# Coldcard Seed Flaw Losses Reach an Estimated $130 Million as Decade-Old Bitcoin Wallets Move

A 2021 firmware build error routed seed generation through software randomness instead of the secure chip. Some wallets ended up with roughly 40 bits of entropy, which made their keys guessable years later.

- Published: 2026-08-05T05:31:30.193Z
- Canonical: https://polylog.news/crypto/2026-08-05/coldcard-seed-flaw-losses-reach-an-estimated-130-million-as
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CoinDesk](https://www.coindesk.com/markets/2026/08/05/you-stole-please-return-some-coldcard-hacker-s-wallet-becomes-a-graffiti-wall-of-pleas-and-hustles), [Bitcoin Magazine](https://bitcoinmagazine.com/news/32-million-in-dormant-bitcoin-moves), [Bitcoin Magazine (opinion)](https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody), [CryptoSlate](https://cryptoslate.com/why-ai-is-now-a-bigger-threat-to-bitcoin-than-quantum-computers-in-the-short-term/), [Bitcointalk Dev &amp; Technical](https://bitcointalk.org/index.php?topic=5589927.0</source)

The theft from Coldcard hardware wallets began on 30 July, and the total keeps rising. Researchers at Galaxy count 1,596 BTC taken from about 7,300 addresses across three confirmed waves. They have flagged a fourth wave they have not yet confirmed, which would push the total toward 2,000 BTC, [or roughly $130 million](https://www.theblock.co/post/410533/coldcard-hack-130-million-galaxy-research). [TechCrunch reported the same scale](https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/) on Tuesday.

The cause is not a smart contract and not a remote intrusion. A build error in a March 2021 firmware release by the Canadian manufacturer Coinkite sent seed generation through a software random number generator instead of the device's hardware source. On Mk3 devices running versions 4.0.1 through 4.1.9, [the resulting recovery seeds carried about 40 bits of entropy rather than the intended 128](https://cryptobriefing.com/coldcard-firmware-flaw-bitcoin-hack-89-million/), which puts them within reach of a brute-force search. Later models are estimated at roughly 72 bits. The first wave drained [594 BTC from around 500 dormant addresses in under 30 minutes](https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep). Coinkite published patched firmware within about two days, and users are being told to move funds to seeds generated on unaffected devices, [as the emergency notice on Bitcointalk sets out](https://bitcointalk.org/index.php?topic=5589927.0). No attacker has been identified, and none of the stolen coins have been frozen or recovered.

Holders are responding on-chain. A wallet that had not spent since 2013 moved 500 BTC worth close to $32 million, and [Bitcoin Magazine reports the transfer came as the estimated loss reached $130 million](https://bitcoinmagazine.com/news/32-million-in-dormant-bitcoin-moves). Victims and opportunists are now paying transaction fees to attach messages to the thief's main address, some asking for the coins back and some advertising services, [CoinDesk reports](https://www.coindesk.com/markets/2026/08/05/you-stole-please-return-some-coldcard-hacker-s-wallet-becomes-a-graffiti-wall-of-pleas-and-hustles).

The argument now running through Bitcoin's technical community is about what conclusion to draw. [Bitcoin Magazine argues that abandoning self-custody would surrender the property Bitcoin exists to provide](https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody), and that the failure was one vendor's build process rather than the principle itself. [CryptoSlate makes the narrower engineering point](https://cryptoslate.com/why-ai-is-now-a-bigger-threat-to-bitcoin-than-quantum-computers-in-the-short-term/) that an offline key still depends on entropy, firmware, signing software and recovery software, and that machine-assisted code review is now finding those defects faster than quantum computing threatens elliptic-curve keys. Both readings identify the same weak layer, which is the implementation rather than the cryptography.

## What this means

The loss channel here is manufacturing quality control, not protocol design, and it falls on long-term self-custody holders who bought a device precisely to avoid counterparty risk. Every wallet vendor now faces a demand to prove how its entropy is sourced and audited. The immediate beneficiaries are custodians, exchange-traded products and multi-vendor multisig providers, which replace a single undetected code defect with diversified, insured exposure. Two outcomes are possible. Either vendors publish reproducible builds and entropy audits and self-custody keeps its user base, or repeated defects push risk-averse holders into regulated custody and concentrate coins with a handful of institutions.

## What to watch

- Whether Coinkite discloses how many devices shipped with the defective seed path, which determines how much bitcoin is still sitting on guessable keys.
- Whether other hardware-wallet makers publish independent entropy audits. Silence would suggest the industry has no routine test for the exact failure that occurred here.
- Continued movement of coins dormant for five years or more, which shows whether long-term holders are relocating keys or selling.
