crypto news

Coldcard's 5-Year Entropy Bug Sweeps $89M from 4,585 Wallets

A 2021 firmware flaw that replaced true randomness with predictable device data enabled a multi-wave exploit, exposing the fatal weakness in trusting consumer hardware wallet entropy.

The July 30, 2026 Coldcard exploit didn’t breach blockchain security. It shattered hardware entropy. A 2021 firmware bug that used predictable device data instead of true randomness for seed generation[^claim_1] allowed an attacker to drain 1,196 wallets in a 41-minute sweep, netting roughly $70 million[^claim_1]. Within days, the damage widened: by August 2, 4,585 addresses had been compromised, with combined losses reaching nearly $89 million—1,367 BTC in total[^claim_2]. The attack unfolded in three waves[^claim_2], each a grim recursion as the exploiter methodically emptied every wallet whose seed was deterministically derived from device-specific, non-random inputs.

Initial estimates pegged the loss at $38 million[^claim_3], but the figure more than doubled as investigators traced the 5-year-old flaw[^claim_3] through the entire population of vulnerable devices. The bug made Coldcard seeds as predictable as the hardware’s own firmware fingerprint—a fatal design error that sat dormant while users accumulated funds, confident in air-gapped security. In practice, the isolation meant no network-level alarms could fire; the attacker simply needed the seed derivation logic and a list of affected addresses to orchestrate a slow-motion bank run.

The lesson is unambiguous: local entropy generation without verifiable randomness is a single point of failure. Coldcard’s deterministic seeds prove that any consumer hardware wallet can harbor a catastrophic flaw for years, invisible to users and auditors alike. The only durable defense is to eliminate the assumption that a single device can be trusted to generate true randomness. Multi-signature quorums, MPC-based signing, or audited hardware security modules (HSMs) where entropy is externally verifiable become architectural necessities, not luxuries.

Bitcoin was trading around $63,500[^claim_9] as the exploit unfolded; the protocol remains unshaken. But for the 4,585 wallets that became deterministic vaults, the damage is absolute

Provenance ledger

7 span-verified · 3 web-cited

7 claims below are locked to a verbatim span re-verified against the source. The remaining 3 are web citations: the URL was checked, but the excerpt is the researcher's summary and was not re-derived from the page. Citation markers in the text jump here.

[1] Coldcard hardware wallets suffered a firmware vulnerability that drained approximately $70 million from 1,196 Bitcoin wallets in a 41‑minute sweep on July 30, due to a 2021 firmware bug that used predictable device data instead of true randomness for seed generation. span-verified
Verbatim source span
“a firmware vulnerability discovered on July 30 drained approximately $70 million from 1,196 Coldcard hardware wallets in a 41-minute sweep… Root cause: a 2021 firmware bug that used predictable device data instead of true randomness for seed generation.”[3]
SHA-256 of span
40a625b7e137589766cc40cdeffbee86f1203d55e31e0569dcc3b7b2d31d188e
↩ back to text
[2] Follow‑up analysis reports that the Coldcard vulnerability expanded to 4,585 addresses with combined losses reaching approximately 1,367 BTC, or nearly $89 million, across three attack waves. span-verified
Verbatim source span
“The Coldcard vulnerability expanded to 4,585 addresses with combined losses reaching approximately 1,367 BTC, or nearly $89 million, across three attack waves.”[5]
SHA-256 of span
3890da98694df3768b266e52940ad3b1c64106b916086b9eeb6aa03333ef8980
↩ back to text
[3] The Coldcard exploit is attributed to a 5‑year‑old firmware flaw that made wallet seeds predictable, enabling an attacker to sweep funds from more than 500 wallets, with total losses climbing from $38 million to ~$70 million as of August 2. web-cited
Excerpt reported by researcher (not re-verified)
“Coldcard Hack Balloons to $70M. A 5-year-old firmware flaw made Coldcard wallet seeds predictable. Losses have climbed from $38M to ~$70M across 500+ wallets since the July 31 exploit.”[2]

