
One tiny bug inside a “safe” bitcoin wallet let thieves guess secret keys and drain up to $89 million without ever touching a single device.
Story Snapshot
- About 1,367 bitcoin vanished from 4,585 addresses in three fast waves of theft.
- Galaxy Research tied the attack to a broken random number generator in Coldcard wallets.
- The first major sweep hit 1,196 addresses in 41 minutes, stealing over $70 million.
- The flaw made seed phrases partly predictable, turning “cold storage” into easy prey.
How A Trusted Cold Wallet Turned Into A Soft Target
Coldcard was sold as one of bitcoin’s safest homes: an offline hardware wallet made by Canadian firm Coinkite, built for people who take self-custody seriously. That trust cracked open at the end of July, when researchers watched hundreds of quiet bitcoin addresses suddenly stripped bare in minutes.
Galaxy Research traced those drains and found many linked to wallets whose seeds were likely generated on flawed Coldcard firmware.
Owners thought their coins were safe because the device stayed offline, but the danger hid in the math inside the firmware. A tiny coding mistake changed how the wallet created its seed phrase, the master secret that controls every future address.
Instead of using the hardware random number generator chip, some versions quietly fell back to a weak software generator. That bug meant parts of those “random” words were no longer truly random.
The Three Waves That Emptied 4,585 Bitcoin Addresses
The first shock came July 30. Blockchain observers saw about 594 bitcoin, roughly $38 million, drain from around 500 wallets in less than half an hour.
Hours later, Galaxy Research mapped an even larger sweep: 1,196 addresses emptied of 1,082.65 bitcoin in about 41 minutes, worth around $70 million at the time. Those addresses mostly held more than 0.15 bitcoin, and every one was single-signature, which made them easier to brute-force and steal.
That was only the opening act. Over the next days, researchers spotted more coordinated sweeps. Follow-up analysis by Galaxy and others pushed the total theft to about 1,367 bitcoin, from 4,585 different addresses, across three major waves.
Later waves hit more addresses but with smaller balances, suggesting the attacker started with “whales” and then moved on to mop up the leftovers. By then, estimated losses had climbed to nearly $89 million in today’s prices.
The Firmware Bug That Broke Self-Custody
The heart of the problem was a firmware bug dating back to March 2021. Block’s Bitcoin engineering team and other analysts say a build error disabled the hardware random number generator and pushed seed creation through a predictable software path on certain Coldcard devices.
That change cut effective randomness down to a level advanced attackers could brute-force offline, especially with modern computing power.
Attackers did not hack into the devices over the internet or steal them from homes. They simply guessed the secrets. By precomputing large sets of possible private keys based on the flawed generator, they could match those keys to public addresses on the blockchain, spot which ones held money, and then sign transactions to sweep the funds. The whole plan ran without warning on the victim’s side.
What Coinkite Did Once The Alarm Went Off
Once the first drains were spotted, Coinkite moved from quiet bug to public crisis. The company released a security advisory stating that seeds generated on affected Mk3 firmware, starting around version 4.0.1, might be at risk and urged users to update their software and move funds.
Coinkite’s chief executive officer apologized and took responsibility for the firmware mistake, acknowledging that the flaw had turned a flagship security product into a liability for some customers.
I think many are still shocked and might not have a clear understanding of what happened here but let me explain.
A firmware flaw introduced in March 2021 caused Coldcard devices to skip their hardware randomness generator and fall back to predictable software-based key… https://t.co/VAWGNmRnxi
— Emmanuel Brighton (@SBE_PENXCHAIN) August 2, 2026
Galaxy Research and other teams stressed that their on-chain work shows patterns, not every private detail of each wallet. They cautioned that while many compromised addresses appear tied to Coldcard-generated seeds, investigators cannot yet prove every single one came from the flawed firmware.
Still, the match between the bug timeline, the affected models, and the swept addresses looks strong enough that most serious researchers now treat the flaw as the main cause.
What Conservative Common Sense Says About This Failure
The Coldcard episode hits a nerve for anyone who believes in personal responsibility and sound money. Self-custody is supposed to free people from shaky third parties, but that only works if the tools are solid.
Shipping a security product with a broken random number generator for years cuts against basic engineering duty and the trust that free markets rely on. When a single bug can vaporize $89 million in savings, that is more than a tech glitch; it is a failure of stewardship.
At the same time, many users treated hardware wallets like magic shields and stopped checking the fine print. This case pushes people to “trust, but verify.” That means reading advisories, testing backups, and not assuming any vendor is perfect.
The lesson here is hard but clear: if you hold life-changing wealth in new digital tools, you must demand transparent code, independent audits, and clear accountability when things go wrong.
Sources:
foxbusiness.com, thehackernews.com, coindesk.com, crypto.news, techspot.com, cryptopolitan.com, finance.yahoo.com, youtube.com, kucoin.com, bingx.com, bloomberg.com














