Good morning everybody.
Bitcoin is still parked around $64,000, and once again the biggest story has nothing to do with price.
It’s Coldcard.
What initially looked like a bad firmware bug has turned into one of the largest hardware wallet failures we’ve seen in years, and the estimated losses continue climbing.
The Coldcard Losses Keep Growing
Yesterday’s estimate was roughly $88 million.
Today, researchers from Galaxy and K33 believe the exploit has now involved at least 15 attackers, with confirmed or estimated losses exceeding $100 million. Some estimates now approach $130 million, representing nearly 1,600 Bitcoin stolen from approximately 7,300 wallet addresses.
Those numbers tell a bigger story.
Most of those wallets probably weren’t holding hundreds of Bitcoin.
They were holding fractions of a Bitcoin.
Maybe 0.1 BTC.
Maybe 0.3 BTC.
Maybe half a Bitcoin that someone had been slowly accumulating for years.
For a lot of those people, that wasn’t just another investment account.
That was their savings.
That was the money they hoped would eventually pay off their mortgage or help fund retirement.
Now it’s gone.
If You’re Selling Security, You Better Deliver Security
I know the counterargument.
People will say holding companies fully responsible discourages innovation.
Good.
It should.
If you’re building a hardware wallet whose entire purpose is protecting customer assets, security isn’t an optional feature.
It’s the product.
If your product fails because of your own implementation, customers shouldn’t be left carrying the loss while the company simply goes bankrupt and disappears.
Crypto has already learned this lesson once.
After exchange hacks became common, companies started creating insurance funds and reserve programs. Binance’s SAFU fund became one of the best-known examples.
The industry understood that if customers were expected to trust exchanges with billions of dollars, those exchanges needed to stand behind their own mistakes.
Hardware wallet manufacturers shouldn’t be held to a lower standard.
The Industry Is Quietly Moving Toward Institutions
While Coldcard dominates the headlines, traditional financial companies continue expanding their blockchain infrastructure.
Circle announced the founding validator group for its new ARC blockchain, including organizations such as BlackRock, Visa, Mastercard, DTCC, Galaxy, ICE, and MoneyGram.
ARC is an Ethereum-compatible Layer 1 network that uses USDC as its native gas token while offering sub-second finality and optional privacy features.
Circle also reported approximately $701 million in second-quarter revenue and reserve income, an increase of 7% year over year.
The trend is becoming obvious.
Large financial institutions are no longer experimenting with blockchain.
They’re building on it.
Visa and Mastercard Keep Expanding Stablecoins
Visa announced it is expanding stablecoin capabilities through a partnership with Zero Hash, allowing eligible clients to fund merchant accounts and send payouts using stablecoins through Visa Direct.
Mastercard is also testing its Crypto Credential framework with Borderless.xyz, creating standardized identity and compliance signals for cross-border stablecoin payments spanning more than 100 countries.
This is exactly the type of adoption that often gets overlooked.
Most consumers won’t even know they’re using blockchain.
They’ll just notice that payments arrive faster.
One Bitcoin ETF Is Closing
Hashdex announced it will liquidate its DeFi Spot Bitcoin ETF after August 17.
The fund reportedly held only about $14.7 million in net assets, making it one of the smallest spot Bitcoin ETFs in the United States.
Not every ETF succeeds.
Competition is intense, and products that fail to attract assets eventually disappear.
That’s normal.
The Market Is Already Pricing In a CLARITY Delay
Bitwise CIO Matt Hougan said crypto will be fine even if Congress misses this week’s deadline for the CLARITY Act.
I generally agree.
The legislation is important.
Clear rules matter.
But Bitcoin existed before the CLARITY Act, and it will continue existing regardless of whether Congress acts this week or next year.
The market increasingly appears to believe lawmakers won’t meet the current timeline anyway.
Physical Bitcoin Robberies Are Increasing
Three Missouri men have been charged in connection with an alleged plot to kidnap a Bitcoin holder in Connecticut and force the victim to transfer cryptocurrency.
According to prosecutors, the suspects rented vehicles, obtained air rifles, conducted surveillance on the target, and ultimately abandoned the plan before carrying it out.
This is another reminder that personal security matters just as much as cybersecurity.
The larger Bitcoin becomes, the more criminals will look beyond hacking and toward physical coercion.
World Chain Wants Faster Block Production
World Chain announced a significant Layer 2 upgrade that aims to dramatically improve throughput by allowing validators to verify independent transactions in parallel while blocks are still being built.
Activation is currently planned for August 17.
If you’ve never read Mastering Bitcoin by Andreas Antonopoulos, it’s still one of the best technical explanations of how blocks, mining, and Bitcoin’s architecture actually work.
Understanding how blocks are built makes stories like this much easier to follow.
Crypto Prices
Bitcoin: $64,000
Ethereum: $1,866
BNB: $599
USDC: #5
XRP: $1.05
Solana: $73.70
TRON: $0.328
Hyperliquid: $56.89
Dogecoin: $0.069
Total Crypto Market Cap: $2.19 trillion
Fear & Greed Index: 38 (Fear)
My Take
The Coldcard story isn’t just another crypto hack.
It’s a trust failure.
When customers buy a hardware wallet, they’re purchasing one thing above everything else: confidence that their private keys are safe.
If a flaw in the company’s own software leads to more than $100 million in losses, that confidence disappears.
The crypto industry has spent years telling people to move assets off exchanges and into self-custody.
That advice is still generally sound.
But self-custody only works if the tools designed to protect users actually do what they’re promise to do.
When they don’t, companies shouldn’t be able to shrug, declare bankruptcy, and move on.
If security is your business, security has to be your responsibility.


