Morning Edition · Saturday, August 1, 2026Published at 1:29 AM EDT · New York
Coldcard Firmware Flaw Lets Attackers Drain 594 Bitcoin From Self-Custody Wallets
A weak key-generation routine present since 2021 made seed phrases guessable, and thieves drained roughly $38 million from about 500 devices in 25 minutes.

A software defect in the Coldcard Mk3, one of the most widely used bitcoin hardware wallets, allowed attackers to reconstruct users' private keys and move funds without ever touching the physical device. CoinDesk reported that roughly 594 bitcoin, worth about $38 million, was drained across roughly 500 devices, with much of the theft carried out within about 25 minutes.
The root cause was weak randomness in key generation. Instead of relying on the chip's hardware random number generator, affected firmware derived seed material from weaker inputs tied to the device serial number and an internal counter, making the resulting seed phrases guessable. The flaw was present in Mk3 units running firmware 4.0.1 or later, dating to March 2021, which is why the drained wallets were overwhelmingly older, single-signature addresses that had sat untouched for years. Coinkite, the manufacturer, has released fixed firmware and urged owners of at-risk models to move coins to freshly generated keys immediately. Bitcoin Magazine put the total value exposed at more than $70 million once vulnerable but not-yet-drained balances are counted.
The disclosure carries a second, unusual detail. Coinkite founder Rodolfo Novak said an artificial-intelligence-assisted code review appears to have identified the latent bug, and researchers believe the attacker may have used the same class of tooling to find and exploit it at scale. Rival manufacturer Blockstream said its Jade device is unaffected because it generates keys differently. The stolen funds were consolidated into a small number of addresses and have not moved, and no recovery or attribution has been confirmed.
- If true, who benefits
Custodial platforms and spot bitcoin ETF issuers, whose pitch is that they absorb exactly this key-management risk, plus rival vendors like Blockstream marketing a different entropy design.
- The nuance
The 594 BTC drain and the weak-entropy root cause are confirmed by Coinkite and multiple outlets, but the AI-found-it claim is Novak's own supposition ("must assume," no forensic evidence) and the "pushes investors to ETFs" line is interested framing, not a measured flow.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The failure sits at the layer self-custody advocates treat as safest, the offline hardware key. Because the defect is in key generation rather than in a smart contract, no on-chain audit or multisig policy would have caught it for a single-signature user, and the exposed population is anyone who created a Mk3 seed since 2021. The direct beneficiaries are custodial products and spot exchange-traded funds (ETFs), which convert this kind of operational risk into a counterparty most investors already accept, and the losers are the hardware-wallet vendors whose entire business case is that you never have to trust a third party.
What to watch
- Whether the consolidated stolen coins move to a mixer, an exchange, or a blockchain-analytics-flagged address, which would signal an intent to cash out and possible attribution.
- Whether other hardware vendors disclose similar randomness weaknesses now that an AI-assisted review has shown how to find them, which would widen the affected population well beyond Coldcard.
- Net flows into spot bitcoin ETFs and custodial platforms in the coming weeks, a direct read on whether the scare pushes holders away from self-custody.
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · Bitcoin Magazine · Bitcoin Magazine
Part of a tracked trend
Hardware-Wallet Trust Erodes
Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.
More from this edition
- Aztec Ships Alpha V5, Putting Private Smart Contracts Live on Ethereum
- Tether Reports $1.5 Billion Quarterly Profit as Its Reserve Cushion Halves
- Aave Moves to Abandon Six Blockchains Earning Less Than $5,000 a Quarter
- IBM Chief Says Quantum Computing Will Generate Real Revenue Before 2030
- Circle Wins New York Trust Charter, Deepening the Regulated Path for USDC
- US Sanctions Two Iranian Firms That Took Bitcoin for Strait of Hormuz Shipping Insurance
- Uniswap Adds In-App Lending Through Morpho Vaults
- Miden Argues Practical Privacy Is the Gate to Blockchain's Next Phase
- Reward-Recycling Exploit Drains $578,000 From LULA as Smaller DeFi Hacks Persist
- Ondo Weighs a $500 Million Acquisition as Tokenized Securities Pass $36 Billion
- Strategy Posts $8.2 Billion Loss and Says It Will Keep Selling Bitcoin