Coldcard exploit drives record OKX inflows as users rethink self custody

By crypto.news | Created at 2026-08-04 14:25:01 | Updated at 2026-08-04 23:50:17 9 hours ago

OKX has reported record inflows to its centralized exchange following the Coldcard hardware wallet exploit, as the company says users are increasingly prioritizing managed custody after one of the largest known Bitcoin wallet security incidents.

Summary

  • OKX says it has recorded record exchange inflows after the Coldcard hardware wallet exploit prompted some users to move assets from self custody.
  • The exchange said it prevented $26.3 million in scam related losses and protected more than $1.1 billion in customer assets during the first half of 2026.
  • Galaxy Research has confirmed thefts totaling 1,596 Bitcoin across three attack waves, with losses potentially reaching 2,055 Bitcoin if a fourth wave is verified.
  • The Coldcard flaw has renewed calls from security experts for independent testing of hardware wallet firmware and seed generation.

According to The Block, OKX Chief Compliance Officer Jonathan Brockmeier said customer behavior has changed noticeably in the wake of the Coldcard attacks, with the exchange recording unusually high inflows as users move assets away from self-custody.

“We’re seeing record levels of inflows now to centralized exchanges post-Coldcard,” Brockmeier told the publication. “It’s interesting — it’s sort of the flip side of FTX. FTX happens, and everybody moves their money into self-custody, and it’s coming back now.”

He said managing private keys requires users to take responsibility for their own security, while exchanges can offer dedicated security teams and automated monitoring systems. 

Brockmeier explained that OKX uses layered security controls supported by artificial intelligence to identify suspicious behavior before customers are affected, while still allowing users to choose self-custody if they prefer.

Coldcard exploit has changed custody decisions

The comments come as investigators continue tracking losses tied to the Coldcard hardware wallet vulnerability, which has become one of the largest known Bitcoin thefts linked to a flaw in wallet seed generation.

Galaxy Research said on Aug. 4 that it has confirmed the theft of 1,596 BTC from about 7,300 addresses across three verified attack waves. The firm added that the total could increase to roughly 2,055 BTC, worth nearly $130 million, if a fourth suspected wave receives sufficient confirmation from affected wallet owners.

Earlier blockchain analysis had estimated larger on-chain losses across four observed waves, but Galaxy narrowed its confirmed figures after distinguishing verified victim reports from blockchain observations. According to the research firm, investigators continue refining address mapping while coordinating with cryptocurrency exchanges, cyber investigation groups and U.S. law enforcement agencies.

Galaxy also reported that roughly 90% of the stolen Bitcoin has not moved since the attacks, giving investigators additional time to monitor the funds if they begin moving through exchanges or other services.

OKX says AI has prevented millions in scam losses

Alongside the change in customer behavior, Brockmeier told The Block that fraud prevention has become a growing focus for the exchange as digital asset scams and exploits continue affecting users.

According to figures shared by OKX, the exchange prevented $26.3 million in scam-related losses during the first half of 2026 by stopping suspicious transfers before they were completed. The company also said it protected more than $1.1 billion in customer assets belonging to over 500,000 users during the same period.

Brockmeier said the exchange has expanded its use of artificial intelligence to monitor blockchain activity for patterns associated with compromised devices, account takeovers and social engineering attacks before customer funds leave the platform.

He added that security preferences should vary depending on each customer’s needs. Users who want additional protection can choose stricter account controls even when the exchange’s internal systems do not classify their accounts as high risk, he said.

OKX also told The Block that its investigative unit includes former law enforcement officials, including former U.S. Drug Enforcement Administration personnel and a principal agent involved in the Silk Road investigation.

Coldcard flaw remained unnoticed for years

The attacks originated from a vulnerability that Coinkite disclosed last week after determining that affected Coldcard firmware generated wallet seeds using a deterministic pseudo-random number generator instead of the intended hardware-backed true random number generator.

According to Coinkite’s technical review, the flaw was introduced in March 2021 while engineers integrated a new cryptographic library into the wallet firmware. Although the hardware random-number generator remained active elsewhere in the software, wallet creation mistakenly relied on MicroPython’s deterministic generator, reducing the strength of newly created seed phrases.

Block’s Bitcoin engineering and security team independently reached the same conclusion after reviewing the firmware. The company said vulnerable devices called the deterministic MicroPython fallback rather than the STM32 hardware random-number generator during seed creation, although it noted that it had not completed empirical testing across every affected model before publishing its findings because reports of active theft had already surfaced.

Coinkite estimates that affected Mk2 and Mk3 devices may provide roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q models may generate around 72 bits, well below the intended 128-bit security level.

Emergency firmware updates have since been released for every affected product line. Coinkite has stressed, however, that updating firmware protects only wallets created after the fix. Users whose seed phrases were generated with vulnerable firmware have been instructed to create entirely new wallets, verify a receiving address with a small test transaction and move funds only after confirming the transfer.

The company also said wallets created using at least 50 fair private dice rolls are not exposed by the random-number-generation flaw alone, although it still recommends migrating vulnerable seeds even when users employ a strong BIP-39 passphrase.

Industry has called for independent firmware verification

Separate comments from Kraken Chief Security Officer Nick Percoco have renewed discussion around how hardware wallets are tested before reaching customers.

Writing on X earlier this week, Percoco argued that manufacturers should not be the only parties validating how production firmware generates wallet seed phrases. He said independent testing should confirm that approved hardware entropy sources are actually used during wallet creation instead of relying primarily on code reviews or vendor audits.

To support that argument, Percoco pointed to NIST SP 800-90B, which governs validation of true random-number generators used in cryptographic systems, and Germany’s BSI AIS-31 framework. According to him, comparable end-to-end verification is not routinely performed for hardware wallet firmware despite the importance of secure seed generation.

The latest Coldcard incident has unfolded against a year of continued security breaches across the cryptocurrency industry. Last year, Dubai-based exchange Bybit lost approximately $1.4 billion in the largest recorded cryptocurrency theft, while blockchain security firm Blockaid reported that crypto projects lost more than $1 billion to hacks during the first half of 2026 as the number of verified exploits reached a record level.

Read Entire Article