Polylog
The Polylog Crypto Intelligence Brief

Morning Edition · Sunday, August 2, 2026Published at 1:31 AM EDT · New York

Coldcard Cold-Wallet Theft Nears $89 Million as a Five-Year-Old Firmware Bug Reproduces Users' Keys

Galaxy Research counts three rounds that drained about 1,367 bitcoin from 4,585 single-signature wallets, all traceable to seeds that a 2021 update generated with predictable software randomness.

Coldcard Cold-Wallet Theft Nears $89 Million as a Five-Year-Old Firmware Bug Reproduces Users' Keys

An attacker has drained roughly 1,367 bitcoin, worth close to $89 million at current prices, from about 4,585 Coldcard hardware wallets, according to CoinDesk's account of Galaxy Research's on-chain mapping. The loss started at $38 million late last month and has since moved through three separate rounds. The most recent round targeted smaller balances and used more complex transaction patterns to collect the funds.

The root cause is not a broken chip or a stolen recovery phrase. A firmware integration error shipped in March 2021 routed seed generation on affected Coldcard devices to a deterministic software pseudorandom number generator instead of the STM32 chip's hardware random number generator. Because the software fallback was seeded from fixed factory metadata and predictable clock values, an attacker could reconstruct the private keys off-chain without ever touching a victim's device, seed card, or computer. Every drained wallet used a single signature and held more than roughly 0.15 bitcoin, and the affected coins span 2021 through 2026, which matches the age of the flaw.

Coinkite, Coldcard's maker, has released fixed firmware and urged users to move funds to newly generated wallets. The company's founder, who goes by NVK, said that code review assisted by artificial intelligence can now find hidden bugs faster than experienced human auditors, and that the same kind of tooling may have helped whoever found this one. Watcher Guru put the running total above $88 million before the third round pushed it higher.

The neutral read is that this is a failure of the randomness used to create the keys, not a compromise of the secure-element hardware. That distinction matters for who is exposed. The certified hardware operated correctly. The bug was in how the software requested randomness, which means no amount of physical tamper resistance would have protected a key that was predictable from the moment it was created.

Veracity: Corroborated
88/100
If true, who benefits

Custodians, multisig providers, and spot bitcoin ETF issuers gain as each self-custody failure pushes risk-averse holders toward managed products, while rival wallet makers gain from Coinkite's damaged reputation.

The nuance

The $89 million figure and 4,585-wallet count are Galaxy Research's on-chain estimates, and the claim that artificial intelligence aided the attacker is Coinkite founder NVK's speculation rather than established fact.

An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.

What this means

The loss comes from the randomness used to generate the keys, not from device theft, so it affects exactly the population that chose self-custody hardware for safety. Holders of any single-signature wallet created on affected firmware between 2021 and 2026 are exposed, and dormant balances are the most valuable targets because those keys were always reconstructable. Each incident of this kind pushes risk-averse holders toward multisig, custodians, and spot exchange-traded funds (ETFs), which is the opposite of the self-custody promise that hardware wallets are sold on.

What to watch

  • Whether Galaxy Research or chain-analytics firms attribute the three rounds to one operator or several, which would tell holders whether the exploit method has spread beyond a single actor.
  • Whether other wallet makers that use software randomness fallbacks disclose audits, since the same integration mistake could exist elsewhere.
  • Net flows into spot bitcoin ETFs and custodial products in the days after the theft, a direct measure of whether confidence in self-custody is weakening.

Observations to monitor, not financial advice.

3 sources

Synthesized from: CoinDesk · Bitcoin Magazine · Polylog editors

Part of a tracked trend

Hardware-Wallet Trust Erodes

Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.