# Coldcard's Five-Year Entropy Defect Accounts for Roughly a Tenth of 2026's $1.2 Billion in Crypto Theft

Firmware shipped in March 2021 generated seeds with a software pseudorandom number generator instead of the device's hardware chip, and attackers used the resulting weak keys to take 1,816 BTC from more than 5,200 addresses.

- Published: 2026-08-09T06:30:14.346Z
- Canonical: https://polylog.news/crypto/2026-08-09/coldcard-s-five-year-entropy-defect-accounts-for-roughly-a-t
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Bitcointalk Dev &amp; Technical](https://bitcointalk.org/index.php?topic=5589927.0), [Polylog editors](https://polylog.news), [CoinDesk](https://www.coindesk.com/business/2026/08/08/hardware-wallet-sales-in-russia-more-than-double-as-new-crypto-rules-near)

The running total of stolen crypto in 2026 has passed $1.2 billion across 276 incidents, and the Coldcard hardware wallet failure alone [accounts for close to a tenth of that sum](https://t.me/GokuCryptoNews/20320). The [emergency notice on Bitcointalk](https://bitcointalk.org/index.php?topic=5589927.0) tells Coldcard owners to treat any seed generated since March 2021 as compromised, regardless of what firmware the device runs today.

The root cause is not a smart contract and not a phishing message. Firmware version 4.0.0 caused affected devices to skip the STM32 chip's hardware random number generator during seed creation and fall back to MicroPython's Yasmarang software pseudorandom generator. On Mk3 units, that [collapsed effective key entropy from 128 bits to as little as 40 bits](https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack), a search space small enough to enumerate. Beginning on 30 July, attackers moved 1,816 BTC, worth about $116 million, out of more than 5,200 addresses in four waves. One wave took 1,082 BTC from 1,196 addresses [in 41 minutes](https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html). The keys were never stolen. They were derived.

A second, cruder attack surface is open at the same time. A counterfeit Trezor website has been appearing at the top of Google results as a sponsored listing, and at least one user [says they lost their entire holdings](https://t.me/GokuCryptoNews/20318) after clicking through. That failure requires no cryptographic insight, only advertising spend.

Demand for the devices is nonetheless rising in places where custodial access is restricted. In Russia, hardware wallet sales [more than doubled](https://www.coindesk.com/business/2026/08/08/hardware-wallet-sales-in-russia-more-than-double-as-new-crypto-rules-near) as new crypto rules approach, with the marketplace Wildberries reporting an average price 13% lower at 7,900 rubles and the electronics chain M.Video widening its range. Neither retailer identified what is driving the demand.

## What this means

Self-custody transfers counterparty risk to the manufacturer's code, and a randomness defect is the worst version of that trade because it is silent, retroactive and unfixable by updating: coins generated with weak entropy stay vulnerable until they are moved to a new seed. The exposed parties are long-term holders who did exactly what the security guidance told them to do. Each incident of this kind strengthens the commercial case for regulated custodians and exchange-traded products, which is a direct transfer of assets from individual key management to institutional balance sheets.

## What to watch

- Whether the number of affected addresses keeps rising, which would show that attackers are still working through the reduced key space rather than having exhausted it.
- Whether other hardware vendors publish independent entropy audits of their own key generation, since the same class of fallback bug is easy to introduce and hard to observe from outside.
- Whether exchange-traded fund inflows and custodial account openings pick up among long-term holders, which would indicate the incident is changing custody behaviour rather than just the conversation.
