OKX Reports Record Exchange Inflows After Coldcard Exploit Drains Over $100M in Bitcoin
A firmware flaw dating to March 2021 in Coldcard hardware wallets has triggered the largest single-day Bitcoin exchange deposit event since the FTX collapse, as roughly 7,300 wallet addresses lose an estimated 1,596 BTC to ongoing theft.
OKX told The Block on August 4 that it is seeing what it described as record inflows to its centralized exchange platform following the Coldcard hardware wallet exploit, which went public on July 30, 2026. The surge represents a direct reversal of the post-FTX trend that pushed Bitcoin holders toward self-custody. On July 31 alone, net Bitcoin deposits across major exchanges reached 11,163 BTC, the highest single-day figure recorded since November 2022, according to on-chain data from TimechainIndex. OKX received 1,291 BTC of that total, ranking fourth behind River (3,679 BTC), Binance (3,224 BTC), and Kraken (2,848 BTC).
The panic deposits trace back to a critical firmware defect in Coldcard devices manufactured by Canadian company Coinkite. A build configuration error introduced on March 1, 2021 caused affected devices to silently fall back to a software pseudorandom number generator (specifically MicroPython's Yasmarang fallback PRNG) instead of the STM32 hardware chip's built-in entropy source. The result: seed phrases generated on vulnerable devices contain far less randomness than required. Mk2 and Mk3 devices produced seeds with roughly 40 bits of effective entropy instead of the 128 bits a secure 12-word BIP-39 seed (a standardized recovery phrase format) requires. Mk4, Mk5, and Q devices fared slightly better at approximately 72 bits, but remain exploitable. Attackers who can narrow down a device's unique identifier and timer state can reconstruct candidate seed phrases entirely offline, then verify them against Bitcoin's public transaction history without ever touching the physical device. Coinkite shipped patched firmware on July 31 but issued a clear warning: updating firmware does not fix a seed that was already generated under the flaw. Affected users must create a new seed on patched firmware and transfer funds to the newly generated addresses. Devices running Mk2 or Mk3 firmware versions v4.0.0 through v4.1.9, Mk4 or Mk5 firmware versions before v5.6.0, or Q firmware versions before v1.5.0Q are affected and require immediate action. Coldcard owners who cannot immediately migrate should know that adding a strong BIP-39 passphrase creates a separate wallet layer that a seed-only attacker cannot reach; Coinkite still recommends full migration but acknowledges the passphrase as a partial protective measure in the interim. Coinkite's other products, including TAPSIGNER, OPENDIME, and SATSCARD, are not affected by this flaw.
The theft unfolded in at least three documented waves. The first, on July 30, swept 1,082 BTC from 1,196 addresses in approximately 41 minutes. Two subsequent waves hit through August 2, bringing confirmed losses to roughly 1,596 BTC. The third wave, spanning August 1 through 2, involved a significant tactical shift: each victim's funds moved to individual destinations rather than shared collector addresses, outputs used pay-to-witness-script-hash structures consistent with multisig or timelock arrangements, and attackers batched approximately six victims per sweep. Researchers flagged this pattern as potentially indicating new operators or upgraded operational security. Galaxy Research estimates a potential fourth wave could push total losses to 2,055 BTC, or approximately $130 million. At least 15 separate actors are now actively draining vulnerable wallets, fragmenting what began as coordinated sweeps into open, opportunistic exploitation. Galaxy also notes that roughly 90 percent of stolen coins have not yet moved from attacker wallets, leaving a narrow window for exchanges to freeze flagged addresses. Coinkite CEO NVK offered a pointed observation about how the flaw was likely found: "AI-assisted code review can now find latent bugs at a speed outpacing even the industry's most seasoned experts," he said in a statement to Bitcoin Magazine. Notably, the company's own AI-assisted reviews had not caught the defect before it was externally discovered.
The retail response showed up clearly in on-chain metrics. CryptoQuant data cited by CoinDesk shows that Bitcoin deposits under 10 BTC, a proxy for individual rather than institutional transfers, hit 7,300 BTC on July 31, the highest reading since February 6, 2026. Active Bitcoin addresses nearly reached 1 million that day. "Daily exchange deposits of Bitcoin transfers under 10 BTC spiked," said Julio Moreno, Head of Research at CryptoQuant. "Could be related to the Coldcard hack, as people move their holdings looking for safety." The sentiment shift was sharp enough to prompt broader commentary. "This is the worst hit in Bitcoin history to the most knowledgeable and 'properly secured' bitcoiners," said Bitcoin commentator Guy Swann, speaking to CoinDesk. Lorenzo Valente of ARK Invest framed the trade-off plainly: "Consumers have traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk."
The event carries particular weight in markets where self-custody has served as a practical shield against institutional or regulatory risk. India ranks first in Chainalysis's 2025 Global Crypto Adoption Index, and Pakistan ranks third. Both countries have significant populations of privacy-conscious Bitcoin holders who prefer self-custody as a hedge against regulatory overreach and currency depreciation. For those users, the Coldcard flaw is not an abstract security story; it is a direct financial threat to the setup they considered most secure. Pakistani users who migrate to custodial exchanges in response face a distinct new set of considerations: KYC requirements and government access to exchange data in Pakistan's regulatory environment mean that moving to centralized platforms is not a straightforwardly safer path. Across Sub-Saharan Africa, Nigeria and Kenya have driven regional crypto growth largely through peer-to-peer Bitcoin markets. Many users in those countries moved toward self-custody after the FTX collapse in 2022, contributing to a regional total of approximately 75 million crypto wallet users by 2025, nearly double the figure from two years prior. The Coldcard exploit now presents the opposite pressure for that fast-growing base. OKX has been expanding its footprint across India, Turkey, and Sub-Saharan Africa. The exchange's claim of preventing $26.3 million in scam-related losses during the first half of 2026, supported by its February adoption of Chainalysis Alterya for real-time fraud detection, positions it well to capitalize on that narrative shift.
The exploitation is ongoing as of publication. Coinkite and Galaxy Research are providing active updates, and current loss figures should be treated as a floor rather than a final number. Any Coldcard user whose seed was generated between March 2021 and July 31, 2026 on a vulnerable firmware version should treat that seed as compromised and migrate funds immediately. Seeds created using at least 50 fair, independent dice rolls are the one documented exception to that guidance.