Eight Years of Bitcoin Savings Lost in Fifteen Minutes. Hardware Manufacturer's Error Cost 1367 BTC
A user on the r/Bitcoin subreddit on the social media platform Reddit, using the pseudonym DuckDuckMoss, shared his story with the community. He writes that due to a software error in his hardware wallet, he lost his 2 BTC that he had saved for eight years. His post is one of hundreds of similar accounts that have emerged online since July 30, when an unknown perpetrator began draining wallets set up on Coldcard devices. According to calculations by Galaxy Research, 1367 BTC, worth approximately $88.6 million, has disappeared from victims' accounts so far.
Key Facts
- The cause is an integration error in Coldcard's software, which since March 2021 directed the generation of seed phrases to a software-based, predictable pseudorandom number generator.
- Instead of the intended 128 bits of entropy, seeds from the Mk3 model had about 40 bits, while those from Mk4, Mk5, and Q had around 72 bits.
- Three waves of attacks targeted 4585 addresses. The haul amounts to 1367 BTC and has not been touched so far.
- Coinkite released emergency software for all models, but the update does not fix previously generated seeds.
- The debate has resurfaced about whether individual investors should even manage their private keys themselves.
A Line of Code from March 2021 as the Source of the Crisis
Coldcard is a hardware wallet from the Canadian company Coinkite, exclusively supporting Bitcoin and regarded for years as the hardware for the most demanding users. Its software runs on a modified MicroPython. In the board configuration, the manufacturer deliberately disabled the built-in support for the hardware generator because it had its own implementation. The problem is that the libngu library only checked whether the appropriate flag existed at all, not what its value was. The compilation passed without warning, and the randomness-fetching function ended up in the software backup path inherited from MicroPython.
This backup generator initializes once, at the first call, based on the chip's factory number and clock states. None of these values are cryptographic secrets. The serial number is fixed and partially visible even in the device's USB identifier, and the time registers can be narrowed down to a small number of possibilities. A detailed reconstruction was published by Block's security team in a technical report on the emergency generator in Coldcard's firmware.
The change entered the repository on March 1, 2021, and reached the released software on March 17 with version 4.0.0. All drained addresses were created after this date. The attacker did not need to touch any device. It was enough to recreate possible random streams, derive addresses from them, and compare them with the public blockchain.
Three Waves and 4585 Addresses
The first sweep of wallets lasted from 3:10 to 3:51 Polish time on July 30 and spanned nine blocks. Chainalysis estimated that over $30 million disappeared in the first ten minutes, with the largest single victim losing about $1.8 million. Initial estimates spoke of 594 BTC from nearly 500 wallets. Subsequent analyses by Galaxy Research raised this number to 1082, then to 1158, until August 1 when a third wave was detected, in which 207.73 BTC were extracted from 1912 addresses. This time, the perpetrator targeted balances in the range of a few thousand dollars, settling for "small change."
The stolen funds remain untouched at the attacker's addresses. Analysts note that all transactions had the same fee rate and did not generate change, allowing them to be grouped, but this in itself proves nothing. A batch transfer looks identical regardless of whether the coins are moved by the thief or the owner.
Coinkite issued a relevant warning on July 30, and the following day they released updated software for all models and both release paths. However, the manufacturer notes in an official security statement that the update only secures new seeds and does not fix those already created. Those who added at least 50 fair, unsaved dice rolls when setting up their wallet are safe. A strong, unique BIP-39 password creates a separate wallet and significantly complicates matters, but the manufacturer still recommends migration. Multisig only protects if the quorum does not consist solely of vulnerable devices. TAPSIGNER, OPENDIME, and SATSCARD operate on different code and are not affected by the issue.
Should the Average Investor Guard Their Own Key?
Rodolfo Novak, head of Coinkite, apologized to users and took responsibility for the error, admitting that internal code reviews did not catch it. He suggested that the vulnerability might have been discovered by artificial intelligence running through older versions of the open firmware. A few weeks earlier, the company had run the same code through one of the best available models and received no warning signals. However, some researchers believe that the AI thread distracts from a simple engineering mistake that a standard key generation audit should have caught years ago.
Industry reactions are sharp. Commentator Guy Swann called it the most painful blow in Bitcoin's history aimed at people who secured themselves correctly, as this time it is not about an exchange with hot keys, but about thousands of private wallets. Lorenzo Valente from ARK Invest stated directly that clients have swapped counterparty risk for software, hardware, supply chain, and their own mistake risks. Nick Neuman from Casa criticizes the manufacturer's recommendation itself, as adding fifty dice rolls is not feasible for the vast majority of users. David Lawrence from Amicus adds that after such incidents, new investors will choose ETFs and regulated custodians.
Exactly this conclusion was drawn by a Reddit post author who regrets not buying shares in the investment fund when they launched. No one publicly verified his individual case, as he did not provide either the device model or the software version. Galaxy Research warns that the list of affected individuals may still grow. The vulnerability is already public, and some owners of vulnerable seeds have yet to transfer their funds.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

