A 5-year-old bug just drained $38 million in BTC from 500 wallets.
Bearish mood for August builds as $60K put becomes top BTC trade. Coldcard wallet flaw drains 594 BTC ($38M) in 25 minutes. BTC falls despite equity rally. July ends as crypto’s best month in a year.
As July ends, the options market is flashing a clear bearish signal heading into August. The $60,000 bitcoin put option — a position protecting against a price drop — is now the most popular bet on Deribit, the world’s largest crypto options exchange, with notional open interest of $1.17 billion. Until yesterday, $70,000 and $72,000 call options were the market leaders, each boasting $2.5 billion in open interest as traders positioned for a post-Fed rally. That didn’t happen, and Friday’s $10 billion options expiry at 08:00 UTC likely flushed much of that bullish positioning. Seasonality adds to the caution: since 2013, a positive July — bitcoin is up 8.9% this month, near the historical median of 8.61% — has typically been followed by a negative August, with a median return of −7.51%. BTC and ETH are falling today even as equities rally, with the CoinDesk 20 on track for its best monthly gain since July 2025. Stay alert.
Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep.
Roughly 594 bitcoin — worth approximately $38 million — was swept from around 500 separate wallets between 01:31 and 01:56 UTC on Friday in an attack traced to a flaw in how Coldcard hardware wallets generated their cryptographic keys. The attacker moved 1,324 chunks of bitcoin across 500 transactions inside a three-block window, then consolidated 562 BTC into a single address that has not moved. Every drained wallet was single-signature and held more than 0.15 BTC, with many dormant for years. The vulnerability was introduced in Coldcard firmware 4.0.0 in March 2021: a build setting caused devices to skip their hardware randomness generator and fall back to a software substitute seeded from the chip’s serial number and clock registers — none of which are secrets. Block’s Bitcoin engineering team disclosed the flaw publicly because exploitation was already under way. Coinkite has warned users who created seeds on Mk3 devices running firmware 4.0.1 or later, and stated that Mk4, Q, and Mk5 appear unaffected. The exposure extends beyond wallet seeds to paper wallet private keys, seed-splitting masks, device cloning keys, and Key Teleport transfers. Bitcoin traded above $63,700 as the news broke, with the drain appearing to have little immediate market impact.
CoinDesk Disclosure: The information contained in this newsletter, and any information linked through the items contained herein, is not intended to provide sufficient information to form the basis for an investment decision. You should seek additional information regarding the merits and risks of investing in any cryptocurrency or digital assets.
L1.co Disclosure: This material is for informational purposes only, and the content contained herein should not be considered investment advice or a solicitation, offer, or recommendation to sell or buy any asset, strategy, or product. Investing in digital assets involves a high degree of risk, including the loss of principal.
Crypto Daybook Americas: A newsletter from CoinDesk