A silent entropy defect buried in Coldcard Mk3 firmware since March 2021 let an attacker drain $38 million from 500 "cold" wallets in a single automated, 25-minute sweep β proving that "not your keys, not your coins" means nothing if the keys themselves were never random.
594.48 BTC (~$38 million) was swept from roughly 500 single-signature addresses across 1,324 UTXOs in just three consecutive Bitcoin blocks (960188β960191) between 01:31 and 01:56 UTC on July 31, 2026 β a 25-minute operation that cost the attacker only ~0.044 BTC in fees.
Coinkite, maker of the popular Coldcard hardware wallet, confirmed the flaw traces to firmware 4.0.1 through 5.0.3 on the Mk3 model only, where the device may have skipped its hardware random-number generator and derived seeds from non-secret, predictable chip data β a bug alive in production for roughly five years before exploitation.
The consolidation of 562 of the stolen BTC into a single unmoved address, the narrow victim profile (wallets holding 0.15β0.26 BTC, dormant since 2021), and the sub-second-per-wallet drain speed point to a pre-computed, automated key-recovery script rather than opportunistic hacking β reviving hard questions about supply-chain trust in "offline" hardware wallets.
Root cause remains unconfirmed: Coinkite's own advisory stops short of blaming its secure element outright, and CEO NVK's initial public denial (later deleted) shows how quickly incident narratives can shift in the first hours of a live exploit.
Coinkite is urging Mk3 holders to add a BIP-39 passphrase immediately or migrate to fresh seeds on Mk4/Q/Mk5 hardware, which use a dual-secure-element architecture specifically designed to hedge against this exact single-vendor failure mode.
Bitcoin's entire self-custody value proposition rests on one assumption: that a private key generated offline, on a purpose-built device disconnected from the internet, is unforgeable and unguessable by anyone who doesn't physically hold that device. Hardware wallets like Coinkite's Coldcard exist specifically to remove the largest attack surface in crypto β malware-infected general-purpose computers β by generating and storing keys on a dedicated secure element. The Coldcard, built by Canadian firm Coinkite, has been a mainstay of the Bitcoin-maximalist and sovereign-individual community since 2019, prized for its open-source firmware, air-gapped signing via microSD, and support for advanced features like PSBT and multisig.
That trust model is precisely why the July 31, 2026 incident is significant beyond its dollar value. This was not a phishing scam, a supply-chain compromise of a software dependency, or a social-engineering attack against an exchange β it was, per preliminary analysis, a flaw in the fundamental cryptographic randomness that underpins key generation itself. If entropy generation is broken, every downstream security assumption β PINs, air-gapping, passphrases layered later β becomes irrelevant, because the attacker doesn't need to breach the device; they only need to guess or recompute a key space that was never as large as advertised.
The timing compounds the concern. Bitcoin was trading above $64,000 during the Asian trading session when the sweep occurred, and the ~$38 million heist barely registered as a market event β a reminder that individual wallet-security incidents, however severe for victims, rarely move BTC price on their own. But the incident lands amid a year in which institutional Bitcoin exposure has expanded dramatically (Strategy alone booked an $8.2 billion Q2 loss on its BTC treasury position, underscoring how much capital now sits in concentrated on-chain custody arrangements), and in a market where dormant, decade-old UTXOs are increasingly scrutinized by chain-analysis firms as proxies for both lost coins and re-activated risk.
Critically, the flaw's five-year dormancy β introduced in firmware 4.0.0 in March 2021 and only exploited in July 2026 β illustrates a recurring pattern in hardware-wallet security: vulnerabilities in offline, low-telemetry devices can persist far longer than in networked software, because there is no equivalent of a fuzzing bot or intrusion-detection system watching a hardware secure element in the wild. Someone β possibly the attacker themselves, possibly a security researcher whose findings leaked or were independently rediscovered β appears to have identified the weak entropy pattern and built tooling to walk the reduced key space at scale, long after the affected devices had been sold, used, and in many cases forgotten by their owners.
March 2021 β The flaw is introduced. Coldcard Mk3 firmware version 4.0.0 ships an update that, per Coinkite's later advisory, could cause the device to bypass its hardware randomness generator under certain conditions and fall back to software-derived key generation seeded by non-secret chip data (reportedly serial number and clock register values). This firmware branch persists through version 5.0.3, the final supported release for the Mk3 model.
