

In what has quickly become one of the most sobering events in cryptocurrency history, over $100 million in Bitcoin has been systematically drained from thousands of Coldcard hardware wallets. Widely regarded by security professionals as the gold standard of self-custody, Coldcard devices were long considered virtually unhackable when kept offline.
However, an automated exploit targeting a five-year-old firmware flaw enabled attackers to sweep funds out of cold storage without physical access, without phishing, and without asking users to approve a single malicious transaction. In many instances, Bitcoin that had sat completely untouched in physical vaults for years vanished in mere minutes.
Here is a comprehensive breakdown of how this critical entropy vulnerability occurred, why standard security practices failed, and the emergency protocol you must follow immediately to safeguard your assets.
The initial wave of automated sweeps began on the night of 30th July 2026. Within a tightly coordinated 25-minute window, nearly 600 Bitcoin—worth approximately $38 million—was drained from roughly 500 single-signature Coldcard wallets.
By early August, researchers tracking mempool activity confirmed that the damage had expanded dramatically:
Unlike typical crypto drains where users fall prey to malicious links or sign compromised smart contracts, victims of this attack did everything right according to traditional advice. They bought dedicated hardware, wrote down their recovery seed phrases on paper or steel, and never connected their devices to compromised internet software. The exploit did not break Bitcoin’s cryptographic protocol, nor did it break into the physical hardware; instead, it exploited the software responsible for generating the seed phrases in the first place.
To understand how offline devices were drained remotely, we have to look back to March 2021, when Coldcard manufacturer Coinkite migrated its device firmware to a new cryptography library known as Libangu.
Buried within the codebase was a single logic flaw regarding hardware-based random number generation. In C programming, checking whether a configuration setting exists is entirely different from checking whether that setting is enabled:
Coinkite had explicitly set the hardware random number generator flag (MicroPy_HW_ENABLE_RNG) to 0 because their device architecture utilised its own custom hardware randomness wrapper. However, the newly integrated cryptography library only checked whether the setting existed. Because the flag was present in the code, the system erroneously assumed hardware randomness was already active and bypassed the dedicated hardware random number generator chip altogether.
The Software Fallback Trap
With the dedicated hardware random number generator bypassed during key creation, the device fell back to a software pseudo-random number generator built into MicroPython called Yasmarang.
This software fallback derived its initial seed values using only two predictable variables:
Because these parameters represent a finite, easily guessable range of values, the output was far from truly random. Attackers did not need to physically breach hardware or guess passwords; they simply ran automated scripts that generated every possible seed combination resulting from those predictable starting parameters, checked the corresponding public Bitcoin addresses, and swept any discovered balances.
The core security model of any cryptocurrency recovery phrase rests on entropy—the mathematical measure of randomness used to generate your 12 or 24 words.
A 40-bit search space is trivial for modern computation. A standard home laptop running automated cracking scripts can iterate through one trillion seed possibilities within a matter of hours, deriving addresses and broadcasting sweep transactions seamlessly.
A Wider Blast Radius
This compromised randomness path was not restricted solely to primary 24-word recovery phrases. The broken code path was also referenced when generating:
Despite the broad impact across single-signature setups, three specific categories of users emerged from the incident completely unscathed. Analyzing why these setups survived highlights vital lessons for future self-custody design:
Each surviving setup relied on an added layer of defence introduced explicitly by the user, rather than relying solely on default device parameters.
Following confirmation of the flaw, Coinkite leadership took immediate public accountability. CEO NVK issued an urgent warning advising all users who generated seed phrases on affected devices to migrate their funds immediately. Coinkite subsequently halted hardware shipments, destroyed vulnerable warehouse inventory, and released emergency firmware patches.
However, an important distinction must be understood regarding firmware patches: Updating your device firmware does not fix an already compromised seed phrase.
The new firmware prevents your Coldcard from generating weak keys in the future, but it cannot retroactively fix a recovery phrase created under broken entropy. The vulnerability travels with the recovery phrase itself, meaning importing the same seed into a different brand of hardware wallet leaves you equally exposed.
The Privacy Trade-Off
Coinkite maintains a strict privacy policy that purges customer purchasing data after 120 days to protect user identities in the event of a database breach. While this policy protects customer anonymity, it also created a severe notification barrier: Coinkite had no mechanism to directly email five years of historical buyers to warn them of the critical flaw, relying instead on public announcements and social channels.
This incident is part of a broader, historical pattern where faulty random number generation causes severe self-custody breaches. Because a poorly generated random number looks visually identical to a cryptographically secure one, entropy bugs remain hidden until automated scripts discover them:
If you possess a Coldcard wallet or generated your recovery phrase using one, follow this step-by-step action plan immediately to secure your assets:
While an incident of this magnitude can tempt users to retreat back toward centralised exchanges, doing so exchanges transparent cryptographic risks for opaque counterparty risks.
The primary takeaway from this event is that self-custody is evolving from trusted self-custody to verifiable self-custody. Tools like physical dice rolls, multi-vendor multi-signature architectures, and custom passphrases are no longer optional luxuries for the overly cautious—they are the new baseline standard for securing digital wealth.
Coin Bureau - $100M DRAINED From Crypto's Safest Wallet!
"Massive Bitcoin thefts just hit thousands of hardware wallet users as attackers exploited a five-year-old bug in Coldcard’s firmware. Even wallets kept fully offline weren’t safe—no phishing, no dodgy computers, funds simply disappeared.
We break down how the bug worked, which wallets got drained, why your setup could still be at risk, and exactly what to do before it’s too late. If you keep your crypto in so-called “safe” self-custody, you can’t afford to miss this."
~ TIMESTAMPS ~
0:00 Bitcoin’s “Safest” Wallet Just Got Hacked
2:05 How Offline Wallets Were Drained
4:10 The 5-Year-Old Seed Phrase Bug
6:15 How Attackers Cracked the Wallets
8:20 The 3 Security Steps That Saved Users
10:25 Why a Firmware Update Is NOT Enough
12:30 Other Wallet Bugs You Need to Know
14:35 The Emergency Fix for Coldcard Users
16:00 Is Self-Custody Still Safe?
Source 👉 https://www.youtube.com/watch?v=xSonLY4u0u4
Disclaimer: This article is provided for informational purposes only, mistakes may be made, and it's not offered or intended to be used as legal, tax, investment, financial, or any other advice.
