Ledger and Trezor told users their funds are safe after a firmware flaw in rival Coldcard wallets enabled a $70 million Bitcoin (BTC) theft in 41 minutes.
Key Points:
- Ledger, Trezor, Bitkey, Jade and Tangem said the Coldcard firmware flaw does not touch their devices.
- Attackers drained 1,082.65 BTC from 1,196 addresses on Jul. 30, nearly double the first estimate.
- Bitcoin social sentiment fell to a record low, and spot ETFs lost $265.4 million on Jul. 31.
Ledger And Trezor Reject Coldcard Link
Ledger said it was not affected by the Coldcard Mk3 advisory, citing a certified random number generator built into its secure element chip.
Trezor told customers on Friday that the fault sits in Coinkite's own custom firmware, which Trezor does not share. Bitkey, Jade and Tangem also moved to reassure their users within hours.
Trezor attached one warning. Anyone who created a seed on an affected Coldcard and later restored it on another device stays exposed, because the weak randomness travels with the seed itself.
Also Read: AI Infrastructure, Payday Lender's Desperate $1B Pivot To Dominate Data Centers
Bitcoin Sentiment Falls To Record Low
Galaxy Research linked the sweep to a 41-minute window early on Jul. 30, covering 1,082.65 BTC across 1,196 addresses. That total roughly doubled the 594 BTC first reported. Santiment then logged a bullish-to-bearish commentary ratio of 0.58, its weakest Bitcoin reading on record.
Money followed the mood.
U.S. spot Bitcoin ETFs shed $265.4 million on Jul. 31, ending two days of inflows. BlackRock's IBIT accounted for $122.7 million of that, with Fidelity's FBTC next at $54.8 million. Bitcoin itself has held near $63,000 since Friday's decline of almost 3%.
Ido Ben-Natan, chief executive of security firm Blockaid, argued that most 2026 crypto losses came from compromised keys rather than broken smart contracts. Joe Burnett of Strive wrote that the episode could permanently reshape how investors think about self-custody.
Coldcard Firmware Flaw Timeline
The vulnerability sat unnoticed for five years. Block's engineers traced it to a code commit dated Mar. 1, 2021, which shipped in firmware 4.0.0 and quietly routed seed generation to a software substitute.
Effective entropy on Mk3 devices fell to roughly 40 bits, against the 128 bits a standard seed should carry.
Coinkite issued its first public advisory about 30 hours after the sweep began, covering Mk3 units before widening it to Mk4, Mk5 and Q models.
Patching alone does not help, since seeds already made on vulnerable firmware stay guessable.
Read Next: Foldable iPhone Rumors Get Specific: $2,500, No Face ID, No Telephoto






