Morning Edition · Sunday, August 2, 2026Published at 1:31 AM EDT · New York
Coldcard Cold-Wallet Theft Nears $89 Million as a Five-Year-Old Firmware Bug Reproduces Users' Keys
Galaxy Research counts three rounds that drained about 1,367 bitcoin from 4,585 single-signature wallets, all traceable to seeds that a 2021 update generated with predictable software randomness.

An attacker has drained roughly 1,367 bitcoin, worth close to $89 million at current prices, from about 4,585 Coldcard hardware wallets, according to CoinDesk's account of Galaxy Research's on-chain mapping. The loss started at $38 million late last month and has since moved through three separate rounds. The most recent round targeted smaller balances and used more complex transaction patterns to collect the funds.
The root cause is not a broken chip or a stolen recovery phrase. A firmware integration error shipped in March 2021 routed seed generation on affected Coldcard devices to a deterministic software pseudorandom number generator instead of the STM32 chip's hardware random number generator. Because the software fallback was seeded from fixed factory metadata and predictable clock values, an attacker could reconstruct the private keys off-chain without ever touching a victim's device, seed card, or computer. Every drained wallet used a single signature and held more than roughly 0.15 bitcoin, and the affected coins span 2021 through 2026, which matches the age of the flaw.
Coinkite, Coldcard's maker, has released fixed firmware and urged users to move funds to newly generated wallets. The company's founder, who goes by NVK, said that code review assisted by artificial intelligence can now find hidden bugs faster than experienced human auditors, and that the same kind of tooling may have helped whoever found this one. Watcher Guru put the running total above $88 million before the third round pushed it higher.
The neutral read is that this is a failure of the randomness used to create the keys, not a compromise of the secure-element hardware. That distinction matters for who is exposed. The certified hardware operated correctly. The bug was in how the software requested randomness, which means no amount of physical tamper resistance would have protected a key that was predictable from the moment it was created.
- If true, who benefits
Custodians, multisig providers, and spot bitcoin ETF issuers gain as each self-custody failure pushes risk-averse holders toward managed products, while rival wallet makers gain from Coinkite's damaged reputation.
- The nuance
The $89 million figure and 4,585-wallet count are Galaxy Research's on-chain estimates, and the claim that artificial intelligence aided the attacker is Coinkite founder NVK's speculation rather than established fact.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The loss comes from the randomness used to generate the keys, not from device theft, so it affects exactly the population that chose self-custody hardware for safety. Holders of any single-signature wallet created on affected firmware between 2021 and 2026 are exposed, and dormant balances are the most valuable targets because those keys were always reconstructable. Each incident of this kind pushes risk-averse holders toward multisig, custodians, and spot exchange-traded funds (ETFs), which is the opposite of the self-custody promise that hardware wallets are sold on.
What to watch
- Whether Galaxy Research or chain-analytics firms attribute the three rounds to one operator or several, which would tell holders whether the exploit method has spread beyond a single actor.
- Whether other wallet makers that use software randomness fallbacks disclose audits, since the same integration mistake could exist elsewhere.
- Net flows into spot bitcoin ETFs and custodial products in the days after the theft, a direct measure of whether confidence in self-custody is weakening.
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · Bitcoin Magazine · Polylog editors
Part of a tracked trend
Hardware-Wallet Trust Erodes
Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.
More from this edition
- Aztec Launches Alpha V5, an Ethereum Layer-2 That Proves Private Transactions on the User's Own Device
- Strategy Holds STRC Dividend at 12 Percent After $8.2 Billion Loss and Its First Bitcoin Sale in Four Years
- SEC Reopens Nasdaq Bitcoin Options Approval as CME Argues the Contracts Belong to the CFTC
- Index Coop Issuance Contract Hit by a Time-of-Check Bug as DeFi Exploit Losses Keep Compounding
- Tokenized Stock Trading Jumped 288 Percent in July, but a Single Nasdaq-100 Token Drove Most of It
- Miden Pitches 'Practical Privacy' With Guardian, a Recovery Layer for Confidential Accounts
- Russia Bans Crypto Mining in Moscow Region Until 2032, Citing Power-Grid Strain
- Bank of Italy Study Finds Stablecoin Remittances Often No Cheaper Than Traditional Transfers
- Bitcoin Mining Difficulty Falls 14 Percent From Its Yearly High as Weak Revenue Forces Operators Offline
- Solana Foundation's New Security Chief Warns AI Is Making Crypto Scams Harder to Detect
- US and Japan Mount Joint Yen Intervention as Bessent Notes Point to a $5–10 Billion Purchase