Two critical Bitcoin infrastructure exploits were disclosed this week: a Coldcard Mk3 firmware flaw that drained over $116 million from 5,200+ addresses and a BTCPay Server vulnerability that exposed Lightning node cr... Bitcoin’s price initially dipped nearly 3% but has since rebounded to around $64,000, reflecting...

Create a landscape editorial hero image for this Studio Global article: What critical vulnerabilities were disclosed this week in Bitcoin infrastructure — including the Coldcard Mk3 firmware exploit that has led. Article summary: Two critical Bitcoin infrastructure exploits were disclosed this week — the Coldcard Mk3 firmware RNG flaw that has drained over $116 million across 5,200+ addresses, and the BTCPay Server vulnerability that exposed Ligh. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fak
Two critical Bitcoin infrastructure exploits were disclosed this week, sending shockwaves through the crypto community. The Coldcard Mk3 firmware RNG flaw has drained over $116 million across more than 5,200 addresses, while a BTCPay Server vulnerability exposed Lightning node credentials, leading to active fund theft. The ecosystem responded with an AI-driven "Bitcoin Red Team" audit that uncovered 85 critical and 635 high-severity flaws across 390 open-source repositories, along with urgent patching and fund migration warnings from both vendors. Bitcoin's price initially dipped but has since rebounded to around $64,000, though traders remain cautious .
Root cause: A critical flaw in Coldcard firmware version 4.0.0, shipped in March 2021, caused the device to bypass its dedicated hardware randomness chip during seed generation. Instead of the expected 128+ bits of entropy, seeds were generated with only about 40 bits of effective security on Mk3 devices — making them trivially guessable by attackers who understood the weakness . The bug affected Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9, as well as Mk4, Mk5, and Q models prior to specific firmware updates
.
Scale of losses: Over $116 million in Bitcoin was stolen from more than 5,200 addresses across four waves of thefts . On July 30 alone, attackers drained 1,082.65 BTC (worth approximately $70.2 million) from 1,196 wallets in roughly 41 minutes — just 30 hours before Coinkite, the company behind Coldcard, publicly disclosed the vulnerability
. A second wave hit roughly 594 BTC from about 500 wallets, and subsequent waves brought the total losses to 1,816 BTC as identified by Galaxy Research
.
Response: Coinkite released corrected firmware, but users must generate entirely new seeds and migrate their funds, as old seeds remain compromised . Former Binance CEO Changpeng Zhao warned that even cold storage is not fail-safe, emphasizing that this incident demonstrates no security measure is absolute
.
Root cause: A logic error in BTCPay Server's API authentication layer allowed unauthenticated remote attackers to access .macaroon credential files protecting LND Lightning nodes . These credentials are used for API authentication, and once obtained, they grant full control of the associated Lightning node
.
What was stolen: Attackers emptied Lightning network channels on BTCPay Server instances, hitting confirmed victims including hardware wallet maker Foundation and Bitcoin zine Citadel21 . Standard BTCPay on-chain wallets were not affected
.
Response: BTCPay Server released emergency version 2.4.2 on August 7, telling all operators to update immediately or take their servers offline . Critically, the patch stops new access but does not invalidate credentials already stolen — operators must also manually revoke and rotate LND macaroons and move funds from any BTCPay-generated on-chain hot wallet
. BTCPay confirmed funds were stolen and said the attacks it reviewed targeted only files with the .macaroon extension
.
Bitcoin Red Team: A volunteer group led by developer Calle and AnchorWatch CEO Rob Hamilton, funded by OpenSats, launched a "large-scale ecosystem audit" using multiple AI models including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2 .
Results: In roughly 30 hours, the team scanned 390 open-source Bitcoin repositories and filed 4,962 security findings, including 85 critical-severity and 635 high-severity vulnerabilities . The audit cost over $40,000 in AI compute
. The team is responsibly disclosing vulnerabilities and plans to open-source its tooling to harden Bitcoin self-custody and broader crypto infrastructure
.
Impact: The Coinkite bug has pushed open-source wallet developers toward AI-powered code audits as a standard practice . Coinkite itself noted it was likely that "someone used AI to review previous versions of our firmware" in its post-mortem
.
Bitcoin logged 2.27 million new wallets and 751,000 active wallets this week — its strongest onchain activity in months — as holders raced to move funds off Coldcard devices . Research firm K33 reported roughly 890,000 BTC moved over the prior seven days, the highest weekly active supply figure recorded in 2026
. Both Coinkite and BTCPay Server issued urgent public warnings that funds are at immediate risk and "attacks are ongoing"
.
Bitcoin initially dropped nearly 3% to briefly touch below $62,000 when the Coldcard hack broke on July 31 . However, prices recovered quickly. By Monday August 3, BTC climbed past $64,000 — a 2.9% gain — as analysts noted the hack's limited market impact and the presence of eager buyers
. As of August 8, Bitcoin remains near $64,000, but traders remain nervous, with Forbes reporting BTC is "braced for more critical exploits" amid the BTCPay news
. The price has broadly held up despite back-to-back infrastructure shocks, reflecting market resilience.
The events of this week underscore several important lessons for Bitcoin holders and infrastructure operators:
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Two critical Bitcoin infrastructure exploits were disclosed this week: a Coldcard Mk3 firmware flaw that drained over $116 million from 5,200+ addresses and a BTCPay Server vulnerability that exposed Lightning node cr...
Two critical Bitcoin infrastructure exploits were disclosed this week: a Coldcard Mk3 firmware flaw that drained over $116 million from 5,200+ addresses and a BTCPay Server vulnerability that exposed Lightning node cr... Bitcoin’s price initially dipped nearly 3% but has since rebounded to around $64,000, reflecting market resilience despite back to back infrastructure shocks.
The incidents have pushed open source wallet developers toward AI powered code audits as a standard practice.