Every material change to our methodology, data, and content, dated and public. Independence means showing our work, including when it changes. See also the corrections log.
The incident page carried Galaxy Research's August 4 snapshot: 1,596 BTC from roughly 7,300 addresses on 73 victim reports, with a suspected fourth wave projected at about 2,055 BTC. Galaxy's August 24 update supersedes it at 1,789.28 BTC across 8,865 addresses on 221 victim reports, about $114.7M at the prices when the coins moved, or roughly 1,824 BTC including medium-confidence cases; the 2,055 BTC projection does not appear in that update. Added: on September 21, 2026 white-hat operators swept 52.37 BTC away from the attacker into an address presented as the Crypto Recovery Trust, 40.71 BTC of it in block 967,948. The block and timestamp were checked against mempool.space; the coins were not traced independently and the trust's website did not respond, so the page records the coins as out of the attacker's reach rather than returned. Figures also updated in the registry, the OG image, llms.txt and the signal monitor's baseline.
Features carries 10% of every platform's score. It was defined as "IRA, lending, inheritance, dynasty trusts, DCA, Lightning, card rewards", which awarded points for product catalogue breadth. Proof of Custody is published by Onramp, and that list described Onramp's product range, so the category could reward the publisher's own configuration rather than custody safety. It is now defined as capability that changes what happens to your bitcoin: recovery options, inheritance mechanism, withdrawal controls, trust and entity titling, and exit and migration. The weight stays at 10%. The change is prospective: scores were computed under the old definition and are recomputed under the new one at the October 5 scoring run, and this entry states the date so nobody has to guess which definition produced a given score.
The explainer on per-vault versus pooled insurance is published by Onramp Bitcoin and described the structures in general terms without saying which one Onramp has. It now states it: Onramp carries up to $50 million in aggregate coverage through Canopius, a Lloyd's of London syndicate, which is an aggregate limit rather than per-vault coverage. A reader comparing the two structures on a page we publish is entitled to know where we sit, particularly when the structure we do not have is the one that sounds better.
58 pages described Multi-Institution Custody as keys "distributed", "split" or "sharded" across institutions. Nothing is split between institutions. Sentences now say it takes two of three institutions to move anything, and nothing moves without the holder's permission. Google AI Mode had been quoting the older wording (Onramp ticket MAR-661).
A monthly fact-check of every IRA provider against their live sites found several facts superseded since the May build, and all affected pages have been updated. Swan's IRA custodian is now Equity Trust rather than Fortress Trust. BitcoinIRA's custodian of record is Digital Trust, a Nevada non-depository trust company, with BitGo providing wallet infrastructure and up to $250M in custody insurance via BitGo Trust and Lloyd's of London; its fee schedule is now published at 2% per trade plus 0.08% of assets monthly, the most expensive published structure in the category. iTrustCapital's chain is Fortis Bank as qualified custodian with storage split across Coinbase Custody, Fidelity Digital Assets, and Fireblocks; iTrust does not publish which provider holds a given account's assets. Unchained IRA fees are confirmed at $250 per year with a 1.5% IRA trading fee and $2,000 transaction minimum. Every change was verified against the provider's own site or help center before publication; the original facts were accurate when published and are superseded rather than corrected. Credit: the discrepancies were surfaced by an internal fact-check pass and independently re-verified before this update.
Two legacy imported articles, Replace Your Bank with Onramp and Earn 5% on Your Cash with Onramp, were product marketing for the publisher and did not belong on an independent comparison site. They have been removed. Product content about Onramp belongs on onrampbitcoin.com; Proof of Custody covers Onramp only through the same scoring and comparison treatment applied to every other platform. The removal follows an AI-citation audit in which this site was cited zero times across 47 assistant queries while vendor domains were cited routinely; content that reads as vendor marketing undermines the independence that makes a comparison site citable.
