Crypto Fraud Watch: The Coldcard Loss Doubles to $70M, a $4B Iran Pipeline in Dubai, and a Frozen Nasdaq Approval
In several of this weekend's crypto stories, the number reported first was not the real number. A hardware wallet drain nearly doubled, a Dubai platform turned out to have moved billions for sanctioned Iranian entities, and a May exchange approval is frozen. Here is what broke between July 30 and August 1, and what it means legally.
The Coldcard Drain Was Twice as Big as First Reported
Galaxy Research published a full reconstruction of the Coldcard hardware wallet theft on Friday. Between 01:10 and 01:51 UTC on July 30, an attacker swept 1,082.65 BTC, roughly $70 million, out of 1,196 wallets. Early reporting caught one of four receiving addresses, which is why the loss first appeared as $38 million. The proceeds have not moved.
The mechanism matters more than the figure. A build setting told Coldcard's firmware to skip its hardware randomness generator, and a library check tested only whether that setting existed rather than whether it was on. Key generation fell through to a software substitute seeded from the chip's serial number and clock registers, collapsing the key space on the Mk4, Q and Mk5 to roughly four billion possibilities. The attacker never touched a device. That reframes the legal theory: this reads less like a theft claim than a product defect claim against a manufacturer, sounding in design defect, warranty and failure to warn. The obstacle is proof. No test shows whether a given owner's seed fell inside the reproducible range, which complicates causation and class certification alike.
Reuters Traces a $4 Billion Iranian Pipeline to a Dubai Office
A Reuters investigation published July 31 identified Shelbit, an unlicensed platform run from an office above a budget hotel in Dubai's Deira district, as the hub of what analysts call the largest Iranian sanctions-evasion network uncovered since 2016. At least $4 billion moved through it since May 2024, connecting more than 2,000 illegal gambling sites, the Central Bank of Iran and the IRGC to global markets. Analytics firms found direct transactions with wallets tied to sanctioned Iranian exchange Nobitex, and Dubai's Virtual Assets Regulatory Authority ordered Shelbit to cease operations.
OFAC liability is strict: no intent requirement, and no safe harbor for not knowing your counterparty's counterparty. Any U.S. desk with Shelbit-adjacent flow now has a lookback exercise, and self-disclosure earns real mitigation credit only if it lands before the subpoena does.
The SEC Freezes Nasdaq's Bitcoin Options Over a Turf Fight
An SEC order released for public inspection on July 31 paused the agency's own May approval of Nasdaq PHLX's cash-settled bitcoin index options, ticker QBTC, and granted CME Group's petition for review. CME's argument is jurisdictional: bitcoin is a commodity, options on its value fall within the CFTC's exclusive jurisdiction, and the agencies cannot use exemptive relief to move a product from one regulator's shelf to another's. Statements are due August 24 while the full Commission reconsiders.
If CME prevails, Nasdaq must register as a CFTC venue or redesign the contracts around a security such as a spot bitcoin ETF. March's joint SEC-CFTC interpretation settled how sixteen major assets are classified without settling which agency approves derivatives built on them. A conditional approval is not a launch, and a rival's petition can freeze one for months.
Tether's Cushion Shrinks by Half
Tether's BDO attestation, released Friday, shows $1.5 billion in second-quarter operating profit but excess reserves of $4.11 billion, down from $8.23 billion three months earlier, against $183.64 billion in liabilities. That buffer, now near 2.2 percent, is what absorbs a redemption wave, and an attestation is a point-in-time opinion, not an audit.
How to Protect Yourself
If you hold bitcoin on a Coldcard, treat migration as urgent. Generate a fresh seed on firmware confirmed outside the affected scope and move funds to new addresses; an untouched balance is not proof of an unaffected seed, and Galaxy warned further waves are likely. The episode also argues for splitting holdings across wallets from different manufacturers.
Recourse depends on the theory. A defect-based loss may support claims against a manufacturer, so preserve the device, firmware version, purchase records and your seed-generation timeline before evidence degrades. File with IC3 promptly, since tracing works best while funds sit unmoved, as they do here. And if you received funds that later trace to a sanctioned network, discuss disclosure with counsel before regulators reach you.
At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud โ whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.
Disclaimer
This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.