crypto news

The Coldcard Entropy Collapse Is a $116M Reminder: Trust Is Priced In

A Lightning node exploit and a Coldcard entropy regression drained over $120M, even as institutions quietly built on Ethereum.

In the year of our algorithm 2025, the Bitcoin network’s security architecture didn’t fork at the consensus layer—it quietly hemorrhaged at the endpoints, the digital equivalent of a 19th-century bank vault that forgot to reinforce the teller windows. BTCPay Server, the Lightning payment router that processes transactions like a steampunk switchboard operator, was forced to emergency-patch to version 2.4.2 after attackers siphoned macaroon credentials—those authentication tokens that grant bearer access to Lightning Network nodes—effectively turning them into bearer bonds for digital loot[^claim_628]. The update slammed shut public remote connections to LND nodes and auto-regenerated credentials on standard installs, while its release notes pleaded with operators to audit their channels for unauthorized payments[^claim_629]. But by then, the damage was already wired into the same silent ledger that had been leaking from Coldcard hardware wallets for months. A 2021 firmware update had taken a cryptographic shortcut worthy of a bad spy novel: it shaved seed entropy from 128 bits down to a laughable 40, turning what should have been a brute-force fortress into a combination lock with only a few million combinations. Remote attackers simply iterated through the possibilities, and approximately 1,816 BTC—around $116 million—evaporated from over 5,200 addresses, a cold, hard lesson in supply-chain trust[^claim_630]. These are not glitches but systemic fractures. Bitcoin’s foundational assumption—that the private key remains secret—can be nullified by a single committer’s sloppiness in a third-party library, a single oversight in a firmware diff. And the network’s immune response is prehistoric: when a contentious fork (BIP-110) tried to enforce alternate rules, miners simply stopped building on it after two blocks, leaving the main chain as immaculate as ever, while the edge continued to bleed[^claim_632]. Yet, in the grand casino of crypto finance, the bets only get larger. MARA, the mining behemoth, pledged 18,750 BTC (~$1.2 billion) as collateral for a $600 million loan to fund AI infrastructure, opting not to sell a single satoshi, a maneuver that treats bitcoin as a pristine reserve asset even as its custody pipes leak[^claim_637]. Meanwhile, J.P. Morgan tokenized $900 million in assets on Ethereum, joining the real-world-asset DeFi craze that’s now a $27 billion market, half of it on Ethereum—a network that, on the same day, watched the Coinsbuy platform hemorrhage over $7.9 million to an exploit across Ethereum and TRON[^claim_633][^claim_634]. And in a roadmap update that landed like a silent alarm, Vitalik Buterin placed privacy and quantum resistance at the center of Ethereum’s survival plan, a tacit admission that the very cryptographic foundations may be rusting out[^claim_636]. The takeaway is as cold as a margin call: the crypto industry is scaling its financial ambitions like a leveraged buyout, while its software supply chain remains held together with hope and merge requests. Self-custody, that sacred cow, now burdens users with auditing not just wallet source code but firmware history and node remote-access policies, a due-diligence nightmare. Lightning, in particular, opens attack surfaces that demand the constant paranoia of a Cold War spy—and expect a wave of wallet firmware audits and remote-connection lockdowns across Bitcoin’s service stack, even as the institutions keep tokenizing reality on the other chain.

Provenance ledger

7 span-verified · 3 web-cited

7 claims below are locked to a verbatim span re-verified against the source. The remaining 3 are web citations: the URL was checked, but the excerpt is the researcher's summary and was not re-derived from the page. Citation markers in the text jump here.

