Morning Edition · Sunday, August 9, 2026Published at 2:30 AM EDT · New York
Firmware shipped in March 2021 generated seeds with a software pseudorandom number generator instead of the device's hardware chip, and attackers used the resulting weak keys to take 1,816 BTC from more than 5,200 addresses.

The running total of stolen crypto in 2026 has passed $1.2 billion across 276 incidents, and the Coldcard hardware wallet failure alone accounts for close to a tenth of that sum. The emergency notice on Bitcointalk tells Coldcard owners to treat any seed generated since March 2021 as compromised, regardless of what firmware the device runs today.
The root cause is not a smart contract and not a phishing message. Firmware version 4.0.0 caused affected devices to skip the STM32 chip's hardware random number generator during seed creation and fall back to MicroPython's Yasmarang software pseudorandom generator. On Mk3 units, that collapsed effective key entropy from 128 bits to as little as 40 bits, a search space small enough to enumerate. Beginning on 30 July, attackers moved 1,816 BTC, worth about $116 million, out of more than 5,200 addresses in four waves. One wave took 1,082 BTC from 1,196 addresses in 41 minutes. The keys were never stolen. They were derived.
A second, cruder attack surface is open at the same time. A counterfeit Trezor website has been appearing at the top of Google results as a sponsored listing, and at least one user says they lost their entire holdings after clicking through. That failure requires no cryptographic insight, only advertising spend.
Demand for the devices is nonetheless rising in places where custodial access is restricted. In Russia, hardware wallet sales more than doubled as new crypto rules approach, with the marketplace Wildberries reporting an average price 13% lower at 7,900 rubles and the electronics chain M.Video widening its range. Neither retailer identified what is driving the demand.
Part of a tracked trend
Implementation Bugs, Not Just Exploits, Threaten Custody
Cryptographic implementation errors in wallets and signers (biased nonces, reused randomness, faulty derivation) keep surfacing as a distinct custody risk alongside smart-contract exploits, eroding the assumption that certified hardware protects keys.
Start a discussion in Townsquare.
More from this edition
Regulated custodians, exchange-traded product issuers and competing hardware vendors, each of which gains from a defect that makes individual key management look like the riskier option.
The loss total is not settled, with published estimates ranging from about $38 million traced on-chain to $116 million and higher, so the claim that this single failure is roughly a tenth of the year's theft rests on the largest of those numbers rather than a confirmed one.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Self-custody transfers counterparty risk to the manufacturer's code, and a randomness defect is the worst version of that trade because it is silent, retroactive and unfixable by updating: coins generated with weak entropy stay vulnerable until they are moved to a new seed. The exposed parties are long-term holders who did exactly what the security guidance told them to do. Each incident of this kind strengthens the commercial case for regulated custodians and exchange-traded products, which is a direct transfer of assets from individual key management to institutional balance sheets.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Bitcointalk Dev & Technical · Polylog editors · CoinDesk
Comments
0No comments yet.