Polylog
The Polylog Crypto Intelligence Brief

Morning Edition · Saturday, August 1, 2026Published at 1:29 AM EDT · New York

Coldcard Firmware Flaw Lets Attackers Drain 594 Bitcoin From Self-Custody Wallets

A weak key-generation routine present since 2021 made seed phrases guessable, and thieves drained roughly $38 million from about 500 devices in 25 minutes.

Coldcard Firmware Flaw Lets Attackers Drain 594 Bitcoin From Self-Custody Wallets

A software defect in the Coldcard Mk3, one of the most widely used bitcoin hardware wallets, allowed attackers to reconstruct users' private keys and move funds without ever touching the physical device. CoinDesk reported that roughly 594 bitcoin, worth about $38 million, was drained across roughly 500 devices, with much of the theft carried out within about 25 minutes.

The root cause was weak randomness in key generation. Instead of relying on the chip's hardware random number generator, affected firmware derived seed material from weaker inputs tied to the device serial number and an internal counter, making the resulting seed phrases guessable. The flaw was present in Mk3 units running firmware 4.0.1 or later, dating to March 2021, which is why the drained wallets were overwhelmingly older, single-signature addresses that had sat untouched for years. Coinkite, the manufacturer, has released fixed firmware and urged owners of at-risk models to move coins to freshly generated keys immediately. Bitcoin Magazine put the total value exposed at more than $70 million once vulnerable but not-yet-drained balances are counted.

The disclosure carries a second, unusual detail. Coinkite founder Rodolfo Novak said an artificial-intelligence-assisted code review appears to have identified the latent bug, and researchers believe the attacker may have used the same class of tooling to find and exploit it at scale. Rival manufacturer Blockstream said its Jade device is unaffected because it generates keys differently. The stolen funds were consolidated into a small number of addresses and have not moved, and no recovery or attribution has been confirmed.

Veracity: Corroborated
91/100
If true, who benefits

Custodial platforms and spot bitcoin ETF issuers, whose pitch is that they absorb exactly this key-management risk, plus rival vendors like Blockstream marketing a different entropy design.

The nuance

The 594 BTC drain and the weak-entropy root cause are confirmed by Coinkite and multiple outlets, but the AI-found-it claim is Novak's own supposition ("must assume," no forensic evidence) and the "pushes investors to ETFs" line is interested framing, not a measured flow.

An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.

What this means

The failure sits at the layer self-custody advocates treat as safest, the offline hardware key. Because the defect is in key generation rather than in a smart contract, no on-chain audit or multisig policy would have caught it for a single-signature user, and the exposed population is anyone who created a Mk3 seed since 2021. The direct beneficiaries are custodial products and spot exchange-traded funds (ETFs), which convert this kind of operational risk into a counterparty most investors already accept, and the losers are the hardware-wallet vendors whose entire business case is that you never have to trust a third party.

What to watch

  • Whether the consolidated stolen coins move to a mixer, an exchange, or a blockchain-analytics-flagged address, which would signal an intent to cash out and possible attribution.
  • Whether other hardware vendors disclose similar randomness weaknesses now that an AI-assisted review has shown how to find them, which would widen the affected population well beyond Coldcard.
  • Net flows into spot bitcoin ETFs and custodial platforms in the coming weeks, a direct read on whether the scare pushes holders away from self-custody.

Observations to monitor, not financial advice.

3 sources

Synthesized from: CoinDesk · Bitcoin Magazine · Bitcoin Magazine

Part of a tracked trend

Hardware-Wallet Trust Erodes

Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.