Morning Edition · Friday, July 31, 2026Published at 1:30 AM EDT · New York
Hardware Wallet Flaw Drains 594 Bitcoin in a 25-Minute Sweep
A flawed random-number process made supposedly unguessable wallet keys guessable, exposing about $38 million held in self-custody.

A flaw in a hardware wallet's key-generation process allowed attackers to drain 594 bitcoin in a single 25-minute operation, CoinDesk reported. The problem lay in how the device produced the random numbers that create a wallet's secret key. When that randomness is weak, keys that should be effectively impossible to guess become reachable through systematic search.
At bitcoin's recent trading level near 64,000 dollars, confirmed by Fortune's daily price data, the stolen coins were worth roughly 38 million dollars. The speed of the operation, with hundreds of coins moved in under half an hour, indicates the attackers had already identified the vulnerable wallets and needed only to execute.
The episode is a reminder that the security of self-custody rests entirely on the integrity of the tools holding the keys. Bitcoin's own protocol was not breached. The failure was in a device that users trusted to generate secrets no one else could reproduce.
For a market that has spent years urging holders to move assets off exchanges and into personal custody, incidents like this contradict that message. The promise of self-custody is control, but control depends on hardware and software that most users cannot independently verify.
Part of a tracked trend
Crypto Self-Custody Risk
Recurring failures in wallet hardware and crypto infrastructure impose tail risk on holders and strengthen the case for regulated custodians, slowing the self-custody model the industry has promoted.
What this means
The channel is confidence in self-custody, the practice the crypto industry has promoted as safer than leaving assets on exchanges. A key-generation flaw that lets attackers reconstruct private keys turns the safest-sounding option into a single point of failure, and every holder of the affected device is exposed regardless of their own security habits. The beneficiaries are regulated custodians and exchanges that can argue their infrastructure is more accountable, and the losers are the hardware vendors whose trust depends on flawless randomness.
What to watch
- Identification of the specific device and firmware involved, because the scope of the flaw determines how many wallets remain at risk.
- Whether institutional custody providers cite the incident to argue for regulated custody over self-custody, which would shape how new capital enters the asset.
Observations to monitor, not financial advice.
More from this edition
- AI Infrastructure Selloff Forces Aschenbrenner's Fund to Hand Public Bets to Citadel
- Bank of Japan Holds Rate at 1% After Intervening to Slow the Yen's Decline
- Anthropic Says Its Most Powerful Model Broke Out of Testing and Hacked Three Firms
- Russia Strikes Ukrainian Fuel Stations and Ports as the Energy War Widens
- Trump Announces Phased Deal to Disarm Hamas and Withdraw Israeli Forces From Gaza
- Iran Buries Revolutionary Guards as US-Iran Strikes Persist Despite Reported Talks
- EU-China Trade Talks Approach October Deadline With Little Expected From Beijing
- US Weighs $100,000 Fee on Foreign Graduates' Work Permits
- Bajaj Finance Jumps 5% as Quarterly Profit Rises 28%
- China Fires Hypersonic Anti-Ship Missile From a Smaller Warship as Japan Opens New Intelligence Bureau
- Death Toll From Kumamoto Earthquake Rises to 34 as Survivors Shelter in Cars