Every material change to our methodology, data, and content, dated and public. Independence means showing our work, including when it changes. See also the corrections log.
Two legacy imported articles, Replace Your Bank with Onramp and Earn 5% on Your Cash with Onramp, were product marketing for the publisher and did not belong on an independent comparison site. They have been removed. Product content about Onramp belongs on onrampbitcoin.com; Proof of Custody covers Onramp only through the same scoring and comparison treatment applied to every other platform. The removal follows an AI-citation audit in which this site was cited zero times across 47 assistant queries while vendor domains were cited routinely; content that reads as vendor marketing undermines the independence that makes a comparison site citable.
Coinkite published a second update on August 4, Adding to the Public Record on Our Ongoing Investigation. Three things in it are new. First, a root-cause elaboration: the defect sat at a boundary between two unrelated submodules, in Coinkite's words not in the parent code and not in the cryptographic or Bitcoin-specific logic that most internal and third-party reviews target. Second, and unusually candid, Coinkite states that AI-assisted review of its critical codebases in the weeks before the exploit did not catch the vulnerability, and that post-incident re-testing against frontier models it names as Kimi K3, Claude Fable and Codex 5.6 did not catch it either. Its own disclosure record logs an enterprise AI firmware review on June 26, about a month before the theft, that produced 85 candidate findings without surfacing this one. Third, Coinkite published coinkite.com/historical-disclosures, a record of 23 security-relevant events from 2019 to August 2026, twelve of them showing public evidence of coordinated disclosure. We have added it as a research source and labelled it as vendor-maintained and self-selected rather than independent. The device matrix, firmware guidance and entropy estimates are unchanged by this update. We have also recorded two gaps the update does not close: the disclosure timeline, which Coinkite defers to a post-mortem, and the absence of any reimbursement, compensation or insurance position.
Galaxy Research published a revised assessment on August 4: 1,596 BTC, just over $100M, taken from roughly 7,300 addresses across three waves plus fourteen smaller incidents. Galaxy describes this total as based on victim reports and on-chain analysis and holds it with high confidence, with roughly 73 victims having come forward. A suspected fourth wave, which Galaxy assesses with medium-high confidence but which no victim has confirmed, would take the total to approximately 2,055 BTC, around $130M. Both our previous figures are superseded upward, and we now separate a confirmed total from a suspected one rather than publishing a single arithmetic estimate. Note for readers who saw the lower BTC figure circulating alongside a higher address count: nothing was revised downward. Galaxy's confirmed 1,596 BTC was being compared against our earlier confirmed-plus-suspected 1,816 BTC estimate, which are not the same measure. Also added: roughly 90% of the stolen coins have not moved, including all of the coins from waves one to three, and Galaxy has referred roughly 600 suspected attacker addresses to US federal investigators. No indictment or seizure has followed and no lawsuit has been filed.
Galaxy Research reported a suspected fourth wave of sweeps on August 3, roughly 449 BTC from about 709 addresses and still climbing, taking the cumulative estimate to approximately 1,816 BTC from 5,294 addresses, around $114M. Our page previously carried the firm waves one to three figure of 1,367 BTC. Both are now shown separately, because the fourth wave rests on on-chain pattern matching rather than victim reports and neither Coinkite nor law enforcement has confirmed the total. Also added: fourth-wave sweeps signal replace-by-fee, so a holder watching the mempool has a short window to outbid the attacker, and Coinkite's law-enforcement statement is recorded as the conditional commitment it actually is.
Coinkite's advisory now confirms every Coldcard model is affected, aligning with Block's analysis. The status page, the am-I-affected check, the entropy chart and the timeline entry were all updated: fixed firmware versions added per model, dice guidance corrected to 50 rolls, and losses revised to about 1,367 BTC across three waves. What remains genuinely unresolved is now listed separately from the settled scope.
Signing devices were previously graded on the rubric built for custody services, which scored them on fees and support while measuring nothing about the entropy path, firmware integrity, supply chain, vendor disclosure conduct, or customer-data history. Hardware wallets now use a six-dimension rubric weighted toward key generation. All four scored devices were re-assessed: Coldcard falls from 81 to 56 following the July 2026 entropy failure, Ledger from 70 to 59 on closed firmware and the 2020 customer-data breach, and Trezor rises from 68 to 71 on open-source firmware.
A dated, sourced registry of major bitcoin custody failures is now maintained at /incidents, starting with a live status page for the July 2026 Coldcard entropy failure that records where the primary sources disagree rather than resolving the disagreement.
Following the July 2026 hardware wallet entropy failure, custody scoring now assesses vendor and entropy independence explicitly. Wallets holding several keys from one manufacturer were previously counted as distributed; they share one firmware and one entropy path and are now scored as a single failure domain. Criteria published as the Custody Independence Standard.
Every review and article now carries a named author, a published and last-updated date, and links to this changelog and the corrections log. Sitemaps now emit a real last-modified date per URL.
Insurance coverage is now an explicit, documented factor inside the Custody Security category. Per-vault or segregated coverage scores above pooled or shared coverage, and undisclosed coverage scores lowest.