102506?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">appeared completely bricked<\/a> after installing the update. Reports have primarily involved Mk4 and Q devices, although some Mk3 users have also described similar problems. As of Aug. 2, Coinkite had not publicly confirmed a widespread firmware defect, but several user reports have fueled growing concern throughout the Bitcoin community.<\/p>\n<h2>Security Experts Push Users to Move Funds First<\/h2>\n<p>One of the <a href=\"https:\/\/x.com\/lopp\/status\/2083958797354127631?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">strongest messages circulating<\/a> among experienced bitcoin security advocates is that owners of potentially vulnerable wallets should migrate funds before updating firmware whenever possible.<\/p>\n<p>That recommendation reflects an important limitation of the emergency patch. Updating software cannot strengthen a weak seed that was already created years ago. If the original wallet was generated with insufficient randomness, the only lasting solution is to move funds into an entirely new wallet created with strong entropy.<\/p>\n<p>For many users, verified seed backups have become the difference between a hardware failure and permanent loss, since a damaged device can often be replaced while the recovery phrase restores access to the funds.<\/p>\n<h2>Confidence Faces Its Biggest Test Yet<\/h2>\n<p>The <a href=\"https:\/\/news.bitcoin.com\/crypto-news\/coldcard-theft-balloons-to-88m-as-exchange-deposits-spike-old-btc-moves\/\">ongoing Coldcard incident<\/a> has evolved beyond a single firmware flaw into a broader test of confidence in hardware wallet security. The combination of a historic entropy bug, a public laundering solicitation embedded directly on Bitcoin\u2019s blockchain and reports that emergency updates may brick some devices has intensified debate over wallet design, seed generation, and long-term self-custody practices.<\/p>\n<p>While monitoring of the known attacker addresses continues, users are now watching two developments just as closely: whether the stolen bitcoin eventually moves and whether Coinkite issues additional guidance for customers experiencing firmware failures.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/crypto-news\/coldcard-hacker-gets-brazen-bitcoin-laundering-offer-onchain\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Coinkite thefts reached 1,359.8820 BTC after new attack waves through Aug. 2. OP_RETURN carried a 10% laundering offer to the Coldcard hacker on Aug. 1. Coldcard users await Coinkite guidance as firmware bricking reports continue. The new developments come just days after Coinkite disclosed that a [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":76285,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76284"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=76284"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76284\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/76285"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=76284"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=76284"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=76284"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}