Market Update: Wallet theft calls Bitcoin self-custody into question A serious security incident has shaken the Bitcoin world: attackers were able to steal more than 1,500 bitcoins because of a firmware flaw affecting certain Coldcard hardware wallets. Bitcoin itself was not hacked. The weakness concerned the generation of private keys on the affected devices. The incident shows that even established custody solutions cannot provide absolute security. At the same time, the Bitcoin price has proved remarkably resilient: despite the theft, Strategy’s sale of bitcoins and continued uncertainty surrounding the CLARITY Act in the United States, Bitcoin remains above USD 60,000.Chart: Galaxy Research attributes 1,596 stolen bitcoins from around 7,300 addresses to the Coldcard attack with a high degree of confidence. Including suspected but unconfirmed cases, the loss could rise to approximately 2,000 bitcoins, equivalent to USD 130 million. | Source: Galaxy ResearchThe weakness affected key generation, not BitcoinHardware wallets are regarded as a particularly secure custody solution for private individuals. They generate and protect the private keys used to authorise Bitcoin transactions. The bitcoins themselves are not stored on the device but remain part of the decentralised network.In the current incident, the vulnerability was located in the firmware of certain Coldcard devices. A programming error meant that the private keys were not generated with the intended level of randomness. This allowed attackers to narrow the potential key space, reconstruct affected keys and transfer the associated bitcoins.The incident was therefore not an attack on the Bitcoin protocol. It affected an application that manages access to the protocol. For those affected, this distinction is technically important, although it does not change the loss of their bitcoins.Why randomness is critical for BitcoinA private Bitcoin key can be selected from 2256 possible combinations. This corresponds to approximately 1077 different values. By comparison, the number of atoms on Earth is estimated at around 1050.Given this vast universe of possibilities, a correctly generated private key cannot realistically be guessed, even with powerful computers. This security depends, however, on the source of randomness providing sufficient entropy.That was precisely the problem with the affected devices. The firmware flaw significantly reduced the number of keys that could actually be generated. A task that would normally be computationally infeasible consequently became solvable for the attackers.The incident highlights the difference between Bitcoin’s cryptographic security and the security of individual implementations. Even a robust protocol cannot prevent defective code, inadequately tested firmware or weaknesses in key generation.A wake-up call for the entire industryThe theft is a wake-up call for hardware-wallet manufacturers and providers of applications that interact with the Bitcoin protocol. It is at least striking that the incident coincides with the broad release of the new open-source AI model Kimi K3. Powerful and freely available AI models lower the technical barriers to automated vulnerability discovery.This does not necessarily establish a direct causal link between Kimi K3 and the Coldcard incident. It does, however, underline how quickly attackers’ capabilities are developing. Developers and providers of security-critical applications should therefore use the same AI models to review their systems continuously and make them more secure. What users should review nowAnyone who holds bitcoins in self-custody should now be particularly diligent in reviewing their setup regularly. This includes the devices and applications used, installed firmware versions, secure storage of recovery words and the provenance of the software involved.For larger holdings of digital assets, an institutional custody solution may be appropriate. Relevant considerations include high standards for key generation and entropy, clearly separated access rights, multi-stage approval processes and robust control and contingency procedures. Self-custody and institutional custody have different advantages and disadvantages. The appropriate solution depends on individual requirements, capabilities and risks. Bitcoin holds firm despite negative newsBitcoin continues to trade above USD 60,000 and has so far reacted with remarkable composure to the latest headwinds.The wallet theft was not the only adverse development. On Monday, Strategy announced that it had sold 1,638 bitcoins during the previous week, adding to selling pressure.Meanwhile, the prospects of the CLARITY Act being passed soon are diminishing. The regulatory framework is intended to establish clearer responsibilities and rules for the US crypto market.Chart: Changes in market expectations regarding the Digital Asset Market CLARITY Act of 2025 (H.R. 3633) being enacted by the end of 2026. The probability shown is based on prices in the Polymarket prediction market and does not represent an official assessment. | Source: Polymarket; legislative reference: Congress.gov.The reasons for Bitcoin’s current stability can only be a matter of speculation. However, the market’s behaviour also allows for a more positive interpretation. If even a succession of negative headlines cannot push the price materially below USD 60,000, this could indicate that Bitcoin is generally tending towards oversold conditions. ConclusionThe theft of more than 1,500 bitcoins was not a failure of the Bitcoin protocol, but a serious weakness at the custody layer. Even so, the incident affected a fundamental pillar of practical Bitcoin use: the secure generation and management of private keys.For users, the incident is a reason to review their custody setup critically. Developers are also under growing pressure to adapt their security processes to an environment in which powerful AI tools are opening up new possibilities for attackers.From a market perspective, the reaction remains notably restrained. If Bitcoin defends the area above USD 60,000 despite the current headwinds, this would indicate relative strength. Important legal informationThis publication is intended for information and marketing purposes only, and does not constitute investment advice or a specific individual investment recommendation. It is not a sales prospectus and does not constitute a request, an offer, or a recommendation to buy or sell investment instruments or investment services, or to engage in any other transaction. Maerki Baumann & Co. AG does not provide legal or tax advice. Investors are therefore advised to obtain independent legal or tax advice concerning the suitability of such investments, since their tax treatment depends on the personal circumstances of the investor in question and is subject to change at any time. Maerki Baumann & Co. AG holds a Swiss banking licence issued by the Financial Market Supervisory Authority (FINMA). This publication is expressly not intended for persons domiciled in Germany or so-called U.S. persons. Editorial deadline: 5 August 2026Maerki Baumann & Co. Ltd.Dreikönigstrasse 6, CH-8002 ZurichT +41 44 286 25 25, info@maerki-baumann.chmaerki-baumann.ch | archip.ch