The Polylog Crypto Intelligence Brief

Morning Edition · Tuesday, August 4, 2026Published at 1:45 AM EDT · New York

Coldcard Seed Flaw Losses Pass $114 Million as Attackers Keep Sweeping Wallets

A build error routed seed generation through a software random number generator. That cut the randomness in each seed (its entropy) to as low as 40 bits on older devices, leaving thousands of wallets an attacker can reconstruct offline.

Coldcard Seed Flaw Losses Pass $114 Million as Attackers Keep Sweeping Wallets

The theft of bitcoin from Coldcard hardware wallets has now run for a fifth day. Bitcoin Magazine now estimates more than $114 million taken in total, and Watcher Guru reported the figure crossing $100 million on Monday. CoinDesk described a fourth sweep of vulnerable addresses overnight. Bitcoin still trades near $64,000, up 1.9% over 24 hours.

The root cause is not a smart contract bug and not a physical attack on the device. It is a build error in the firmware from Coinkite, the Canadian company that manufactures Coldcard. A preprocessor guard checked only whether a configuration setting existed, not what value it held. As a result, the build linked seed generation to a software random number generator from MicroPython instead of the hardware random number generator. According to The Hacker News and Crypto Briefing, that software fallback was seeded from predictable startup values such as the device identifier and timer registers. Affected Mk2 and Mk3 firmware may have produced seeds carrying roughly 40 bits of entropy, and Mk4, Mk5 and Q devices roughly 72 bits. An attacker who can guess the startup conditions can reconstruct candidate seeds offline and then drain every address derived from them, with no network access to the device required.

The timeline is the part users are contesting. Crypto Briefing counts about 1,367 bitcoin taken from 4,585 addresses since July 30, with the first wave of more than 1,000 coins moving inside 41 minutes. That was roughly 30 hours before Coinkite published its advisory. Coinkite shipped patched firmware by August 1 and told holders whose seeds came from affected builds to move funds to new seeds, unless they had added independent entropy or used a strong passphrase. The Bitcointalk advisory thread carries the same instruction to act immediately. Funds have not been frozen or recovered, and no attribution has been made public.

Two arguments now run against each other. Coinkite's position is that a passphrase or user-supplied entropy protected careful holders, which shifts part of the exposure onto user practice. Holders answer that the whole proposition of a dedicated signing device is that they do not need to audit the manufacturer's build system. Both arguments can hold at once, and the practical result is identical. Seeds created on a specific range of firmware versions are guessable, and nothing the owner did after generating them changes that.

Veracity: Corroborated
88/100
If true, who benefits

Custodians, exchange-traded-fund issuers and regulated wallet competitors, who gain the argument that self-custody carries a manufacturer risk retail holders cannot audit, while Coinkite gains from framing losses as partly a user-practice failure.

The nuance

The defect and the sweeps are corroborated well beyond the cited outlets (Fortune, Fox Business, The Defiant), but the dollar totals are moving on-chain estimates that ranged from $38 million to $116 million within four days, and the article's claim that the first wave preceded Coinkite's advisory by roughly 30 hours sits against CoinDesk's account that post-mortems appeared the same evening, and the piece omits that the defect traces to a March 2021 commit and that Coinkite halted shipments and destroyed affected inventory.

An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.

What this means

This is a supply-chain failure inside the tool sold to eliminate counterparty risk, so the exposure runs directly to self-custody holders and indirectly to the wider case for personal key management. Every coin taken came from a device whose owner did exactly what the security guidance told them to do, which is the argument custodians and exchange-traded-fund issuers will now make to risk-averse holders. The offsetting force is that regulated custody concentrates keys with a small number of firms, so the choice on offer is between an audit failure at a device maker and a single institutional point of compromise.

What to watch

  • Whether the stolen coins move to mixing services or to exchanges, since exchange deposits create identifiable counterparties and a realistic path to freezing or attribution.
  • Whether Coinkite publishes a full independent audit of its build pipeline, which would show whether the guard error was isolated or one of a class of defects in how firmware is compiled and signed.
  • Whether other hardware wallet makers publish entropy verification results, because a second vendor with a similar defect would turn this from one company's error into an industry-wide assumption failure.

Observations to monitor, not financial advice.

Part of a tracked trend

Hardware-Wallet Trust Erodes

Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.

Share this article

Comments

0

No comments yet.