Wire
23:35ZSCMPNEWSSearch underway for missing cruise passenger off Hong Kong mega bridge23:34ZSCMPNEWSHong Kong opens trade office in Malaysia, bridging Greater Bay Area: minister23:33ZSCMPNEWSChinese husband builds world's largest hollyhock garden inspired by wife's childhood memory23:32ZSCMPNEWSChinese paratrooper killed in Qinghai military exercise; Beijing acknowledges casualties23:31ZEPOCHTIMESFinnish trial finds partial meniscectomy may accelerate osteoarthritis in older patients23:31ZSCMPNEWSPakistan Signs New Defense Agreement, Prompting Concern in India23:30ZPRESSTVIran army chief calls for enhanced coordination in armed forces to strengthen deterrence23:26ZALALAMFANew York Times: Iranians employed new missile tactics in recent fighting
  • S&P 500 ETF 0.01%
  • Nasdaq 0.60%
  • Nasdaq 100 0.33%
  • Dow ETF 0.01%
Terminal ↗
← The MonexusCrypto

Coldcard hack deepens as Bitcoin slides: a week that exposed crypto's self-inflicted wounds

A hardware-wallet flaw stripped more than $88 million from users in days, while a Polymarket contract priced a sub-$60,000 Bitcoin at 59%. The week's two stories are really one story.

An orange graphic displays the word "CRYPTO" in large white letters, with "DESK" and "MONEXUS NEWS" headers and a note stating "No photograph on file."
An orange graphic displays the word "CRYPTO" in large white letters, with "DESK" and "MONEXUS NEWS" headers and a note stating "No photograph on file." Monexus News

The numbers stopped looking like a glitch sometime on 31 July 2026. By the close of that Friday, a hardware-wallet flaw tied to Coldcard had been linked to the theft of 594 BTC worth about $38 million, and earlier reporting that day had put the figure at roughly $40 million across some 500 compromised devices. Two days later, on 1 August, the cumulative take had crossed $88 million.

That is the surface story. The deeper one is that the same seventy-two hours that exposed a critical random-number generator flaw in a brand long treated as a security benchmark also drove Bitcoin back under $63,000, liquidated roughly $125 million in leveraged positions inside an hour, and priced a sub-$60,000 print by month-end at 59% on Polymarket. The wallet story and the price story are not adjacent. They are the same story, told from two ends of a market that has never resolved its oldest tension: who is responsible when the self-custody pitch meets a self-inflicted wound.

The flaw, the figure, and the moving target

The earliest public figure, reported by WatcherGuru on 31 July at 09:43 UTC, was $40 million across roughly 500 wallets. By the same afternoon at 16:05 UTC, a Polymarket brief cited 594 BTC, valued at about $38 million at the time of the alert, with the company urging users to relocate funds. By 1 August at 21:04 UTC, the cumulative take had crossed $88 million, per a WatcherGuru update. Each revision came with the same caveat: the number was moving as more affected addresses were identified.

The technical line, repeated across the alerts, points to a random-number generator flaw, the kind of bug that turns a hardware wallet from a vault into a sieve. The detail that matters is not the specific chip or firmware version, because the cited posts do not specify it. What matters is the category. Random-number generation is the single component of a hardware wallet whose failure cannot be mitigated by the user. A lost seed phrase can be recovered with backups. A compromised RNG cannot.

That distinction reframes the marketing. Coldcard, like its peers, sells the device as the last line of self-custody defence; the pitch is that the user, not an exchange, controls the keys. When the device itself is the vector, the pitch collapses into its opposite: the user took the responsibility, and the device took the money.

The price prints nobody wanted

Friday's hack landed into a market already leaning the wrong way. On 31 July at 14:55 UTC, WatcherGuru reported Bitcoin back under $63,000 with $125 million in liquidations over the preceding sixty minutes. The 30-year US Treasury yield had hit its highest level since 2007 the same afternoon at 18:30 UTC, a reminder that the macro tape was not in a forgiving mood. Long-duration yields rising tends to compress the multiple on any non-yielding asset, Bitcoin included, and the leverage that had accumulated on the way up was the leverage that got cleared on the way down.

Then on 2 August at 20:15 UTC, Polymarket posted a market giving Bitcoin a 59% chance of trading below $60,000 by month-end. That is not a price target; it is a probability surface, and the implied distribution is a market that does not believe the selling is finished.

Monexus analysis: read together, the two prints describe a feedback loop in slow motion. A wallet exploit forces holders of affected devices to move coins. Some of those coins land on exchanges, increasing immediate sellable supply. Headline-driven liquidation cascades follow, and the probability of a further leg down rises with each forced seller. None of this requires a coordinated actor. It requires a market that has learned, repeatedly, to treat infrastructure incidents as trading signals.

The trust tax, paid in self-custody

Self-custody was sold, for the better part of a decade, as an exit from counterparty risk. Keep your own keys, the pitch went, and the only person who can take your Bitcoin is you, or someone with your seed phrase. The Coldcard episode is a useful case study in what that pitch leaves out: the device vendor is a counterparty, the firmware is a counterparty, the supply chain that delivers the secure element is a counterparty. Removing the exchange from the risk stack did not eliminate counterparty risk. It moved it.

That move has consequences for the user base. On 3 August at 01:59 UTC, the on-chain investigator zachxbt posted that he had stopped answering direct messages from people in the space, citing repeated instances in which victims of one scam attempted a second scam on the person trying to help them. The post was not about Coldcard. The post was about the trust environment Coldcard's users now have to navigate: a market where the infrastructure can fail, the helper can be tested, and the asker may be running a follow-on play.

Monexus assessment: the trust tax is the under-reported cost of every security incident. Each one raises the bar for the next person trying to coordinate a response, fund a recovery, or simply warn a stranger. The bear case for crypto in 2026 is not the price. The bear case is the slow erosion of the social infrastructure that lets the market function between price prints.

What to watch before the month closes

Three dates will determine whether the $60,000 print becomes a floor or a waypoint. First, any updated disclosure from Coldcard on the scope of the RNG flaw and the firmware path for remediation, which the cited posts do not specify. Second, the trajectory of the 30-year yield, which sets the discount rate against which every non-yielding asset is priced. Third, the Polymarket contract itself: a market that gives 59% to a sub-$60,000 print does not have to wait for the print to move, only for the implied probability to drift.

The asymmetry is the point. Holders of affected devices have already paid. Holders of unaffected devices are now repricing the category. And the people on the other end of those DMs, the ones still willing to answer, are deciding how many more times they will.

Desk note: Monexus framed this as one story, not two, because the wallet exploit and the price action share a single root cause: a market that has externalised counterparty risk onto infrastructure it does not audit and a user base it cannot indemnify. The wire so far has treated them as separate beats; this publication reads them as one.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://t.me/watcherguru/14489
  • https://x.com/Polymarket/status/2083222613799616530
  • https://t.me/watcherguru/14492
  • https://t.me/watcherguru/14494
  • https://t.me/watcherguru/14511
  • https://x.com/Polymarket/status/2084010260914647444
  • https://x.com/zachxbt/status/2084096875242869206
© 2026 Monexus Media · AI-native reporting from public-source material