A public bitcoin transaction has been identified that explicitly offers laundering services to the perpetrator of one of the largest self-custody bitcoin thefts. Separately, users are reporting that emergency firmware updates from Coinkite have left some hardware wallets unusable. The disclosure of a long-dormant firmware flaw by Coinkite days earlier adds context to the situation.
A public offer to launder
The transaction, visible on the blockchain, includes a message in its OP_RETURN field offering to help the thief clean the stolen funds. It's a brazen move — the thief behind the self-custody heist, which saw millions in bitcoin drained from individual wallets, now has a direct line to a service willing to obfuscate the trail. The offer is public, meaning anyone can see it, including law enforcement. That doesn't mean it's a trap, but it's certainly a risk for the thief.
The theft itself was one of the largest ever from self-custody setups, where users hold their own keys. The attacker likely exploited weak security practices or targeted specific individuals. Now, a would-be launderer is openly advertising on the same network the thief used to steal.
Emergency updates brick hardware wallets
Meanwhile, users of Coinkite hardware wallets are reporting that emergency firmware updates have rendered some devices unusable. The updates, pushed out in the last few days, were meant to address a security issue. But for some, the fix broke the device entirely. Social media and forums are filled with complaints of wallets that won't boot or connect after the update.
Coinkite hasn't yet commented on the bricked devices. The timing isn't great — trust in hardware wallets is already fragile after a string of vulnerabilities this year. Users who followed the update instructions are now locked out of their funds, at least temporarily.
Coinkite's dormant flaw
Days before the bricked-wallet reports, Coinkite disclosed a long-dormant firmware flaw. The company said the vulnerability had been present in its code for years but was only recently discovered. It's unclear if the flaw was ever exploited in the wild. The disclosure came as a surprise to many users, who thought their devices were secure.
The emergency update was the response to that disclosure. But the rollout appears to have been rushed. Some users say they received no warning before the update was forced. Others report that the update process itself was buggy, leading to the bricked devices.
It's a messy situation for Coinkite. The company now faces a dual problem: a disclosed flaw that may have been exploited, and a fix that broke hardware. Users are demanding answers, and some are calling for a recall.
Whether the laundering offer and the Coinkite issues are connected isn't clear. But both events highlight the ongoing risks in self-custody — from theft to firmware failures. The next step for Coinkite is likely a detailed postmortem and a plan to recover bricked wallets. For the thief, the public laundering offer may be a trap or a lifeline. Either way, the blockchain doesn't forget.