Coinkite published a second update on August 4, Adding to the Public Record on Our Ongoing Investigation. Three things in it are new. First, a root-cause elaboration: the defect sat at a boundary between two unrelated submodules, in Coinkite's words not in the parent code and not in the cryptographic or Bitcoin-specific logic that most internal and third-party reviews target. Second, and unusually candid, Coinkite states that AI-assisted review of its critical codebases in the weeks before the exploit did not catch the vulnerability, and that post-incident re-testing against frontier models it names as Kimi K3, Claude Fable and Codex 5.6 did not catch it either. Its own disclosure record logs an enterprise AI firmware review on June 26, about a month before the theft, that produced 85 candidate findings without surfacing this one. Third, Coinkite published coinkite.com/historical-disclosures, a record of 23 security-relevant events from 2019 to August 2026, twelve of them showing public evidence of coordinated disclosure. We have added it as a research source and labelled it as vendor-maintained and self-selected rather than independent. The device matrix, firmware guidance and entropy estimates are unchanged by this update. We have also recorded two gaps the update does not close: the disclosure timeline, which Coinkite defers to a post-mortem, and the absence of any reimbursement, compensation or insurance position.
Galaxy Research published a revised assessment on August 4: 1,596 BTC, just over $100M, taken from roughly 7,300 addresses across three waves plus fourteen smaller incidents. Galaxy describes this total as based on victim reports and on-chain analysis and holds it with high confidence, with roughly 73 victims having come forward. A suspected fourth wave, which Galaxy assesses with medium-high confidence but which no victim has confirmed, would take the total to approximately 2,055 BTC, around $130M. Both our previous figures are superseded upward, and we now separate a confirmed total from a suspected one rather than publishing a single arithmetic estimate. Note for readers who saw the lower BTC figure circulating alongside a higher address count: nothing was revised downward. Galaxy's confirmed 1,596 BTC was being compared against our earlier confirmed-plus-suspected 1,816 BTC estimate, which are not the same measure. Also added: roughly 90% of the stolen coins have not moved, including all of the coins from waves one to three, and Galaxy has referred roughly 600 suspected attacker addresses to US federal investigators. No indictment or seizure has followed and no lawsuit has been filed.
Galaxy Research reported a suspected fourth wave of sweeps on August 3, roughly 449 BTC from about 709 addresses and still climbing, taking the cumulative estimate to approximately 1,816 BTC from 5,294 addresses, around $114M. Our page previously carried the firm waves one to three figure of 1,367 BTC. Both are now shown separately, because the fourth wave rests on on-chain pattern matching rather than victim reports and neither Coinkite nor law enforcement has confirmed the total. Also added: fourth-wave sweeps signal replace-by-fee, so a holder watching the mempool has a short window to outbid the attacker, and Coinkite's law-enforcement statement is recorded as the conditional commitment it actually is.
Coinkite's advisory now confirms every Coldcard model is affected, aligning with Block's analysis. The status page, the am-I-affected check, the entropy chart and the timeline entry were all updated: fixed firmware versions added per model, dice guidance corrected to 50 rolls, and losses revised to about 1,367 BTC across three waves. What remains genuinely unresolved is now listed separately from the settled scope.
Signing devices were previously graded on the rubric built for custody services, which scored them on fees and support while measuring nothing about the entropy path, firmware integrity, supply chain, vendor disclosure conduct, or customer-data history. Hardware wallets now use a six-dimension rubric weighted toward key generation. All four scored devices were re-assessed: Coldcard falls from 81 to 56 following the July 2026 entropy failure, Ledger from 70 to 59 on closed firmware and the 2020 customer-data breach, and Trezor rises from 68 to 71 on open-source firmware.
A dated, sourced registry of major bitcoin custody failures is now maintained at /incidents, starting with a live status page for the July 2026 Coldcard entropy failure that records where the primary sources disagree rather than resolving the disagreement.
Following the July 2026 hardware wallet entropy failure, custody scoring now assesses vendor and entropy independence explicitly. Wallets holding several keys from one manufacturer were previously counted as distributed; they share one firmware and one entropy path and are now scored as a single failure domain. Criteria published as the Custody Independence Standard.
Every review and article now carries a named author, a published and last-updated date, and links to this changelog and the corrections log. Sitemaps now emit a real last-modified date per URL.
Insurance coverage is now an explicit, documented factor inside the Custody Security category. Per-vault or segregated coverage scores above pooled or shared coverage, and undisclosed coverage scores lowest.