Morning Edition · Friday, August 7, 2026Published at 10:25 AM EDT · New York
A firmware build error routed seed generation through a software pseudorandom generator instead of the hardware's own randomness source, cutting effective entropy from 128 bits to as low as 40 bits on affected devices.

The fallout from the Coldcard hardware-wallet exploit disclosed on July 30 continues to move through Bitcoin's blockchain. Attackers drained roughly 1,816 bitcoin, worth about $116 million, from more than 5,200 addresses across four separate waves, and Galaxy Research has estimated total losses could reach $130 million once suspected additional waves are counted. The root cause was a build-configuration error in a Coldcard firmware release from 2021: instead of drawing randomness from the device's dedicated hardware random-number generator, affected units generated wallet seeds using a deterministic software pseudorandom generator, cutting effective entropy from the intended 128 bits down to as little as 40 bits on the oldest model and 72 bits on newer ones, low enough for a well-resourced attacker to brute-force the private keys.
CoinDesk reported that roughly 210,000 bitcoin has moved out of long-term holder wallets over the past week, a volume that likely reflects Coldcard users who were never directly stolen from rushing to migrate funds off the vulnerable firmware rather than a wave of ordinary selling. Because the flaw affects only wallets whose seeds were generated on the compromised firmware version, updating the device alone does not protect existing funds. Owners have to generate an entirely new seed and move their coins to a fresh wallet, a manual step that leaves any holder who has not yet acted still exposed.
Coldcard's maker has also temporarily suspended its automatic 120-day customer-data deletion policy, citing legal obligations tied to the ongoing incident, preserving records that would otherwise have been erased. Separately, Bitcoin Magazine reported that spot bitcoin exchange-traded fund inflows picked up following the disclosure, consistent with some self-custody holders opting to shift exposure into custodial, exchange-traded products rather than manage hardware-wallet risk themselves.
What this means
The Coldcard flaw was not a smart-contract bug or an exchange breach but a randomness failure baked into supposedly audited, certified hardware, which undercuts the core premise that hardware wallets are categorically safer than software custody. Retail and institutional holders who prize verifiable, non-custodial security are the ones directly exposed, and every dollar that migrates from self-custody into ETFs or exchange custody after an incident like this concentrates counterparty risk with a smaller number of large custodians instead of reducing it.
Part of a tracked trend
Hardware-Wallet Trust Erodes
Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.
Start a discussion in Townsquare.
More from this edition
What to watch
Observations to monitor, not financial advice.
Synthesized from: crypto.news · CoinDesk · Bitcoin Magazine
Comments
0No comments yet.