They Followed Every Rule and Lost Everything Anyway
Thousands of Bitcoin holders did exactly what the industry told them to do. Their savings were gone before they woke up.

Most crypto theft has a villain you can picture. A phishing link. A fake support agent who talks someone through their own robbery. A man with a wrench. Somebody tricks you, or somebody grabs you, and the money walks out the door with a story attached to it.
This one has none of that. In the early hours of July 30, 2026, thousands of Bitcoin holders lost their savings without doing a single thing wrong. They had bought a respected hardware wallet. They had generated their seed offline, on the device, exactly as instructed. They had written the words on paper and never typed them into a computer. Many had left the coins untouched for years. The devices were in safes and drawers and safety deposit boxes, and every one of them stayed exactly where it was while the money left.
The first alarm did not come from a security researcher or from the company that made the wallets. It came from a victim. At 13:19 UTC someone posted to Reddit under the title "Full panic, one of my wallets was drained." The account they gave in the comments was almost unbearably ordinary. A Coldcard bought in 2021. A 24-word seed generated on the device itself. Savings moved over, then years of quiet. In January 2025 they bought a second Coldcard and carefully re-entered the old words, just to confirm the backup was correct. The seed had never touched an internet-connected machine. Only the device, a watch-only wallet for checking the balance, and automatic withdrawals from an exchange to the same address. That night, that address was swept along with hundreds of others.
The numbers describe the people better than any single story does. The median victim lost 0.41 BTC, roughly $26,500. That is not a whale. That is somebody's savings, or a house deposit, or the money they had been quietly stacking since 2021 because they believed in it. The largest single loss was 29.9 BTC, nearly $2 million. Nobody lost less than 0.15 BTC, because the attacker filtered by minimum balance before they started. Every drained wallet was single-signature, and the total cost to the thief for the entire operation was about $2,800 in transaction fees.
Some of the losses have names attached. Jonathan Goodman, in Toronto, posted that 18.25245043 BTC had vanished from his wallets, just over $1.6 million Canadian, taken between 9:36pm and 9:43pm on July 29. He had heard about the hack while at his cottage, thought there was no way it affected him, logged in to check, and found rows of red. His Coldcard had been in a safety deposit box. It had never been connected to the internet.
People in his replies called it fake. The on-chain record does not. Goodman was posting Toronto time, which is UTC minus four; his 9:36pm to 9:43pm converts to 01:36 to 01:43 UTC on July 30, sitting squarely inside the 01:10:20 to 01:51:26 UTC window Galaxy Research mapped for the sweep. The timestamps line up to the minute.
When he tried to report the theft, he walked into a Toronto police station and was told to file online. He filed online and the report was rejected for being too large, with instructions to attend a station in person.
The rest of the victims are mostly anonymous, and that is its own kind of detail. Confirmations arrived from developers the Bitcoin community trusts, and Kevin Loaec of Wizardsardine noted that the affected included multiple well-known Bitcoiners, people who had spent years teaching others how to do this properly. Jameson Lopp reported partial thefts, wallets where only some outputs had been taken. Whatever comfort there was in assuming one careless person had been phished died within a few hours.
What makes this different from every other entry in this section is that there is no lesson the victims could have applied. Multisig would have saved them, and so would supplying their own dice rolls during setup, and both were optional extras that most guides listed as advanced practice rather than baseline. The people who lost everything followed the standard advice available at the time, in full. The failure happened at the one moment nobody can audit: the instant the device created the seed, years before anyone had reason to suspect anything.
It is still true for everyone else who owns one. There is no test an owner can run against their own wallet to find out whether their seed sits inside the guessable range. Coldcard users reading about this can migrate on the assumption they are exposed, or they can wait and hope, and there is no third option that involves finding out.
Coinkite CEO Rodolfo Novak apologized on July 31 and said the company took full accountability. He said Coinkite would publish a technical report and help affected users with police reports, insurance claims, and independent investigations. He has not said the company will compensate anyone for what was taken, and as things stand there is no fund, no insurance scheme, and no realistic legal path for most of these people to recover a satoshi.
Nor is anyone official coming. No government agency has publicly opened a case. Block handed what it found on the attacker to unnamed authorities; Coinkite, based in Toronto, has announced no police referral. Victims are left with the FBI's standard instruction to file a report through IC3 and hope, and Goodman's experience suggests even that can be harder than it sounds. American plaintiff firms have already put up pages soliciting Coldcard victims, which is its own kind of answer about where this is heading. No case had been filed at the time of writing, and no court has ever established that a hardware wallet manufacturer owes anything when its firmware costs someone their savings.
The money itself has not moved. Every coin taken is still sitting in a small number of addresses nobody has touched. Galaxy noted that this is unusual for a theft this size and offered two explanations: the attacker is waiting for attention to die down, or there is no clean way to launder a sum this visible. For the people it was taken from, watching their Bitcoin sit motionless in an address they can see and cannot reach is its own particular cruelty.
For a lot of them the harder thing is not the money. It is that they were careful. They read the guides, bought the recommended device, did the offline setup, protected the backup, resisted every shortcut for years. And it made no difference at all.
If you or someone you know is struggling, help is available. National Suicide Prevention Lifeline: 988 (US). Crisis Text Line: Text HOME to 741741. International Association for Suicide Prevention: https://www.iasp.info/resources/Crisis_Centres/
The Aftermath
Coinkite shipped emergency firmware, but a patch cannot repair a seed that already exists, and it does nothing for anyone already drained. The company has offered to assist victims with police reports, insurance claims, and independent investigations. It has not offered compensation. There is no industry fund covering this class of failure and no established legal route for individual holders to recover funds from a manufacturer over a firmware defect. The stolen coins remain unspent across a small number of attacker-controlled addresses. No government agency has publicly opened a case, and US plaintiff firms have begun soliciting victims. Galaxy has warned that further waves are likely for anyone who has not migrated, and there is no test an owner can run to find out whether their own seed is exposed. Some victims have reported difficulty even getting police forces to accept a report.
COMMENTS