What is a public key in crypto? Keys, addresses, and signatures explained

What Changes with the $1 Billion Credit Facility for USDe? Latest Insights

Binance Ends Wealth Effect of Exchanges, Trump Starts New Wave of Wealth Creation

From Buffett to Dan Bin: Top Seven Funds' 13F Reports Reveal New Round of AI Investment Rotation

Opinion: Binance Ends Wealth Effect of Trading Platforms, Trump Initiates a New Wave of Wealth Creation

Cryptocurrencies: He Steals $500,000 in USDC and Gets Ripped Off by an MEV Bot on Base

Quantum Computer Q-Day: Tether's Issuance Key May Be Compromised Before Bitcoin

Quantum computer attack may mimic wallet hack, says Quantus co-founder

Discussing L1 Value Capture Through Two Proposals from Solana

Can On-Chain Options Replicate the Rise of Perpetual Contracts?

What is account abstraction and why seed phrases are becoming optional

BNB Chain sues ex-employee over $628K memecoin trade

The Trust Trap of Open Protocols: Why Does x402 Need a Centralized Accountability Layer?

Bitcoin is about to give miners a 16% lifeline, but $19 billion in AI deals is luring them away anyway

Cardano founder says quantum threat could dethrone Bitcoin

Hotcoin Research | The Second Battlefield of the AI Super Cycle: A 24/7 On-Chain Pricing Experiment

Robinhood Provides Answers: Why Ethereum Becomes the Optimal Solution After Entering the Real Economy

Best AI Crypto Coins 2026: Top 7 Tokens Ranked by Data

How to Stake Solana: A Step-by-Step Guide for 2026

Morning News | Michael Saylor stated that this week he bought bonds instead of Bitcoin; StablR was attacked and lost about 2.8 million dollars; the U.S. Congress is pushing the Bitcoin Reserve Act again

Security experts warn: AI is accelerating the threat of quantum computing, and the encryption industry faces a continuous security arms race

Circle: From Issuance to Infrastructure

Project Eleven warns that the quantum critical point may "erupt instantly," expected to arrive as early as 2030

CoinEx Founder: The Crypto Endgame in My Eyes

Crypto Regulation News 2026: SEC-CFTC Framework, GENIUS Act, and MiCA 2 Coming
Latest crypto regulation news April 2026: SEC-CFTC joint guidance establishes five-category token taxonomy, Treasury and FDIC propose GENIUS Act implementing rules, EU signals MiCA 2 coming. Actionable compliance insights inside.

What Is RWA? What Is RWA in Crypto (Complete 2026 Guide)
Wondering what is RWA in crypto? We explain what RWA is, break down RWA tokenization in simple no-jargon terms, and cover why it's 2026's hottest crypto narrative.

CoinShares 2026 Report: Have Bitcoin Miners Reached Their Toughest Moment?