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[4] KelpDAO’s liquid restaking token rsETH suffered an approximately $290 million exploit after an attacker abused the single‑verifier configuration of its LayerZero omnichain fungible token bridge to unlock 116,500 rsETH from an Ethereum mainnet escrow. span-verified
Verbatim source span
“KelpDAO's liquid restaking token, rsETH, suffered a ~$290 million hack, the largest DeFi exploit of 2026. An attacker… exploited the single-verifier configuration that KelpDAO chose for its LayerZero omnichain fungible token (OFT) bridge to unlock 116,500 rsETH from the Ethereum mainnet escrow.”[11]
SHA-256 of span
dcaffb4132490d843c5b7cff88a0b305c86b7daf6eb0beca3043bbf613e9c7a7
↩ back to text
[5] Uniswap launched a self‑custodial lending product called Earn that deposits USDC, USDT, and ETH into Morpho vaults directly within the Uniswap app, charging no additional fee beyond gas. web-cited
Excerpt reported by researcher (not re-verified)
“Uniswap Adds Lending With Earn. Uniswap launched a self-custodial lending product depositing USDC/USDT/ETH into Morpho vaults, right inside the Uniswap app, with no extra fee beyond gas.”[2]

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[6] SushiSwap deployed functionality on Robinhood Chain that allows users to create tokens paired against tokenized real‑world assets, with instant liquidity via automatically created Sushi V3 pools. web-cited
Excerpt reported by researcher (not re-verified)
“Sushi Launches RWA Tokens on Robinhood Chain. SushiSwap now lets anyone create tokens paired against tokenized real-world assets on Robinhood Chain, with instant liquidity via auto-created Sushi V3 pools.”[2]

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[7] Bitcoin spot ETFs recorded $61.53 million in net outflows for the week, while Ethereum ETFs posted net inflows of $27.42 million, marking 4 consecutive positive weeks for ETH ETF flows. span-verified
Verbatim source span
“Bitcoin ETFs recorded $61.53M in net outflows for the week; Ethereum ETFs extended their positive streak to 4 consecutive weeks with $27.42M in net inflows.”[3]
SHA-256 of span
bbc440a1e9aac377f084c06ff86a41543854dfb09de360eef6f2a91877d23e16
↩ back to text
[8] A newly launched ASTEROID token on BNB Chain rose 1,557.69% in 24 hours, allegedly linked to a former BNB Chain employee’s unauthorized wallet deployment and subsequent insider sale. span-verified
Verbatim source span
“a newly launched ASTEROID token on BNB Chain exploded 1,557.69% in 24 hours, allegedly tied to a former BNB Chain employee's unauthorized wallet deployment and subsequent insider sale.”[5]
SHA-256 of span
d6835e001fe1f932330f097e0c1842dabfe3928bad8c1369c4c6e3ae71ea42a1
↩ back to text
[9] As of around August 2, 2026, Bitcoin is trading in the $62,900–$63,500 range with 24‑hour moves of roughly +0.66–0.67%, and total crypto market cap is about $2.15–$2.16 trillion with a 24‑hour decrease of −0.34%. span-verified
Verbatim source span
“Bitcoin ranked first at $63,484.94, up 0.66% in 24 hours, with $12.17B in volume.”[5]
SHA-256 of span
aa8a148d16a534cfaece5b681c7094dc17080c2ba62ba4c2cd4875ec8fd68528
↩ back to text
[10] A Minnesota state law banning cryptocurrency kiosks took effect on August 1, 2026, removing on‑ramp infrastructure for physical crypto ATM terminals within that jurisdiction. span-verified
Verbatim source span
“A Minnesota law banning cryptocurrency kiosks took effect on August 1, 2026.”[13]
SHA-256 of span
d839f660a274cdf44dc6d92e213cfd4492ecc1f7b58f685cb67196a34ae7435a
↩ back to text

Sources

  1. https://plainlycrypto.com/weekly-crypto-brief-2026-08-02/
  2. https://coinstats.app/ai/a/crypto-news-update-02-August-2026
  3. https://www.instagram.com/p/DbhWMhOGr7j/
  4. https://www.galaxy.com/insights/research/kelpdao-layerzero-exploit-defi
  5. https://www.livevolatile.com/blog/2026-08-02-crypto-catalyst-watch-listings-upgrades-rules
hardware-walletscoldcardentropydeterministic-seedsbitcoin-securitymultisigmpc
AUTOMATED

Get the synthesis

AI×crypto research, repackaged with every claim hash-locked to its source. New arXiv → analysis in ~3 hours.