SUNDAY, AUG02
1. Bitkey holds, 2. Scan repos now, 3. Never type your seed, 4. Galaxy maps the sweep
From Proto and Bitkey - part of the Bitcoin ecosystem at Block, Inc.
1. bitkey
Block’s Clay Garrett shared initial findings on a reported Bitkey vulnerability and recommended that users continue using Bitkey normally, according to his post on X. The vulnerability would require exceptional circumstances to exploit and can only occur at a specific narrow time during inheritance setup; even if an attacker exploited it — including exploiting TLS internet security — they would not have enough cryptographic material to access funds. Block’s assessment is no risk of remote drains or immediate funds loss. A patch has been submitted to both app stores and a full technical report is forthcoming. The team credited @1440000bytes for responsible disclosure. For a self-custody audience, the Bitkey disclosure is a useful contrast to the Coldcard incident unfolding in parallel: a vulnerability found through responsible disclosure, assessed publicly as presenting no remote drain risk, with defense-in-depth cited as the reason an attacker reaching the vulnerable window still could not access funds. Not every hardware wallet disclosure this weekend is a funds emergency — the contrast in risk profile matters.2. scan
Rob Hamilton, contributor to the Bitcoin ecosystem, is urging engineers who work on bitcoin-related software to use OpenRouter or opencode to run Kimi K3 — an open-weight model released Monday — against any bitcoin-related internal codebases and public repositories for vulnerability scanning, according to his post on X. He has been scanning open-source repos himself and finding issues he is passing along to maintainers, noting that K3 one-shots full vulnerability reports, and that the timing of Kimi K3’s open-weight release against the Coldcard issues unfolding is not a coincidence. For a freedom-tech audience, the call is a direct application of the week’s open-weights thesis to a live security emergency: the same argument that open models make better defenders — demonstrated by Hugging Face using GLM 5.2 to contain the OpenAI incident — now has engineers scanning bitcoin infrastructure with open-weight AI in the immediate aftermath of the largest hardware-wallet compromise in the ecosystem’s history.3. jade
Blockstream Jade issued a scam warning to the bitcoin self-custody community as emotions run high following the Coldcard incident, according to the official Blockstream Jade post on X. The rules listed: never type your recovery phrase into any website, form, checker, or tool; no one legitimate will DM you first asking for seeds or offering to help you migrate; only use official communication channels and software you already trust. Slow down, verify every step, and a few extra minutes of caution is always worth it. For a freedom-tech audience, Blockstream Jade’s warning is the operational complement to Saifedean’s migration checklist and O’Beirne’s dice verification: the technical work of a proper migration matters less if a social engineer intercepts the process and collects the seed phrase directly. Hardware-wallet incidents reliably produce a second wave of theft through phishing and impersonation, and the community is in that window right now. Any unsolicited contact about Coldcard recovery — by DM, email, or any channel — should be treated as an attack.4. losses
Galaxy Research mapped the flow of funds for the Coldcard vulnerability, finding that 1,196 addresses were drained for 1,082.65 bitcoin worth approximately $70.2 million in a 41-minute window on July 30 — roughly 30 hours before Coinkite’s public advisory, according to the Galaxy Research post on X. Every sweep paid an identical hardcoded 30.0 sat/vB fee, a 30 to 75 times overpay versus the market median that week, with no change output — consistent with an automated tool spending keys it already held. Victims were 1,183 native segwit BIP-84 addresses, 7 BIP-49, and 6 BIP-44, consistent with multi-path key scanning. Proceeds consolidated into four addresses and have not moved since. For a self-custody audience, the forensics confirm the attack was pre-planned and automated, and the stolen funds are fully traceable — sitting unmoved in four known addresses — creating an unusual situation where the full scope of the theft is publicly visible but recovery is structurally impossible without the attacker’s cooperation.Consider subscribing and sharing OP_Daily with your community.