[1] BTCPay Server 2.4.2 temporarily disables public remote connections to LND Lightning nodes (e.g., Zeus via BTCPay domain or Tor onion) on Docker deployments after a critical exploit that let attackers obtain macaroon credentials and move funds. span-verified
Verbatim source span
“BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software after attackers exploited a critical vulnerability to obtain credentials and move funds… The restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments.”
SHA-256 of span
e1cbb0ebf3c0dea86d53e246699d2b0a059619c75065b1dd3c0e75e26f85e4a8
↩ back to text
[2] BTCPay Server version 2.4.2 ships LND 0.21.1 and auto‑regenerates macaroon credentials on standard installations, while advising operators to check for unauthorized Lightning payments, unexpected channel closures, unfamiliar peers, and balance discrepancies. span-verified
Verbatim source span
“Version 2.4.2 installs LND version 0.21.1 and automatically regenerates the macaroon credentials on standard BTCPay installations. The project advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies in their onchain or Lightning balances.”
SHA-256 of span
d8a003e7053b9842a59bee076026b13ff768127c603166d0b20468d9937882c7
↩ back to text
[3] A Coldcard hardware‑wallet firmware flaw that reduced seed entropy from 128 bits to 40 bits in a 2021 update enabled remote regeneration of private keys and has been linked to the theft of approximately 1,816 BTC (~$116M) from more than 5,200 addresses, with total reported losses in the broader incident around $114–120 million. web-cited
Excerpt reported by researcher (not re-verified)
“A Coldcard firmware flaw let attackers regenerate private keys remotely, draining ~1,816 BTC (~$116M) from 5,200+ addresses. A 2021 update had collapsed seed entropy from 128 bits to 40.” and OriginBrief: “The Coldcard hardware wallet exploit escalated to approximately $114–120 million in losses, with the flaw remaining live; Coldcard urged users to move bitcoin…”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[4] Brazil’s Central Bank will require local VASPs to place precautionary holds of up to 24 hours on crypto transfers above US$10,000 (or when a customer’s total daily transfers exceed US$10,000) to self‑custody wallets or overseas platforms, effective January 1, 2027. span-verified
Verbatim source span
“The Central Bank of Brazil has announced stricter anti-fraud rules for virtual asset transactions. Under the new framework, local Virtual Asset Service Providers will be required to place precautionary holds of up to 24 hours on certain transfers to overseas platforms or self-custody wallets. The requirement applies to individual transactions above $10,000 and to cases where a customer’s total transactions exceed the same threshold within a single day… The new rules will take effect on January
SHA-256 of span
348cfa9216f634bf60b4ff54ebfac0f28eb155a1dd2e8968eea508821a603087
↩ back to text
[5] Bitcoin’s contested BIP‑110 enforcing branch could only produce two blocks after mandatory signaling began, and miners have effectively stalled the fork, leaving mainline consensus rules unchanged. span-verified
Verbatim source span
“Australia halts Cryptolink ATMs as BIP-110 stalls and Brazil tightens crypto transfer checks… Bitcoin’s BIP-110 enforcing branch has struggled to maintain block production since mandatory signaling began.” and Blockpulse recap: “Bitcoin miners overwhelmingly rejected the BIP-110 fork, keeping the network’s consensus intact.”
SHA-256 of span
c3e46ffc82d1ae668b6c8e3d39edbb26d3f88313eafa5f5c7ea0a3f89949e9e4
↩ back to text
[6] J.P. Morgan has tokenized US$900 million in assets on Ethereum, contributing to real‑world‑asset DeFi total value locked of US$27 billion, with roughly half of that TVL residing on Ethereum via major tokenization issuers. span-verified
Verbatim source span
“J.P. Morgan tokenizes $900M on Ethereum and Wellington launches mWIN credit strategy on Morpho… Real-world-asset TVL reaches $27B, with Ethereum holding about half via major tokenization issuers.”
SHA-256 of span
7a586f234a9dec7f1746233fddcf3247d2cad4773e52e2ce28476b5fe094b8c3
↩ back to text
[7] The Coinsbuy platform suffered a hack in which over US$7.9 million in assets on Ethereum and TRON were stolen via an exploit, characterized as an Ethereum and TRON exploit by incident reporters. web-cited
Excerpt reported by researcher (not re-verified)
“Coinsbuy Hack News: Over $7.9M Stolen in Ethereum and TRON Exploit”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[8] Russia has imposed a ban on bitcoin mining across Moscow and surrounding regions from August 15, 2026, through 2032, citing power‑grid strain as the rationale. span-verified
Verbatim source span
“Russia banned bitcoin mining across Moscow and surrounding regions from August 15 through 2032, citing power grid strain.”
SHA-256 of span
81bfea08060d2fd1df8f924a1a08a9064dbeb717a0b1083f06c9164416f50d90
↩ back to text
[9] Vitalik Buterin’s latest Ethereum roadmap update explicitly elevates privacy and quantum resistance as front‑and‑center priorities, indicating future protocol workstreams on post‑quantum cryptography and improved privacy tooling at the base and rollup layers. web-cited
Excerpt reported by researcher (not re-verified)
The Block front page headline: “Vitalik Buterin puts privacy and quantum resistance front and center in Ethereum’s latest roadmap”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[10] MARA pledged 18,750 BTC (approximately US$1.2 billion) as collateral for a US$600 million loan targeted at financing AI infrastructure build‑out, without selling any of the bitcoin. span-verified
Verbatim source span
“MARA pledged 18,750 BTC (~$1.2B) as collateral for a $600M loan.”
SHA-256 of span
3d075f34511ccad23bbded19fba6c0384cffa0ca624f9c7a204166877aa94e30
↩ back to text

Sources

  1. https://cointelegraph.com/news/what-happened-in-crypto-today
  2. https://x.com/BlockchainFF/status/2086855178184249380
  3. https://www.fameex.com/en-US/news/crypto-news-recap-20260810
  4. https://coinjuice.com/research-hub/what-happened-in-crypto-today-august-10-2026
  5. https://www.coingabbar.com/en/blockchain/crypto-news
  6. https://www.theblock.co/
  7. https://x.com/interlinklabsvn/status/2086724857363120463/photo/1
bitcoinlightning-networkcoldcardhardware-walletsentropyethereumtokenizationinstitutional-adoptionexploitinfrastructure
AUTOMATED

Get the synthesis

AI×crypto research, repackaged with every claim hash-locked to its source. New arXiv → analysis in ~3 hours.