500 WALLETS DRAINED IN FOUR BLOCKS — COLDCARD SEEDS WERE ARITHMETIC. NOT YOUR ENTROPY, NOT YOUR KEYS.
The facts: 594 BTC — roughly $38 million — left 500 single-sig wallets in four blocks on Thursday, a 25-minute sweep. No wallet was broken into. No air gap was crossed. Block’s Bitcoin engineering team root-caused the flaw and CoinDesk led the outside reporting. The attacker didn’t steal 500 keys. He recalculated them.
The cause was a check that asked the wrong question. Coldcard’s firmware ran
#ifndef MICROPY_HW_ENABLE_RNG to test whether the hardware-randomness macro was defined, not whether it was switched on. Coinkite had deliberately defined that macro as zero — because the device was supposed to use its own separate generator — but zero still counts as defined. The safety check passed. The build shipped. Seed creation quietly bound to MicroPython’s software fallback, which drew entropy from the chip’s serial number and its timer registers. Neither is secret. A 12-word seed is meant to carry 128 bits of entropy. Coinkite’s preliminary estimate for affected Mk3 seeds is around 40. Not weak — guessable. The words still looked perfectly random on the device screen; a predictable stream run through a hash comes out statistically uniform and fully reproducible at the same time. No owner on earth could have caught this by reading their seed phrase.1,324 outputs moved across 500 transactions in four blocks. Nobody derives 500 keys in that window. The search ran earlier and offline, against the public ledger. The sweep was only the withdrawal. Coinkite volunteered something even harder: weeks earlier the firm had run its own code through one of the best available AI models and the review found nothing serious. The attackers had the same tools. Multisig with three keys from the same model, same firmware, same generation method is not three defenses — it’s one failure wearing three signatures. The sweep skipped every address holding under 0.15 BTC and touched no Taproot or multisig outputs, which reads like a filtered pull rather than a finished one. Glitchwire has already put the ongoing tally above $40M.
"The Coldcard drain isn’t a Bitcoin failure. The protocol does exactly what it’s told. What it exposes is how badly we want a single thing to point at when something breaks."
— @sminston_with
— @sminston_with
The Technologist read: what actually broke the attack was entropy the device did not generate. Fifty fair dice rolls. A strong, unique BIP-39 passphrase. Everything else was arithmetic dressed up as randomness — a check that never verified what it was supposed to verify, a fallback that failed silently instead of halting, five years of audits that confirmed the real hardware generator sat inside the firmware but never confirmed that seed creation actually reached it. The bug isn’t the whole cause. It’s a piece of a bundle: bug plus no passphrase plus single-sig plus an xpub sitting on-chain plus a silent fallback plus five years of nobody looking at the right line. Remove any one piece and the theft doesn’t happen. Passphrase is the cheapest piece to remove — it costs nothing, and it kills the whole bundle.
"A hardware wallet implementation failed. Self-custody did not. Proper self-custody must never depend on a single device alone."
— Tony Yazbeck, The Bitcoin Way (@V4BTC)
— Tony Yazbeck, The Bitcoin Way (@V4BTC)
Block has raised unresolved questions about the RNG design used in Mk4, Mk5, and Q; practical exploitation of those newer models has not been established, but the investigation continues. Coinkite’s guidance stands: any Mk3 seed generated on firmware 4.0.1 onward, any Mk4 or Mk5 seed made before 5.6.0, and any Q seed before 1.5.0Q should be treated as exposed. Updating firmware protects future seeds and repairs nothing already made. Only migrating to a freshly generated seed — on an unaffected device, or on an affected device using dice-only entropy — removes the exposure. The Maximalist read: our entire ethos is verify, don’t trust. The one thing this hinges on — whether your seed came from real randomness — is the one thing almost none of us can verify. We swore off trust and then trusted the RNG. Sovereignty didn’t fail. Verification of the RNG was never actually done.
Not your keys, not your coins.
Not your entropy, not your keys.
Not your entropy, not your keys.
CoinDesk · Bitcoin engineering root-cause · fri jul 31 2026
MORE COVERAGE
PROTECT YOUR SOVEREIGNTY — COLDCARD MK3 MIGRATION GUIDE.
COLDCARD MK3 ADVISORY — SEEDS AFTER FIRMWARE 4.0.1 AT RISK. COINKITE SELF-DISCLOSES.