FOR IMMEDIATE RELEASE
WILLEMSTAD, Curaçao — August 2, 2026 — Bitkaya B.V., a virtual asset service provider (VASP) based in Curaçao, today confirmed that it has no exposure to the ongoing Coldcard hardware wallet exploit that has drained approximately 1,367 Bitcoin (worth nearly $89 million) from over 4,500 addresses since July 30.
The exploit, tracked by Galaxy Research and first reported by CoinDesk, exploits a firmware flaw in certain Coldcard hardware wallets that caused seed phrases to be generated from predictable data rather than a true hardware random number generator. Attackers are able to reconstruct private keys offline and sweep funds without ever physically accessing the victim’s device.
Bitkaya does not use Coldcard wallets — or any single-signature consumer hardware wallet — for the storage of client funds. The company’s custody infrastructure relies on institutional-grade wallet architecture with hardware security modules (HSMs), multi-signature key management, and documented approval workflows. No client funds held through Bitkaya’s B2B custody are affected by this vulnerability.
“This exploit is a serious reminder that ‘offline’ does not automatically mean ‘secure.’ The weakness wasn’t in how people stored their keys — it was in how the keys were generated in the first place. No amount of operational discipline can compensate for a broken random number generator.”
— Cees Quirijns, Managing Director, Bitkaya B.V.
Bitkaya advises all cryptocurrency users who generated wallet seeds on Coldcard devices (Mk2, Mk3, Mk4, Q, or Mk5) during the affected period to assume their keys may be compromised and to migrate their funds to a freshly generated wallet on a verified, unaffected device without delay.
The company further notes that there is currently no reliable method for an individual to determine whether a given Coldcard seed was generated using the vulnerable firmware path, meaning that affected users cannot verify their own exposure — they can only assume the worst and act accordingly.
For businesses and institutional clients, Bitkaya recommends reviewing key generation and custody procedures to ensure that no single hardware device or firmware version represents a single point of failure. The company’s Crypto Custody services are designed to address this exact risk through multi-signature architecture and HSM-based key management.
About Bitkaya
Cees Quirijns (info@bitkaya.io)