# Hardware Wallet Flaw Drains 594 Bitcoin in a 25-Minute Sweep

A flawed random-number process made supposedly unguessable wallet keys guessable, exposing about $38 million held in self-custody.

- Published: 2026-07-31T05:30:36.358Z
- Canonical: https://polylog.news/2026-07-31/hardware-wallet-flaw-drains-594-bitcoin-in-a-25-minute-sweep
- Publisher: Polylog (Global desk)
- Section: crypto
- Sources: [CoinDesk](https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep), [Fortune](https://fortune.com/article/price-of-bitcoin-07-30-2026/)

A flaw in a hardware wallet's key-generation process allowed attackers to drain 594 bitcoin in a single 25-minute operation, [CoinDesk reported](https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep). The problem lay in how the device produced the random numbers that create a wallet's secret key. When that randomness is weak, keys that should be effectively impossible to guess become reachable through systematic search.

At bitcoin's recent trading level near 64,000 dollars, confirmed by [Fortune's daily price data](https://fortune.com/article/price-of-bitcoin-07-30-2026/), the stolen coins were worth roughly 38 million dollars. The speed of the operation, with hundreds of coins moved in under half an hour, indicates the attackers had already identified the vulnerable wallets and needed only to execute.

The episode is a reminder that the security of self-custody rests entirely on the integrity of the tools holding the keys. Bitcoin's own protocol was not breached. The failure was in a device that users trusted to generate secrets no one else could reproduce.

For a market that has spent years urging holders to move assets off exchanges and into personal custody, incidents like this contradict that message. The promise of self-custody is control, but control depends on hardware and software that most users cannot independently verify.

## What this means

The channel is confidence in self-custody, the practice the crypto industry has promoted as safer than leaving assets on exchanges. A key-generation flaw that lets attackers reconstruct private keys turns the safest-sounding option into a single point of failure, and every holder of the affected device is exposed regardless of their own security habits. The beneficiaries are regulated custodians and exchanges that can argue their infrastructure is more accountable, and the losers are the hardware vendors whose trust depends on flawless randomness.

## What to watch

- Identification of the specific device and firmware involved, because the scope of the flaw determines how many wallets remain at risk.
- Whether institutional custody providers cite the incident to argue for regulated custody over self-custody, which would shape how new capital enters the asset.