2021β2026 β Affected wallets accumulate and go dormant. Users generate seeds on vulnerable Mk3 firmware and fund the resulting addresses. Many of these wallets β later found to hold between roughly 0.15 and 0.26 BTC each β go untouched for years, a common pattern for long-term "cold storage" holders who deliberately don't move coins.
July 31, 2026, 01:31β01:56 UTC β The sweep executes. Across four consecutive Bitcoin blocks (960188 through 960191), an attacker submits 500 transactions sweeping 1,324 UTXOs from roughly 500 distinct single-signature addresses, totaling 594.48 BTC. The entire operation costs approximately 0.044 BTC in transaction fees β a strong signal of pre-computed private keys and scripted, possibly AI-assisted, transaction construction rather than manual, opportunistic looting.
Shortly after β Consolidation. 562 of the stolen BTC are consolidated into a single address (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r), which as of reporting has not moved the funds further β typical behavior for an attacker waiting out heightened monitoring before laundering through mixers or cross-chain bridges.
Same day β On-chain forensics moves fast. AnchorWatch CEO Rob Hamilton publishes initial UTXO-level analysis on X, identifying the 1,324 swept outputs and stating "at first glance, it appears there was faulty entropy in wallet generation somewhere along the path." Wizardsardine CEO Kevin Loaec independently floats the theory that the affected keyspace reflects "entropy that isn't fully broken, but just too weak," noting the narrow BTC-amount clustering among victims and the age of many UTXOs.
Same day β NVK's retraction. Coinkite founder/CEO Rodolfo Novak ("NVK") initially posts publicly attributing the sweep to individually compromised or leaked seeds, explicitly denying evidence of a device-wide RNG issue β then deletes the post, writing: "I don't want wrong information out now that I have more updates, I don't want people to be at risk. Blog incoming." The reversal, within hours, is itself a data point on how incident communications evolve under real-time on-chain scrutiny.
July 31, 2026 β Formal advisory. Coinkite publishes an official security advisory confirming that seeds generated on Coldcard Mk3 devices running firmware 4.0.1 through 5.0.3 may be at risk, explicitly excluding the Mk4, Q, and Mk5 models. The advisory stops short of confirming a root cause but flags the Mk3's reliance on a single secure element (Microchip's ATECC608A) versus later models' dual-chip design (adding Maxim's DS28C36B) as a documented, deliberate architectural distinction that may explain the model boundary.

At the center of this incident is a question every hardware-wallet vendor must answer convincingly: where does randomness actually come from, and what happens when the "true" source is unavailable? Modern hardware wallets typically combine two entropy sources β a certified secure element's onboard true random number generator (TRNG), often augmented with a software-side pseudorandom generator (PRNG) seeded by additional environmental noise β to produce the 128β256 bits of entropy that becomes a BIP-39 seed phrase. The Coldcard Mk3's design centers on a single Microchip ATECC608A secure element, a certified cryptographic co-processor that, among other things, provides hardware TRNG output and PIN-attempt-limiting.
The theory now under investigation β not yet confirmed by Coinkite β is that under specific conditions introduced in firmware 4.0.0, the device's key-generation routine failed to properly draw entropy from the ATECC608A and instead fell back to a software path seeded by non-secret, device-identifiable data such as chip serial numbers and clock register values. If true, this collapses what should be a 128-bit-plus keyspace (astronomically infeasible to brute-force) down to something bounded by the entropy of those predictable inputs β potentially small enough for an attacker with knowledge of the flaw to precompute candidate private keys for every Coldcard Mk3 device manufactured or firmware-flashed during the vulnerable window, then simply check which candidates correspond to funded addresses on-chain.
That precompute-then-sweep model is consistent with the forensic pattern observed: 500 addresses drained across only three to four blocks, with per-wallet execution fast enough that manual key derivation is implausible. Kevin Loaec's suggestion that the attacker used a script β "written with AI" β that derives only BIP84 (native SegWit) paths to a limited depth is notable: it implies the attacker didn't need to search broadly across derivation paths or address types, because the underlying entropy defect was narrow and well-understood by the time of exploitation. This also explains the observed victim profile β every one of the 1,324 stolen UTXOs came from single-signature, native SegWit addresses; none from Taproot, none from multisig β suggesting either the flaw specifically affected certain derivation/address-type combinations, or the attacker simply hadn't finished walking the full affected set when reporting began and public attention forced a stop.
