On July 30, 2026, somebody started emptying bitcoin wallets that nobody had touched.

There was no phishing email. No leaked password. No exchange failure. Nobody got physical access to a device. The wallets in question were hardware wallets, the kind people buy specifically so that their keys never touch an internet connected computer, and they were drained anyway, from a distance, using arithmetic.

That is worth sitting with for a second, because it breaks the mental model most people carry about crypto security. And then it is worth running through our framework, because the answer our framework gives is instructive in a way that "our model rates this asset highly" never is.

What happened

The devices were Coldcards, made by Coinkite. The flaw was in how they created a seed phrase, the string of words that a wallet turns into your private key.

A hardware wallet is supposed to generate that seed using a dedicated hardware source of randomness. A firmware change made in March 2021 quietly routed seed creation somewhere else. As reported on August 3, 2026, the firmware "relied on the chip's serial number and clock registers, reducing the potential keys from cryptographically vast to countable." One report described affected Mk3 devices as offering "roughly 40 bits of effective security, while later affected models provided about 72 bits."

What that means in plain terms: the wallet was still generating a key, but it was drawing it from a pool small enough that somebody willing to do the computation could work out which one it had picked. Not guess a password. Reconstruct the key.

The flaw shipped in March 2021. It was exploited starting July 30, 2026. That is five years in which every seed created on an affected device looked exactly as strong as it was supposed to be and was not.

The numbers, and why they disagree

This is a case where the reported totals are genuinely worth showing side by side rather than averaging into one confident figure.

  • An early report put losses around $38 million.

  • By August 2, 2026, the figure reported was about $88.6 million, roughly 1,367 BTC, across 4,585 tracked addresses, in three waves.

  • An August 3, 2026 report described the same 1,367 BTC as worth about $86 million, across more than 4,500 cold storage addresses.

  • An August 7, 2026 report put the bitcoin linked to the theft at roughly 2,055 BTC, about $130 million, and noted that roughly 90 percent of it had not moved from the addresses it was sent to.

  • An August 17, 2026 report put the total at $115 million, valued at bitcoin prices at the time of each individual theft, and described the largest single wave as 1,082.65 BTC taken from 1,196 wallets inside a 41 minute window between 1:10 and 1:51 UTC on July 30.

Every one of those is a real, sourced, dated number. They do not agree, and the reason they do not agree is not that somebody is lying. The total was still growing. The bitcoin price was moving. Different trackers counted different address sets, and one of them valued each theft at the price on the day it happened rather than at today's price.

We are a ratings company, so we will say the obvious thing rather than skip it: a figure without a date attached to it is not a figure. That applies to loss totals in a news story and it applies to a score on our own website, which is why every number we publish carries the date it was true.

Now run it through our framework

CryptoGrade scores each asset we cover from 0 to 100 across six weighted dimensions, and separately runs nine hard disqualifier gates that can force a grade down regardless of the score. The dimensions and their weights:

  • Tokenomics and Value Accrual, 28 percent

  • On-chain Usage and Economics, 22 percent

  • Security, Decentralization and Durability, 18 percent

  • Ecosystem and Moat, 12 percent

  • Relative Valuation, 12 percent

  • Market Structure, 8 percent

And the nine gates: anonymous or unaccountable team; unaudited or previously exploited contracts; unsustainable or Ponzi like yield; low float plus high FDV plus imminent unlocks; supply concentrated in insider wallets; thin or wash traded liquidity; unregistered security or regulatory kill profile; custody that can freeze, mint or seize; history of rug, abandonment or exploit.

Three of those look, at a glance, like they should have caught this.

"Unaudited or previously exploited contracts." That is a question about the asset's own code. Bitcoin's code was not the thing that failed here.

"Custody that can freeze, mint or seize." That gate asks whether the issuer or protocol behind an asset retains a built in ability to freeze your balance, print more supply, or take funds back. It is a question about the asset's design, not about the device in your drawer. Bitcoin's answer to that question did not change on July 30.

"History of rug, abandonment or exploit." Again, the asset's history. A wallet vendor's firmware is not the asset's history.

