# Coldcard Key-Generation Flaw Pushes Bitcoin Losses Past $130 Million

A firmware fallback shipped in March 2021 made seed phrases predictable, and the wallet holding roughly $36 million of the proceeds has filled with messages from victims.

- Published: 2026-08-05T05:44:56.721Z
- Canonical: https://polylog.news/crypto/2026-08-05/coldcard-key-generation-flaw-pushes-bitcoin-losses-past-130
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CoinDesk](https://www.coindesk.com/markets/2026/08/05/you-stole-please-return-some-coldcard-hacker-s-wallet-becomes-a-graffiti-wall-of-pleas-and-hustles), [Bitcoin Magazine](https://bitcoinmagazine.com/news/32-million-in-dormant-bitcoin-moves), [Bitcoin Magazine (culture)](https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody), [CryptoSlate](https://cryptoslate.com/why-ai-is-now-a-bigger-threat-to-bitcoin-than-quantum-computers-in-the-short-term/), [Bitcointalk Dev &amp; Technical](https://bitcointalk.org/index.php?topic=5589927.0)

The theft began with a single 25-minute transfer of 594 bitcoin. It has since become one of the largest self-custody failures recorded in the Bitcoin ecosystem. Blockchain monitoring firms now put total losses [above $130 million](https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/), up from the roughly $89 million counted across about 4,500 addresses [earlier this week](https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million).

The root cause is not a smart contract and not a compromised exchange. A firmware release shipped in March 2021 by Coinkite, the Canadian manufacturer of the Coldcard hardware wallet, let affected devices skip the dedicated hardware randomness generator. Those devices fell back to software key generation seeded with non-secret chip data, including device serial numbers. Anyone who reconstructed that fallback could recompute the seed phrases and spend the coins. The devices never had to be connected to the internet, which is precisely the property owners bought them for. Coinkite has published fixed firmware, and the [warning circulating on Bitcointalk](https://bitcointalk.org/index.php?topic=5589927.0) tells holders to update, generate a new seed, and move funds, in that order.

Two consequences arrived on Wednesday. Bitcoin Magazine reported that close to [$32 million of bitcoin moved for the first time in 12 years](https://bitcoinmagazine.com/news/32-million-in-dormant-bitcoin-moves), a category of dormant supply that had been treated as effectively lost. The address holding roughly $36 million of the stolen coins [has filled with messages](https://www.coindesk.com/markets/2026/08/05/you-stole-please-return-some-coldcard-hacker-s-wallet-becomes-a-graffiti-wall-of-pleas-and-hustles) paid for by victims asking for partial returns and by strangers advertising to the attacker. The public ledger that recorded the theft now also records those appeals.

The industry argument that follows is about what self-custody actually protects against. Bitcoin Magazine's response is that abandoning personal key management [would abandon the point of the asset](https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody), and that the historical lesson is not to trust custodians instead. CryptoSlate's counter-argument is narrower and harder to dismiss. Offline keys still depend on entropy, firmware, signing logic, and recovery paths, all written by fallible people, which makes [software quality a more immediate threat than quantum computing](https://cryptoslate.com/why-ai-is-now-a-bigger-threat-to-bitcoin-than-quantum-computers-in-the-short-term/). Both positions accept the same fact. The failure was in an implementation, not in the protocol.

## What this means

Every holder of a Coldcard-generated single-signature wallet from the affected firmware period is exposed, and the exposure is retroactive because a bad seed cannot be patched after the fact. The commercial effect points in the other direction. Exchange-traded funds and regulated custodians gain from each self-custody failure, because the marginal risk-averse holder compares an audited counterparty against a device whose random-number path he cannot inspect. Manufacturers face the second-order cost, since attestation and third-party entropy verification stop being optional selling points and start being purchase requirements.

## What to watch

- Whether the loss total keeps climbing past $130 million, which indicates how many affected devices still hold funds that have not been migrated to new seeds.
- Whether other hardware-wallet vendors publish independent entropy audits or open their key-generation code, the most direct way to convert a competitor's failure into market share.
- Movement in more long-dormant addresses, which would show the exploit reaching coins whose owners are inactive and unlikely to see any warning.