The Mk4/Q/Mk5 vs. Mk3 boundary is the most technically interesting clue Coinkite has confirmed. Later Coldcard models deliberately added a second secure element from an entirely different vendor (Maxim's DS28C36B) alongside the original Microchip part β Coinkite's own architecture documentation describes this explicitly as a hedge against single-vendor failure, not a retroactive justification invented after this incident. That the exploit maps precisely onto the model generation that lacked this redundancy is strong circumstantial evidence for a defect isolated to the ATECC608A entropy path or its integration in Mk3 firmware, even though Coinkite has not yet published a confirmed root-cause finding. This also echoes 2020, when Ledger's Donjon security lab disclosed a laser fault-injection attack against the older ATECC508A chip used in the original Coldcard Mk2 β a reminder that this specific secure-element lineage has drawn adversarial scrutiny for years.
sequenceDiagram
participant Dev as Coldcard Mk3 (fw 4.0.1β5.0.3)
participant SE as Secure Element (ATECC608A)
participant Seed as Seed Generation Routine
participant User as Wallet Owner
participant Chain as Bitcoin Blockchain
participant Att as Attacker
Dev->>SE: Request hardware entropy (TRNG)
Note over Dev,SE: Suspected fault: TRNG call skipped or fails silently
Dev->>Seed: Fall back to predictable chip data (serial no., clock regs)
Seed->>User: Generate BIP-39 seed / BIP84 keys
User->>Chain: Fund address, hold long-term (2021β2026)
Att->>Att: Reconstruct reduced keyspace from known chip-data patterns
Att->>Chain: Precompute candidate keys, scan for funded addresses
Att->>Chain: Broadcast 500 sweep txs across blocks 960188β960191
Chain-->>Att: 594.48 BTC confirmed (1,324 UTXOs, 25 minutes)
Att->>Chain: Consolidate 562 BTC into single address (dormant since)Metric | Value | Change | Source |
|---|---|---|---|
Total BTC stolen | 594.48 BTC (~$38M) | N/A (single event) | CoinDesk, AnchorWatch analysis |
Addresses drained | ~500 single-sig addresses | N/A | CoinDesk / on-chain forensics |
UTXOs swept | 1,324 | N/A | AnchorWatch (Rob Hamilton) |
Attack window | 25 minutes (blocks 960188β960191) | N/A | CoinDesk |
Attacker fee cost |
| N/A | On-chain / TFTC reporting |
BTC spot price at time of attack | >$64,000 | Muted market impact | CoinDesk |
Consolidated stolen funds | 562 BTC, single address, unmoved | 0% moved since sweep | On-chain (bc1qq85v2c...) |
Flaw dormancy period | ~5 years (March 2021βJuly 2026) | N/A | Coinkite advisory |
The data underscores an attack defined by precision, not brute force. A 25-minute window across four blocks, combined with a fee spend of under $3,000 to extract $38 million, implies near-zero marginal cost per victim wallet once the underlying keyspace was cracked β the hallmark of a scripted, probably pre-tested exploit rather than a live, adaptive attack. The fact that 562 of 594 BTC remain untouched in a single consolidation address, rather than immediately routed through mixers or cross-chain bridges, suggests the attacker is either confident in operational security, waiting for public attention to fade, or facing logistical friction in laundering a sum this size without triggering exchange-side compliance flags.
Bitcoin's price action β holding above $64,000 with negligible visible reaction β confirms that isolated wallet-security incidents, even eight-figure ones, do not move a multi-trillion-dollar asset's price on their own. This is a meaningfully different risk category from a protocol-level or exchange-level failure (e.g., a stablecoin depeg or a major CEX insolvency): the damage here is fully contained to a specific hardware cohort and does not touch Bitcoin's base-layer security, consensus, or liquidity. That containment is precisely why forensic and vendor response β not price β is the correct lens for evaluating the incident's severity.

Coldcard competes in the Bitcoin-only and multi-asset hardware wallet market against Ledger, Trezor, and a smaller field of niche/open-source devices (BitBox, Foundation Passport, Blockstream Jade). Each has a materially different security and trust model, and this incident sharpens the contrast:
Ledger uses proprietary secure elements (CC EAL5+/EAL6+ certified) but keeps firmware and chip design closed-source, trading auditability for a stronger anti-tamper and anti-extraction track record β no confirmed real-world private-key extraction has ever been reported against Ledger devices, though the company has suffered repeated customer-data breaches (2020 database leak, 2023 Shopify insider breach, 2025 Global-e payment-processor breach, and the widely criticized 2023 "Ledger Recover" cloud-backup feature that alarmed the community over key-custody implications).
