The Polylog Crypto Intelligence Brief

Morning Edition · Tuesday, August 4, 2026Published at 1:32 AM EDT · New York

Coldcard Seed-Generation Flaw Pushes Bitcoin Losses Above $114 Million as Sweeps Continue

Galaxy Research traced the thefts to a March 2021 firmware change that routed key generation to a predictable software random-number generator. Wallets untouched for years are now moving coins.

Coldcard Seed-Generation Flaw Pushes Bitcoin Losses Above $114 Million as Sweeps Continue

The theft from bitcoin addresses created by Coldcard hardware wallets is continuing. Bitcoin Magazine puts the running total above $114 million, and Watcher Guru reported the figure passing $100 million late on Monday. Estimates differ by counting method and by the hour. Galaxy Research, which mapped the drains, counted 1,367 BTC worth about $88.6 million across 4,585 addresses in its confirmed set. By contrast, Fortune reported roughly 1,816 BTC, close to $116 million, already moved off affected wallets. The first set of drains on 30 July emptied 1,196 addresses in 41 minutes.

The root cause is a failure of randomness, not a defect in bitcoin itself. According to Galaxy's analysis, a firmware integration error introduced in March 2021 routed recovery-seed generation to a deterministic software pseudorandom number generator instead of the hardware random number generator on the device's STM32 chip. An attacker who can narrow down the device identifier, the timer state and prior generator calls can reproduce candidate key streams offline, derive the resulting addresses and match them against the public ledger. No physical access to any device was required.

Coinkite, the Canadian manufacturer, has published patched firmware, halted shipments and destroyed the remaining affected stock. It is telling users to move funds to newly generated seeds immediately. Migration is the only remedy, because the device alone cannot show its owner that a seed was safely generated.

A second effect is now visible on-chain. CoinDesk reports a wallet dormant since 2013 moved $31 million on Monday, part of a wider set of old coins in motion since the hack. Some of that is precautionary migration by holders who cannot rule out exposure. Some of it is the attackers. Block data alone cannot separate the two in real time.

Veracity: Corroborated
91/100
If true, who benefits

Custodians, spot bitcoin exchange-traded fund issuers and Coinkite's rivals gain if self-custody looks unsafe, while the attackers gain from every hour holders delay migrating.

The nuance

Coinkite has confirmed the randomness defect and Galaxy's 1,367 BTC figure is the only audited set, so the $114 million to $116 million running totals mix confirmed sweeps with coin movements that could equally be owners migrating, and nobody has publicly identified who moved the 2013-era wallet.

An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.

What this means

The failure sits in key generation, the one layer self-custody users cannot audit themselves, so the cost falls on long-term holders who followed the security guidance exactly. The immediate channel is forced migration. Every affected holder must move coins, which adds real spot supply and exchange deposits while bitcoin trades near $63,000. The wider channel is demand shifting from personal key management toward custodians and exchange-traded funds, the opposite of what hardware wallets were sold to achieve, and that shift affects Coinkite's competitors as much as Coinkite.

What to watch

  • Whether the drains stop once patched-firmware migration spreads, which would confirm that the population of vulnerable seeds is bounded rather than open-ended.
  • Whether other hardware wallet vendors publish audits of their own randomness paths, since a single silent fallback to software entropy is the kind of defect that recurs across firmware codebases.
  • Continued movement of coins dormant for a decade or more, which indicates how much of the old holder base is migrating rather than selling.

Observations to monitor, not financial advice.

Part of a tracked trend

Hardware-Wallet Trust Erodes

Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.

Share this article

Comments

0

No comments yet.