Morning Edition · Saturday, August 8, 2026Published at 1:55 AM EDT · New York
A firmware update shipped in March 2021 cut the randomness in device-generated seeds, letting attackers recompute private keys offline without ever touching a wallet.

Galaxy Research has now tied 1,719 bitcoin, roughly $111 million, to the Coldcard hardware wallet exploit with what it describes as high confidence, and expects the final figure to exceed $130 million as more addresses are traced. Bitcoin Magazine, surveying affected users, reports a median loss of about 1 BTC, which means the damage is spread across a large number of ordinary self-custody holders rather than concentrated in a few large balances.
The root cause is not a smart-contract bug or a stolen key. It is entropy. A firmware release pushed on March 17, 2021 degraded the device's random-number generation for on-device seed creation, producing roughly 72 bits of effective randomness on newer models instead of the intended 128, with older units weaker still, according to reporting on Galaxy's analysis. That gap is the entire attack. It moved seed recovery from computationally impossible to a search an adversary can run offline, with no physical access to the device and no interaction with the victim. Attackers precomputed candidate seeds and swept balances in coordinated waves beginning July 30. TRM Labs calls it the largest hardware wallet exploit of 2026.
Community advisories on Bitcointalk are telling affected owners to treat funds on any device seeded after that firmware date as at risk and to migrate to a seed generated with external entropy such as dice. There is no recovery mechanism. Bitcoin has no issuer that can freeze balances, which is the property that makes it censorship resistant and also the property that makes this loss final. Nothing has been recovered, and no attribution to a named actor has been published.
The market response has moved only one way. Bitcoin exchange-traded funds (ETFs) added close to $800 million in the days after the exploit surfaced. A defect in the tool that exists to remove counterparty risk is pushing capital toward products that reintroduce it.
Part of a tracked trend
Implementation Bugs, Not Just Exploits, Threaten Custody
Cryptographic implementation errors in wallets and signers (biased nonces, reused randomness, faulty derivation) keep surfacing as a distinct custody risk alongside smart-contract exploits, eroding the assumption that certified hardware protects keys.
Start a discussion in Townsquare.
More from this edition
Spot bitcoin funds, qualified custodians and rival hardware vendors gain the flows that leave self-custody, and Galaxy Research gains standing as the reference tracker for the theft.
The totals are moving estimates from one firm rather than settled figures, with Galaxy citing 1,596 bitcoin confirmed and up to 2,055 if a fourth wave is verified, and the piece leaves out that Coinkite disclosed the MicroPython pseudo-random generator substitution itself and shipped patched firmware for every affected model, while the $800 million of fund creations is correlation the article does not establish as caused by the theft.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The failure sits below the layer most holders check. Users can verify a firmware signature, a receive address and a seed backup, and still hold a key an attacker can regenerate, because randomness quality is invisible from the outside. Hardware vendors are exposed through liability and through the certification claims they market, and self-custody holders are exposed with no recourse, since bitcoin has no freeze function. The immediate flow effect is substitution: risk-averse holders move to ETFs and qualified custodians, which concentrates coins with a smaller number of regulated institutions and gives those institutions more influence over the asset's market structure.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Bitcoin Magazine · Polylog editors · Bitcointalk Dev & Technical · Bitcoin Magazine
Comments
1Aug 8, 12:39 PM · edited
Funds generated on device during the affected firmware window that have not yet been swept remain in the same 72 bit keyspace and face ongoing theft risk, not just historical loss.