Skip to content
Signal21

Newsletter

Never miss a signal

Get every new signal the moment it lands — the three-horizon Bitcoin read and company coverage, straight to your inbox. One email per update, no noise. Unsubscribe anytime.

One step left

Now confirm it from your inbox

We sent a confirmation email to your address. Click the button inside it and you’re in — without that click, nothing is subscribed.

Not seeing it? Check your spam folder — early deliveries sometimes land there. Marking it “not spam” makes sure you get the signals.

Markets · 2026-08-03

How a random-number bug drained Coldcard wallets

Signal21 Editorial Desk ·

A Bitcoin wallet's entire security rests on one thing: a secret number chosen at random that no one else can guess. The twelve or twenty-four words a wallet asks you to back up are just a way of writing that number down; every key and address is derived from it. If the number is truly unpredictable, the wallet is safe. If it can be reproduced, the wallet is not — and that is what went wrong for some owners of Coldcard, a Bitcoin hardware wallet made by Coinkite.

According to Galaxy Research, whose figures were reported by CoinDesk and others, roughly 1,367 BTC — around $88.6 million at the time — was drained from about 4,585 addresses across coordinated waves. The largest, reported by The Hacker News, swept about 1,082 BTC (near $70 million) in roughly 41 minutes on 30 July 2026, the same day Coinkite disclosed the underlying flaw.

The cause was a single change to the firmware on 1 March 2021. A hardware wallet is supposed to draw its randomness from a dedicated physical component — on the Coldcard, the chip's hardware random-number generator. The 2021 change quietly rerouted seed creation to a software fallback instead: a routine meant for devices that lack a hardware generator, which only produces numbers that look random from a predictable starting point. The device had the right component; at the critical moment, the wrong one did the work. The bug survived for over five years because a code check confirmed the function existed, not that it was actually being used.

The result was a shrunken haystack. Coinkite's advisory scopes the confirmed exploit to Coldcard Mk2 and Mk3 devices, where researchers put the effective randomness near 40 bits instead of the intended 128 — few enough combinations that an attacker could generate plausible seeds offline, derive their addresses, check the public blockchain for funded ones, and empty them. Coinkite and Block state that the Mk4, Mk5 and Coldcard Q were not affected by the active exploit, thanks to an additional entropy source, though the company notes seeds made on some earlier versions of those models carried a smaller margin than intended.

Two points matter for anyone who used an affected device. First, a patch alone does not fix it: a seed born without enough randomness stays weak for life, and the risk follows the seed, not the device — importing it into a different wallet changes nothing. The only remedy is to install corrected firmware, generate a brand-new seed, and move the coins to the new addresses. Second, Bitcoin itself was not hacked. Its cryptography worked exactly as designed; the network assumes a private key was generated from real randomness and has no way to check whether the number behind it came from physical noise or from software that produced too little.

The episode is an uncomfortable one for self-custody, the practice of holding your own keys rather than trusting a third party. It is a setback for confidence, not a verdict: the failure was one vendor's implementation, not a flaw in the idea that people can hold their own Bitcoin. For those who understand the trade-offs, self-custody remains a legitimate choice — and a reminder that its whole promise depends on the quietest, least glamorous part of the machine working correctly.

This is market analysis, not a recommendation to buy or sell any security.

  • Whether Galaxy's tally rises as more affected addresses are identified, or settles near the current estimate.
  • Whether the episode dents confidence in self-custody broadly, or is read as a single vendor's implementation error.

All Markets reads →