And the closest dimension, Security, Decentralization and Durability at 18 percent of the score, scores the durability of the network itself: whether it keeps producing blocks, how distributed its validation is, how it has held up across cycles. Bitcoin's network did all of that flawlessly throughout. The theft transactions were valid. The network processed them correctly. From the protocol's point of view, nothing went wrong at all.

So here is the honest answer. Not one of our six dimensions and not one of our nine gates reads the firmware of a third party hardware device. There is no input in our framework that could have seen this, and there was never going to be one.

What our own data shows, and what it does not

Bitcoin is rank 1 in our ranking. In our snapshot for September 10, 2026, pulled at the public tier, which is the logged out view showing the top 10 assets by rank and nothing underneath, BTC carries a score of 91.2, tier T1, tier name Prime. Under our published bands that is A / Prime, the top band, 80 and above.

We keep every daily snapshot in a public repository, so this is checkable rather than assertable. Across every snapshot we hold, from August 30 through September 10, 2026, BTC has been rank 1 and Prime in all of them. Its score has moved once in that window, on September 8, carrying our own published change of minus 0.9.

Two limits on that, stated rather than glossed. Our snapshot history starts on August 30, 2026, which is a month after the exploit began, so we cannot show you what our score for bitcoin was during July. We are not going to reconstruct it. And we are attaching no cause to the one move we can see. Our logged out data carries the score, the band and the dated change, and nothing about why. We would rather say that than fill the gap with a plausible story.

The thing worth taking away

A grade is a claim about an asset. It is not a claim about your custody of it.

Those are two separate questions and a rating answers only the first one:

  • Is this asset well constructed? How does its supply and value accrual work, how much is it actually used, how durable is its network, how rich is its ecosystem, how is it priced against comparable assets, how does it trade. That is what our score is.

  • Is the thing you are holding it in going to keep holding it? Your wallet, your device, your firmware version, your backup, your exchange. That is a completely different question, and no asset rating anywhere answers it.

Everyone whose Coldcard was emptied owned an asset that scored well. The asset kept scoring well. It is still rank 1 in our ranking today. The grade was right, and it was irrelevant to what happened to them, because it was never answering that question.

If you have ever thought "I did my research on what to buy, so I am covered," this is the incident that shows the gap. Research on what to buy and research on how to hold it are two separate pieces of work, and the second one is not optional just because the first one went well.

Three questions this incident makes checkable

None of these is about which asset to own. They are about the layer a rating does not cover.

1. Does your wallet vendor publish what went wrong, in detail, when something goes wrong? Coinkite published a security advisory naming the affected models and firmware range. Whether a vendor tells you the mechanism or gives you a vague reassurance is something you can check before you need it, and it is the same test we ask readers to apply to us.

2. Does the fix actually fix your situation, or only future ones? This is the detail most people miss in this story. Installing the patched firmware does nothing for a seed that was already created on a vulnerable build. Coinkite's own guidance is that affected users have to create an entirely new seed, verify the replacement wallet with a test transaction, and move their bitcoin across. A patch that closes the door is not the same as a patch that undoes what already happened, and reading which kind you have been given is on you.

3. When did your key come into existence, and on what? Almost nobody knows the answer. In this case the difference between an affected wallet and an unaffected one was which firmware version was running on the day the seed was created, going back five years. That is a fact about your own setup that is worth writing down while you still remember it.

We are not telling you what to do about any of that. We are telling you which questions our grade does not answer, so that you know to go and answer them somewhere else.

What we are not saying here

We are making no attribution. This piece does not claim that the Coldcard exploit caused any change in any CryptoGrade score, and it does not claim that it did not. Our published change for bitcoin carries a number and a date and nothing more, and the dimension level breakdown behind a score is not part of what we quoted here.

We are also not saying anything about bitcoin's future. We publish how an asset scored against our framework, on a date. That is a description, not a prediction, and it is certainly not advice about your situation, which we do not know anything about.

See it yourself

The top 10 crypto asset scores (powered by AI) are available for free at https://cryptograde.ai

A free account opens up the full top 200, ranked by CryptoGrade's own score, highest to lowest, along with the research behind each one.

If you want the mechanics behind how a score is built in the first place:

Reply

Avatar

or to participate