Ledger and Trezor respond that user funds are safe, competitor Coldcard wallet firmware vulnerability caused $70 million bitcoin stolen in 41 minutes
Key points:
Ledger, Trezor, Bitkey, Jade and Tangem all said that Coldcard firmware vulnerability does not affect their devices. [TAG
The attacker stole 1,082.65 bitcoins from 1196 addresses on July 30, almost double the initial estimate. [TAG
Bitcoin market sentiment fell to an all-time low with a net outflow of $265.4 million from spot ETFs on July 31.
Ledger and Trezor Response: Not related to Coldcard vulnerability
Ledger means not affected by Coldcard Mk3 vulnerability, and its security element chip has a certified random number generator built in. Trezor told users on Friday that the problem originated from Coinkite's own custom firmware, which Trezor did not use. Bitkey, Jade and Tangem also quickly reassured users within hours.
Trezor comes with a warning: If a user creates a seed on an affected Coldcard device and subsequently restores it on another device, there is still a risk because weak randomness will be transferred with the seed itself.
Bitcoin market sentiment drops to record low
Galaxy Research linked the attack to a 41-minute a.m. time window on July 30, involving a total of 1,082.65 bitcoins in 1196 addresses. This total is almost double the number of 594 bitcoins previously reported. Sanitation subsequently recorded a ratio of bullish to bearish comments of 0.58, the lowest in Bitcoin history. The flow of funds follows changes in market sentiment. The U.S. spot Bitcoin ETF had a net outflow of US$265.4 million on July 31, ending two consecutive days of capital inflows. Among them, BlackRock's IBIT products flowed out of US$122.7 million, followed closely by Fidelity's FBTC products, with an outflow of US$54.8 million. Bitcoin has remained at around $63,000 since falling nearly 3% last Friday.
Ido Ben-Natan, CEO of security company Blockaid, believes that most of the cryptocurrency losses in 2026 are due to key leaks, not smart contract vulnerabilities. Strive company Joe Burnett wrote that the incident could permanently change the way investors view self-custody.
Coldcard Firmware Vulnerability Timeline
The vulnerability was hidden undetected for five years. Block engineers traced it back to a code submission on March 1, 2021 that was released with firmware version 4.0.0, quietly routing seed generation to software alternatives. The effective entropy of Mk3 devices drops to about 40 bits, while standard seeds should have 128 bits. Coinkite made its first public announcement about 30 hours after the attack began, involving Mk3 devices, and later expanded its scope to include Mk4, Mk5 and Q-series models. Just patching the firmware will not help, because seeds that have been generated on vulnerable firmware can still be cracked.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC