Morning Edition · Tuesday, August 18, 2026Published at 1:51 AM EDT · New York
A 2021 build error silently bound seed generation to a software random number generator, cutting key strength from the intended 128 bits to as low as 40 on some devices.

Losses from the attack on Coinkite's Coldcard hardware wallets now stand at $115 million in bitcoin, according to Galaxy Digital's latest figures. Galaxy Research has traced 1,719 BTC stolen across three waves and by at least 15 separate attackers, and has said the eventual total could exceed $130 million.
The root cause is not a smart contract and not a phishing campaign. During a 2021 migration to Bitcoin Core's libsecp256k1 library, Coldcard's seed generation began drawing from MicroPython's software pseudorandom number generator rather than the device's dedicated hardware random number generator. Coinkite's own technical account describes a fallback generator seeded from the chip's unique identifier and timer registers. The two functions shared a signature, so the build completed without error. Seeds created on firmware 4.0.1 and later left an effective search space of roughly 40 bits on Mk3 devices, and about 72 bits on the Mk4, Q and Mk5, which mixed in entropy from their secure elements. The design target was 128 bits.
An attacker drained about 594 BTC from roughly 500 wallets in 25 minutes on July 31. Coinkite has since shipped emergency firmware for all affected models and says it destroyed remaining vulnerable inventory. Galaxy reports that roughly 90 percent of the stolen coins have not moved and remain traceable on-chain.
Zach Herbert, chief executive of the competing hardware wallet maker Foundation, argued in CoinDesk that a community organized around verification instead deferred for five years to one vendor's reputation. Coinkite has also said artificial intelligence probably helped the attacker locate the defect, and that its own review of the same code, also assisted by artificial intelligence, missed it.
Regulated custodians, spot bitcoin exchange-traded fund issuers and rival hardware wallet makers gain from a self-custody failure, and Galaxy, which sells institutional custody and trading services, is also the firm supplying the loss estimates.
Part of a tracked trend
Implementation Bugs, Not Just Exploits, Threaten Custody
Cryptographic implementation errors in wallets and signers (biased nonces, reused randomness, faulty derivation) keep surfacing as a distinct custody risk alongside smart-contract exploits, eroding the assumption that certified hardware protects keys.
Start a discussion in Townsquare.
More from this edition
The total is a moving on-chain estimate rather than an audited figure, with Galaxy separately citing 1,596 BTC confirmed and a suspected fourth wave taking the range toward 2,055 BTC, and Coinkite's statement that artificial intelligence helped the attacker locate the defect is the vendor's own assessment, not an established finding.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The failure sits in key generation, which no on-chain audit, multisignature policy or cold storage discipline can compensate for. Holders who generated seeds on affected firmware after March 2021 are exposed regardless of how carefully they have behaved since, and the only remedy is migrating funds to keys made with verified entropy. The commercial consequence runs against self-custody hardware and toward regulated custodians and exchange-traded products, because a buyer cannot audit a closed build pipeline but can read a custodian's insurance and attestations. Manufacturers now face demand for reproducible builds and independent entropy testing as a condition of sale rather than a differentiator.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Bitcoin Magazine · CoinDesk · Rekt News
Comments
1Aug 19, 2:52 AM · edited
Because Coldcard uses hierarchical deterministic wallets, recovering a device's 40 bit seed yields every address it ever generated, so the traceable 1,719 BTC figure understates total exposure.