Coldcard's 5-Year Entropy Bug Sweeps $89M from 4,585 Wallets
A 2021 firmware flaw that replaced true randomness with predictable device data enabled a multi-wave exploit, exposing the fatal weakness in trusting consumer hardware wallet entropy.
The July 30, 2026 Coldcard exploit didn’t breach blockchain security. It shattered hardware entropy. A 2021 firmware bug that used predictable device data instead of true randomness for seed generation[^claim_1] allowed an attacker to drain 1,196 wallets in a 41-minute sweep, netting roughly $70 million[^claim_1]. Within days, the damage widened: by August 2, 4,585 addresses had been compromised, with combined losses reaching nearly $89 million—1,367 BTC in total[^claim_2]. The attack unfolded in three waves[^claim_2], each a grim recursion as the exploiter methodically emptied every wallet whose seed was deterministically derived from device-specific, non-random inputs.
Initial estimates pegged the loss at $38 million[^claim_3], but the figure more than doubled as investigators traced the 5-year-old flaw[^claim_3] through the entire population of vulnerable devices. The bug made Coldcard seeds as predictable as the hardware’s own firmware fingerprint—a fatal design error that sat dormant while users accumulated funds, confident in air-gapped security. In practice, the isolation meant no network-level alarms could fire; the attacker simply needed the seed derivation logic and a list of affected addresses to orchestrate a slow-motion bank run.
The lesson is unambiguous: local entropy generation without verifiable randomness is a single point of failure. Coldcard’s deterministic seeds prove that any consumer hardware wallet can harbor a catastrophic flaw for years, invisible to users and auditors alike. The only durable defense is to eliminate the assumption that a single device can be trusted to generate true randomness. Multi-signature quorums, MPC-based signing, or audited hardware security modules (HSMs) where entropy is externally verifiable become architectural necessities, not luxuries.
Bitcoin was trading around $63,500[^claim_9] as the exploit unfolded; the protocol remains unshaken. But for the 4,585 wallets that became deterministic vaults, the damage is absolute
Provenance ledger
7 span-verified · 3 web-cited7 claims below are locked to a verbatim span re-verified against the source. The remaining 3 are web citations: the URL was checked, but the excerpt is the researcher's summary and was not re-derived from the page. Citation markers in the text jump here.
[1] Coldcard hardware wallets suffered a firmware vulnerability that drained approximately $70 million from 1,196 Bitcoin wallets in a 41‑minute sweep on July 30, due to a 2021 firmware bug that used predictable device data instead of true randomness for seed generation. span-verified
“a firmware vulnerability discovered on July 30 drained approximately $70 million from 1,196 Coldcard hardware wallets in a 41-minute sweep… Root cause: a 2021 firmware bug that used predictable device data instead of true randomness for seed generation.”[3]
40a625b7e137589766cc40cdeffbee86f1203d55e31e0569dcc3b7b2d31d188e [2] Follow‑up analysis reports that the Coldcard vulnerability expanded to 4,585 addresses with combined losses reaching approximately 1,367 BTC, or nearly $89 million, across three attack waves. span-verified
“The Coldcard vulnerability expanded to 4,585 addresses with combined losses reaching approximately 1,367 BTC, or nearly $89 million, across three attack waves.”[5]
3890da98694df3768b266e52940ad3b1c64106b916086b9eeb6aa03333ef8980 [3] The Coldcard exploit is attributed to a 5‑year‑old firmware flaw that made wallet seeds predictable, enabling an attacker to sweep funds from more than 500 wallets, with total losses climbing from $38 million to ~$70 million as of August 2. web-cited
“Coldcard Hack Balloons to $70M. A 5-year-old firmware flaw made Coldcard wallet seeds predictable. Losses have climbed from $38M to ~$70M across 500+ wallets since the July 31 exploit.”[2]
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[4] KelpDAO’s liquid restaking token rsETH suffered an approximately $290 million exploit after an attacker abused the single‑verifier configuration of its LayerZero omnichain fungible token bridge to unlock 116,500 rsETH from an Ethereum mainnet escrow. span-verified
“KelpDAO's liquid restaking token, rsETH, suffered a ~$290 million hack, the largest DeFi exploit of 2026. An attacker… exploited the single-verifier configuration that KelpDAO chose for its LayerZero omnichain fungible token (OFT) bridge to unlock 116,500 rsETH from the Ethereum mainnet escrow.”[11]
dcaffb4132490d843c5b7cff88a0b305c86b7daf6eb0beca3043bbf613e9c7a7 [5] Uniswap launched a self‑custodial lending product called Earn that deposits USDC, USDT, and ETH into Morpho vaults directly within the Uniswap app, charging no additional fee beyond gas. web-cited
“Uniswap Adds Lending With Earn. Uniswap launched a self-custodial lending product depositing USDC/USDT/ETH into Morpho vaults, right inside the Uniswap app, with no extra fee beyond gas.”[2]
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[6] SushiSwap deployed functionality on Robinhood Chain that allows users to create tokens paired against tokenized real‑world assets, with instant liquidity via automatically created Sushi V3 pools. web-cited
“Sushi Launches RWA Tokens on Robinhood Chain. SushiSwap now lets anyone create tokens paired against tokenized real-world assets on Robinhood Chain, with instant liquidity via auto-created Sushi V3 pools.”[2]
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[7] Bitcoin spot ETFs recorded $61.53 million in net outflows for the week, while Ethereum ETFs posted net inflows of $27.42 million, marking 4 consecutive positive weeks for ETH ETF flows. span-verified
“Bitcoin ETFs recorded $61.53M in net outflows for the week; Ethereum ETFs extended their positive streak to 4 consecutive weeks with $27.42M in net inflows.”[3]
bbc440a1e9aac377f084c06ff86a41543854dfb09de360eef6f2a91877d23e16 [8] A newly launched ASTEROID token on BNB Chain rose 1,557.69% in 24 hours, allegedly linked to a former BNB Chain employee’s unauthorized wallet deployment and subsequent insider sale. span-verified
“a newly launched ASTEROID token on BNB Chain exploded 1,557.69% in 24 hours, allegedly tied to a former BNB Chain employee's unauthorized wallet deployment and subsequent insider sale.”[5]
d6835e001fe1f932330f097e0c1842dabfe3928bad8c1369c4c6e3ae71ea42a1 [9] As of around August 2, 2026, Bitcoin is trading in the $62,900–$63,500 range with 24‑hour moves of roughly +0.66–0.67%, and total crypto market cap is about $2.15–$2.16 trillion with a 24‑hour decrease of −0.34%. span-verified
“Bitcoin ranked first at $63,484.94, up 0.66% in 24 hours, with $12.17B in volume.”[5]
aa8a148d16a534cfaece5b681c7094dc17080c2ba62ba4c2cd4875ec8fd68528 [10] A Minnesota state law banning cryptocurrency kiosks took effect on August 1, 2026, removing on‑ramp infrastructure for physical crypto ATM terminals within that jurisdiction. span-verified
“A Minnesota law banning cryptocurrency kiosks took effect on August 1, 2026.”[13]
d839f660a274cdf44dc6d92e213cfd4492ecc1f7b58f685cb67196a34ae7435a Sources
- https://plainlycrypto.com/weekly-crypto-brief-2026-08-02/
- https://coinstats.app/ai/a/crypto-news-update-02-August-2026
- https://www.instagram.com/p/DbhWMhOGr7j/
- https://www.galaxy.com/insights/research/kelpdao-layerzero-exploit-defi
- https://www.livevolatile.com/blog/2026-08-02-crypto-catalyst-watch-listings-upgrades-rules