Trezor is the closest philosophical peer to Coldcard: fully open-source firmware and hardware design, prioritizing auditability over Ledger's closed-source, certified-chip approach. Its security incidents have similarly clustered around phishing and data breaches (2022 MailChimp-enabled phishing, 2024 breach exposing ~66,000 users' contact info, 2025 contact-form abuse) rather than confirmed key-generation flaws β though Ledger's own Donjon researchers demonstrated a lab-conditions voltage-glitching attack against the Trezor Safe 3 in November 2024, requiring physical device access.
Coldcard's differentiator has always been Bitcoin-only focus, air-gapped microSD signing, advanced multisig/PSBT support, and open-source firmware aimed at a more technically sophisticated, sovereignty-focused user base. That focus is precisely what makes this incident so damaging to its brand: Coldcard's marketing and community reputation are built on rigorous, auditable security for exactly the kind of long-term, large-balance holder who was victimized here. A closed-source competitor suffering the same flaw might absorb less reputational damage, since users of closed systems already accept some trust-without-verification; Coldcard's user base explicitly chose the device because it promised the opposite.
Industry-wide, 2025β2026 has seen EAL6+ secure elements become table stakes, with differentiation shifting toward air-gap architecture, transaction "clear signing" (to defeat blind-signing exploits), and early post-quantum cryptography support (Trezor's Safe 7). Coinkite's dual-secure-element design in the Mk4/Q/Mk5 β explicitly built to hedge against exactly this kind of single-vendor entropy failure β now reads as prescient, but the fact that a five-year-old, single-vendor-era model remained in the field, unpatched at the entropy level (a firmware update cannot retroactively fix already-generated weak keys), highlights a structural risk common to all hardware wallets: legacy devices don't get architectural upgrades, only advisories telling users to migrate.
Affected Mk3 users face the most acute risk: any funds still held on a seed generated under firmware 4.0.1β5.0.3 without a BIP-39 passphrase should be treated as potentially compromised and moved immediately to a freshly generated seed on unaffected hardware. Users who already layered a passphrase are, per Coinkite's own advisory, at "minimal risk," since the passphrase adds attacker-unknown entropy that the flawed base-seed generation cannot compensate for.
Coinkite/Coldcard faces a reputational crisis compounded by its own CEO's initial (later retracted) denial. The company's response β publishing a formal advisory, clearly scoping affected firmware/models, and offering concrete remediation steps β is a reasonably strong crisis-management playbook, but the unresolved root cause leaves the door open for further bad news if additional models or firmware ranges are later implicated. Trust rebuilding will likely require an independent third-party audit of the ATECC608A integration and possibly a bug bounty payout to whoever can reproduce the flaw.
On-chain forensics firms (AnchorWatch, and implicitly Chainalysis/Elliptic-class players who will likely follow up) benefit from a high-visibility case that showcases rapid UTXO-level analysis capability β Rob Hamilton's near-real-time breakdown of the 1,324 swept outputs was central to establishing the technical narrative within hours of the sweep, ahead of any vendor statement.
Bitcoin developers and BIP-standards bodies are not directly implicated (this is a vendor-specific hardware/firmware flaw, not a Bitcoin protocol or BIP defect), but the incident will likely reinforce ongoing community pushes for standardized entropy-testing and open, auditable RNG implementations across hardware wallet vendors, and may accelerate adoption guidance around mandatory passphrase use for long-term cold storage.
Regulators and institutional custodians will note that this is a textbook example of concentrated custody risk materializing outside exchange infrastructure β a reminder, especially for funds and treasuries holding Bitcoin via hardware-wallet-based self-custody or multisig-with-hardware-signers setups, that vendor-level firmware supply chain risk is a first-class threat category deserving the same diligence typically reserved for custodian counterparty risk.
Unconfirmed root cause leaves scope uncertain β Coinkite has not definitively proven the ATECC608A/entropy-fallback theory; if the actual defect is broader (e.g., also affecting Mk2 or specific Mk4 batches) or narrower (a specific manufacturing lot rather than all Mk3 firmware 4.0.1+), current remediation guidance could be both under- and over-inclusive. Severity: High. Probability of scope revision: Moderate-to-high given the investigation is explicitly ongoing.
Passphrase-less legacy holders remain exposed until they act β Because the flaw is in key generation itself, no firmware patch can retroactively secure already-generated, already-funded seeds; only user action (adding a passphrase or migrating) closes the exposure. Given how many affected wallets were dormant for years, a meaningful population of still-vulnerable holders likely remains unaware of the advisory. Severity: Critical for affected individuals. Probability of further losses: High without aggressive user notification.
