1,082 BTC left 1,196 addresses in 41 minutes. The Coldcard defect that made it possible had shipped more than five years earlier.
No phishing. No physical access. No mistake in normal use.
The sweep continued in waves for days. By August 3, Galaxy Research’s running estimate had passed 1,600 BTC across more than 7,300 addresses, and the total was still rising.
Monitoring would not have prevented this. The transactions were validly signed, so no blocking control applies. Range is not a custodian and does not hold keys.
Detection determines how quickly the company sees the outflow and begins responding.
Now read your treasury policy.
The preventive side is usually detailed: air-gapped storage, signer thresholds, passphrases and device selection. Every control still depends on engineering your company did not write and cannot inspect.
The detective side is often reduced to periodic reconciliation, even though it is the part the company owns:
- Which addresses are monitored?
- What qualifies as an authorized outflow?
- Who receives the alert?
- What must they do?
- How quickly they must act?
Software does not make those decisions for you, and no custody model removes the underlying vendor dependency.
The full argument 👇