
OKX logged its highest-ever inflows after the Coldcard exploit, compliance chief said. Galaxy confirmed 1,596 BTC stolen across three attack waves. 90% of stolen coins have not moved.
The Coldcard hardware wallet exploit has pushed users back toward centralized exchanges in what OKX's chief compliance officer called the reverse of the FTX dynamic. Jonathan Brockmeier told The Block the exchange recorded its highest-ever inflows after the vulnerability became public, as customers moved assets away from self-custody.
"We're seeing record levels of inflows now to centralized exchanges post-Coldcard," Brockmeier said. "It's interesting -- it's sort of the flip side of FTX. FTX happens, and everybody moves their money into self-custody, and it's coming back now."
The shift reflects a practical trade-off, he said. Managing private keys means users take full responsibility for their own security. Exchanges offer dedicated teams and automated monitoring. OKX uses layered security controls supported by AI to flag suspicious behavior before customers are affected, Brockmeier said, while still letting users choose self-custody if they prefer.
The vulnerability itself came from a firmware bug Coinkite traced to March 2021, when engineers integrated a new cryptographic library. Wallet creation mistakenly relied on MicroPython's deterministic pseudo-random number generator instead of the STM32 hardware-backed true random number generator. Block's Bitcoin engineering and security team independently confirmed the finding after reviewing the firmware.
Coinkite estimates affected Mk2 and Mk3 devices provide roughly 40 bits of effective entropy. Vulnerable Mk4, Mk5 and Coldcard Q models generate around 72 bits. The intended security level is 128 bits.
Galaxy Research said Aug. 4 that it has confirmed the theft of 1,596 BTC from about 7,300 addresses across three verified attack waves. The firm said the total could reach 2,055 BTC, worth nearly $130 million, if a fourth suspected wave receives sufficient confirmation from affected wallet owners. Roughly 90% of the stolen Bitcoin has not moved, Galaxy said, giving investigators additional time to track funds if they begin flowing through exchanges or other services.
Emergency firmware updates have been released for every affected product line. Coinkite stressed that updating protects only wallets created after the fix. Users who generated seeds with vulnerable firmware must create entirely new wallets, verify a receiving address with a small test transaction, and move funds only after confirming the transfer. Wallets created using at least 50 fair private dice rolls are not exposed by the random-number-generation flaw alone, Coinkite said, though it still recommends migrating vulnerable seeds even with a strong BIP-39 passphrase.
Kraken Chief Security Officer Nick Percoco argued this week that manufacturers should not be the only party validating how production firmware generates wallet seed phrases. He called for independent testing to confirm that approved hardware entropy sources are actually used during wallet creation, rather than relying primarily on code reviews or vendor audits. Percoco pointed to NIST SP 800-90B and Germany's BSI AIS-31 frameworks as standards that cover end-to-end verification for true random-number generators -- verification that he said is not routinely performed for hardware wallet firmware.
OKX said its investigative unit includes former law enforcement personnel, including former Drug Enforcement Administration agents and a principal agent involved in the Silk Road investigation. The exchange prevented $26.3 million in scam-related losses during the first half of 2026 by stopping suspicious transfers before they were completed, according to figures the company shared. Brockmeier said OKX has expanded its use of AI to monitor blockchain activity for patterns associated with compromised devices, account takeovers and social engineering attacks.
The broader crypto security picture remains grim. Dubai-based exchange Bybit lost approximately $1.4 billion last year in the largest recorded cryptocurrency theft. Blockaid reported that crypto projects lost more than $1 billion to hacks during the first half of 2026, with the number of verified exploits reaching a record level.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.