Reputational contagion to the broader hardware-wallet category β Retail and institutional users conflate vendor-specific flaws with category-wide risk; a high-profile, easily-summarized headline ("bitcoin wallet flaw drains $38M") can suppress hardware-wallet adoption broadly, even though Ledger and Trezor are architecturally unrelated. Severity: Moderate. Probability: Moderate, historically self-correcting within weeks to months as forensic clarity emerges.
Laundering of the consolidated 562 BTC β the unmoved consolidation address is a monitorable asset today, but once the attacker begins moving funds (via mixers, cross-chain bridges, or OTC desks with weak KYC), recovery odds drop sharply and the case becomes a long-tail forensic pursuit rather than an active interdiction opportunity. Severity: High for recovery prospects. Probability of eventual movement: Very high β attackers holding stolen BTC this size rarely leave it permanently dormant.

For funds and institutions holding Bitcoin via hardware-wallet-secured self-custody or multisig arrangements, this incident is an immediate operational-risk trigger, not a market-moving event. Any treasury or fund using Coldcard Mk3 devices β even as one leg of a multisig quorum β should treat firmware-level entropy audits as a mandatory diligence item going forward, on par with smart-contract audits for DeFi exposure. The broader lesson for institutional custody design is that single-vendor, single-secure-element architectures represent a correlated failure risk that diversified multisig setups (mixing hardware vendors across signing keys) are specifically designed to mitigate β and this incident is the clearest real-world justification yet for that added complexity and cost.
For builders and hardware-wallet vendors, the strategic signal is that entropy generation deserves the same open, continuously-audited scrutiny as smart contract code, not a "trust the secure element" assumption baked in at launch and left unrevisited for years. Expect increased demand for third-party, reproducible RNG testing tools, and possibly renewed momentum behind open, verifiable entropy standards (some Bitcoin developers have long advocated for user-supplied dice-roll entropy specifically to avoid single points of hardware trust β Coinkite itself recommends this as an interim workaround). Vendors that can credibly demonstrate dual-source, cross-vendor entropy architectures β as Coinkite's own Mk4/Q/Mk5 already do β stand to gain competitively from a market newly attentive to this failure mode.
For traders and market observers, the muted price reaction confirms this is a custody-layer event, not a Bitcoin-network event, and should not be read as a signal about BTC's fundamental security. It should, however, factor into any due-diligence framework for evaluating counterparties, funds, or custodians whose disclosed security practices lean heavily on a single hardware vendor's attestations rather than independently verifiable, auditable processes.
30 days: Expect Coinkite to publish a definitive technical post-mortem confirming or ruling out the ATECC608A entropy-fallback theory, likely accompanied by an independent third-party security audit announcement and/or a bug-bounty escalation. Watch for whether the consolidated 562 BTC begins moving β the first sign of active laundering β which would trigger renewed forensic-firm coverage (Chainalysis/Elliptic likely to publish their own analyses within this window).
180 days: Expect a measurable, if modest, market-share shift toward hardware wallets with publicly documented dual-secure-element or multi-vendor entropy architectures, alongside increased default adoption of BIP-39 passphrases as a "best practice" recommendation across the self-custody education ecosystem. A class-action or formal legal claim against Coinkite by affected Mk3 holders is plausible if the confirmed root cause implicates a known, preventable engineering oversight.
365 days: This incident likely becomes a canonical case study cited in Bitcoin self-custody security literature and audit frameworks β comparable to the 2020 Ledger Donjon laser fault-injection disclosure β driving industry-wide standardization around reproducible, auditable RNG testing for hardware wallets. Institutional custody frameworks and multisig-policy templates will more explicitly mandate cross-vendor hardware diversification as a baseline control, rather than a niche recommendation for the most risk-averse holders.
Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep β CoinDesk
Coinkite Issues Mk3 Security Warning After 594 BTC Swept in Minutes β TFTC
Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3 β BitRss
594 bitcoin drained in fifteen minutes: what we know so far β Atlas21
Coldcard Wallet Flaw Leads to 594 BTC Theft Worth $38M β KuCoin
Coldcard Mk3 warning follows $38M Bitcoin drain β crypto.news
Coinkite Warns Coldcard Mk3 Owners After Reports of $38M Bitcoin Loss β Bitcoin.com News
Hardware Wallet Comparison 2026: Ledger vs. Trezor β New Models, New Risks β KuCoin
Strategy (MSTR) books $8.2 billion Q2 loss on bitcoin price decline β CoinDesk