When the screen of his mobile phone showed an unauthorized transfer close to midnight, Felipe Ojeda realized that the balance of ten years of work had just been reduced to zero.
The bitcoin (BTC) funds he had stored at his home in Brazil, in a Coldcard hardware wallet manufactured by the Canadian company Coinkite to operate isolated from the internet, had been transferred to an unknown address.
In a live broadcast through his YouTube channel, Bitcoin Liberdade, Ojeda exposed the impact of detecting the transaction that left him without his BTC:
I haven't even been able to cry from the anger I have. My throat is dry. When I start to think about this, I run out of breath. I've gone two nights without being able to sleep well. It was ten years of work. It's desperate. And what bothered me the most was seeing the founder of this company, in the early moments, dismissing the claims on X (formerly Twitter). Felipe Ojeda.
Like Ojeda, there are thousands of cases. Analysis from the research firm Galaxy Research places the confirmed figure of drained bitcoin at 1,596, equivalent to approximately 100 million dollars at current prices.
A fourth wave of attacks, still under investigation, could raise the total to 2,055 BTC. The origin of this massive loss dates back to March 2021. It occurred when a compilation error in the Coldcard firmware reduced the entropy of the 256-bit seeds to just 40 bits in the most affected models, equivalent to a three-word key. This allowed attackers to brute-force the combinations in less than a second.
Ojeda, one of the leading promoters of Bitcoin in Brazil with over ten years of experience, had chosen Coldcard precisely for its reputation. He trusted that it was the device that the community pointed to as the safest, the "war chest" for storing capital long-term.
He never shared his keys. He also did not connect the device to the internet. His wallet was what in slang is called "from a holy father". It only received, just like other victims previously reported by CriptoNoticias.
And yet, the funds were gone. Felipe Ojeda reported the loss of ten years of savings stored in his Coldcard and announced legal actions against the Canadian company Coinkite. Source: YouTube/Bitcoin e Liberdade.
Now, his YouTube channel has become the meeting point for Portuguese and Spanish-speaking victims. Ojeda claims to have filed a police report. And, defying the dogmas of the Bitcoin community, he announced that he would sue Coinkite.
I have already filed the occurrence report. I am going to process Coinkite. If anyone says that I am less 'ancap' [anarcho-capitalist] for appealing to the State, let them reject my decision if they want. This is not an appeal to the State; it is a demand for civil liability. They sold a defective product and they knew it. I am not going to receive anything because the company is worth less than the stolen bitcoins, but I want it to be known that this case cannot go unpunished. The next time a company wants to sell a chest without showing how it works, the community will remember this. Felipe Ojeda.
This phrase summarizes the dilemma: is suing a manufacturer a betrayal of self-custody or simply demanding accountability for a defective product?
Ojeda asserts that lawyers specializing in technology law and consumer protection in Brazil are evaluating legal avenues to challenge Coinkite's liability waiver clauses. Their argument is that a critical manufacturing defect in a security device could violate consumer protection standards.
For this reason, he is promoting the creation of a victims' group to file a class action lawsuit against the manufacturing company. His reasoning is that, having acknowledged the error, Coinkite has no defense regarding the failure itself.
The decision to go to court opens a complex legal and regulatory debate about the nature of cold wallets:
On one hand, as attorney Cristina Carrascosa points out, Coinkite lacks regulatory responsibility for the custody of funds. As it is not a virtual asset service provider (CASP or centralized custody), the company does not bear a direct legal obligation to restore the stolen capital. Furthermore, proving in court that the company could have foreseen the exact attack vector constitutes a severe procedural obstacle.
Analyst José Antonio Bravo Mateu, where he outlines the possible legal grounds for a lawsuit for misleading advertising and product liability against Coinkite, using the judicial precedent of Ledger in the U.S. Source: X/Jabravo.
The origin of the tragedy, for Ojeda, has a clear moral culprit: Coinkite's decision to close its source code in 2021, after a competitor used its open code. In one of the most powerful metaphors circulating in the community, Ojeda states:
Coldcard did not fail at its Achilles' heel; it failed at the sack of Adam. It was not a peripheral error. It was at the very center of its reason for being: key generation. The company profited from the community's trust for years with open code. But when a competitor used its code, they got angry, closed it, and introduced the update that contained the fatal error right in the part that we could no longer review. If the code had remained open, someone would have seen that cursed line in months, not in five years. They took away our ability to verify and sold us a broken lock. Felipe Ojeda.
Indeed, Coinkite closed the code that the community had audited for years and introduced the error in the part that could no longer be reviewed. Security researcher and co-founder of Casa, Jameson Lopp, supports this underlying concern. He highlights the fact that the "don't trust, verify" is a luxury that 99.9% of users cannot afford.
And when a company closes the code precisely to prevent that verification, trust becomes an act of faith.
On July 31, Coinkite issued an official statement acknowledging <
When asked by CriptoNoticias about possible compensations, a remediation program, or the estimated number of users still at risk, the company did not respond to those specific questions. It only reiterated technical instructions and referred to its official blog.
However, its blog does not answer the question that millions of affected users are asking: who pays?
In this regard, Venezuelan lawyer Ana Ojeda, specialized in technology law and consumer protection, argues that, although Coinkite includes liability waiver and arbitration clauses in Ontario, these are not impregnable.
The lawyer points out that Coldcard was not sold as a simple device, but as a high-security infrastructure with <
This promise of security, along with a defect in the core mechanism of the product and a pattern of losses technically linked to that defect, constitutes the basis for a lawsuit for defective product and professional negligence.
The courts, she explains, could interpret this not as <
The case sets the stage for an important precedent. It highlights that one cannot sell maximum security, fail at the core of that security, and then expect to be protected by generic clauses. The goal is not just economic compensation; Coinkite's assets would not cover the total stolen, but to establish that principle for the entire industry.
Did you find this content useful and relevant?YesNo
Send
This note helped you to *Understand what happenedAnalyze the contextMake an informed decisionEntertainUpdateDid not help you
Send
What content are you looking for today in CriptoNoticias? *Quick newsReportsMarket analysisInterviewsOpinion articlesEducational material
Send
How valuable do you consider this note?012345
Send
Would you recommend this article to a friend or colleague?YesNo
Send
In what format would you like to complement this information? *Short videoAudio or podcastInfographicText is enough
Send
What action will you take after reading this note? *I will look for more on the topicI will adjust my investmentsI will continue reading other newsNothing in particularI will take new security measures
Send
How easy was it for you to understand this text? *I understood everything at onceSure, but with some complex termsI had to look up what some words and ideas meantI got lost, it's too complicated
Send
Would you like to see more content like this?YesNo
Send
Tags: Bitcoin (BTC)BrazilHardwareLatestRegionalWallets (Wallet or Purse)
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

Bitget announced on 3 August 2026 that it will stop serving residents of Japan, halting new registrations that day, switching affected accounts to Close-Only mode on 1 November 2026 at 11:00 GMT+9, and force-closing all remaining open positions on 31 December 2026 at 11:00 GMT+9. Crypto withdrawals are stated to remain available after that date, with no withdrawal deadline published.





























Bitget announced on 3 August 2026 that it will stop serving residents of Japan, halting new registrations that day, switching affected accounts to Close-Only mode on 1 November 2026 at 11:00 GMT+9, and force-closing all remaining open positions on 31 December 2026 at 11:00 GMT+9. Crypto withdrawals are stated to remain available after that date, with no withdrawal deadline published.