594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.




Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Hardware wallets are supposed to remove a single category of risk: the possibility that someone who is not you can compute your private key. Early this morning, roughly 500 Bitcoin holders discovered that their devices had failed at exactly that job, and had been failing quietly since March 2021.
The loss came to about 594 $BTC, roughly $38 million, and it took 25 minutes.
Bitcoin Wallet Hack: What exactly happened?
Between 01:31 and 01:56 UTC on Friday 31 July 2026, an attacker swept funds out of around 500 separate Bitcoin wallets. The mechanics were industrial. More than 1,300 individual UTXOs were moved across 500 transactions inside a three-block window, then 562 BTC was consolidated into a single address. At the time of writing, that address has not moved.
The victim profile is unusually consistent:
- Every drained wallet was single-signature.
- Every one held more than 0.15 BTC.
- Most had been dormant for years.
- Wallet creation dates spanned 2021 to 2026, closely matching the window during which the flaw was live.
That last point is the tell. The attacker was not picking targets by observing the network. The targets were determined by when each wallet was created.
How did the attacker guess keys that should be unguessable?
This is the part that matters, and it has nothing to do with phishing, malware, or a compromised computer.
A Bitcoin seed phrase is meant to be drawn at random from a pool so vast that guessing is arithmetically hopeless. The entire security model rests on that randomness being real. Hardware wallets include a dedicated hardware random number generator precisely so that the randomness does not depend on software.
According to analysis published by the Bitcoin engineering and security teams at Block, affected Coldcard firmware was not using it.
A build setting instructed the device to skip its own hardware randomness generator. A check in a supporting library then tested only whether that setting existed, not whether it was switched on. With no working hardware source and no error raised, key generation fell through to a basic software substitute, seeded from the device's serial number and its internal clock registers.
Neither of those inputs is secret. The serial number is fixed factory metadata. The clock values are timing state that an attacker can narrow down, or simply measure on an identical device they own.
The result: a seed that was supposed to be one candidate among an unimaginable number became a solvable problem. Coinkite, the Canadian firm that builds Coldcard, traced the change to a commit dated 1 March 2021, shipped in firmware 4.0.0 that same month.
The flaw sat in production for nearly five and a half years before someone exploited it.
Which Coldcard devices are affected?
Coinkite's advisory centres on Mk3 devices where the seed was generated on firmware 4.0.1 or later. Based on preliminary analysis, the company says Mk4, Q and Mk5 appear unaffected.
One critical distinction: exposure depends on which firmware was running at the moment the wallet was created, not on when you bought the device or what firmware it runs today. Updating your firmware now does not retroactively fix a seed that was generated with bad randomness. The key material is already weak.
Reporting on the full list of affected models has not been fully consistent, and the investigation is still developing. If your seed was generated on any older Coldcard, treat it as suspect until Coinkite confirms otherwise rather than assuming your model is on the safe list.
What should you do right now if you own a Coldcard?
Coinkite is urging affected users to move their funds. Concretely:
- Identify which device and firmware generated your seed. Not what it runs now. What it ran when the wallet was first created.
- If that was an Mk3 on firmware 4.0.1 or later, treat the seed as compromised. Not at risk. Compromised.
- Generate a fresh wallet on a device you have reason to trust, and move the funds. Do not reuse the existing seed anywhere.
- Do not wait for confirmation that you were specifically targeted. The wallets drained this morning were mostly dormant, which means their owners were not watching. The attack cost nothing per additional target.
- Consider multi-signature for meaningful balances. Every wallet drained in this incident was single-signature. A multi-sig setup across devices from different manufacturers would have survived a flaw in any one of them.
If you generated your seed by rolling dice and entering the entropy yourself, a practice Coldcard has long supported, your randomness did not come from the broken code path.
Why did the Bitcoin price not react?
It barely moved. Bitcoin traded around $63,847 through the morning, down roughly 1% on the day and already softer on the week before the news landed.
Partly that is scale. $38 million is a rounding error against a $1.28 trillion market cap, and the stolen coins have not been sold, only consolidated. Partly it is the current market. This week also contained a record two-day crash in Korean equities and a 17% KOSPI rebound, and crypto ignored both. A market where almost nothing produces a reaction is not necessarily a strong one.
What does this actually tell us about hardware wallets?
Three things worth separating from the panic.
- This is not a Bitcoin failure. The protocol worked exactly as designed. It faithfully executed valid signatures from keys the attacker was able to reconstruct. Nothing about Bitcoin's cryptography was broken.
- This is not an argument against self-custody. Exchange failures have cost holders far more than $38 million, repeatedly. The lesson is not that self-custody is unsafe, it is that a hardware wallet is a piece of software running on a small computer, and software has bugs.
- It is an argument against single points of failure. The uncomfortable feature of this incident is the delay. A silent randomness failure produces no symptoms. Nothing looks wrong. There is no alert, no failed transaction, no warning. The wallet works perfectly for five years and then, in 25 minutes, does not.
That is the case for multi-signature setups, for hardware from more than one vendor, and for user-supplied entropy on high-value wallets. Not because any single device is untrustworthy, but because a device that fails silently gives you no chance to notice before it matters.
Frequently asked questions about the Coldcard firmware flaw
Related articles
- Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
- $130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
- How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
- Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
- How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
August 21, 2026 7:26 PM

Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
Your seed is yours; the device belongs to a company. This article explains what the open BIP39 standard actually guarantees, why a wrong derivation path makes a full wallet look empty, and the test that settles both in twenty minutes.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 23, 2026 10:15 AM

Coldcard 5.6.1 Is Here: Why the Update Will Not Rescue Your Old Seed
Coinkite shipped Coldcard firmware 5.6.1 and 1.5.1Q on August 20, 2026. The update closes the gap for new seeds but does not repair a seed already affected.
April 27, 2026 10:30 AM

Win $5,000 in BTC: Tangem Launches Exclusive 2026 Prize Draw
Tangem announces a massive prize draw with $5,000 in BTC and iPhone 17s up for grabs. Secure your crypto and enter today using our exclusive link.
September 10, 2026 1:14 PM

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 22, 2026 10:29 AM

Bitcoin Fork: What Happens to Your Coins When the Chain Splits
On October 31, 2026 a new chain called ECX splits off from Bitcoin, and every holder is credited automatically. Who actually receives the coins depends on the private keys, on voluntary replay protection and on a tax rule many overlook.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
September 3, 2026 10:21 AM

Bitcoin Lost in a Wallet Hack: What Tax Applies in Austria?
Bitcoin lost to hackers? In Austria, the theft of privately held coins generally does not create a capital loss you can use for tax. Only a later payout can change that.
August 22, 2026 4:34 PM

BitBox02: Firmware 9.26.5 Closes Three Security Vulnerabilities. What to Check Now
BitBox released firmware 9.26.5 on August 17, 2026, closing three security vulnerabilities in the BitBox02 and BitBox02 Nova. Existing seeds are not affected according to the manufacturer; an update is due anyway, and with unused devices the order matters.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 7, 2026 1:27 PM

Liquid Network: Around 4,000 Bitcoin Drained via a Peg-Out, and What L-BTC Holders Must Check Now
Around 4,000 Bitcoin drained out of the Liquid Network federation wallet on September 6, even though no key was stolen. The network is halted and redemption is blocked. Here is what you should check now as an L-BTC holder.
September 26, 2026 7:34 AM

Setting Up a Multisig Wallet: When Two of Three Keys Are Worth It for You
A multisig wallet demands several keys for a transfer and so makes a single theft worthless. We show which threshold fits you, what you have to back up besides the keys, and why most setups fail at the configuration.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
September 11, 2026 1:26 PM

Alby Hub Security Flaw: How to Check Whether Your Bitcoin Lightning Node Is Reachable From the Internet
Alby confirmed a critical flaw in Alby Hub v1.7.0 through v1.18.5 on September 9, 2026; it is only exploitable if the management interface sits openly on the internet. What to check on your node, why the fix is a good twelve months older than the warning, and which step comes before the update.
December 28, 2018 3:02 PM

How To Use a Trezor Wallet?
Trezor is a hardware wallet which gives exceptional security for managing Bitcoin and other cryptocurrencies private keys.It incorporates and deposits personal keys securely and enables users to carry trade without an Internet link. Trezor grants its users with numerous benefits, […]
September 25, 2026 7:11 AM

EU Supervisors Rate Quantum Risk as High: What to Check on Crypto Custody and Exchange Choice
EBA, EIOPA and ESMA name quantum computers explicitly as a threat to blockchain cryptography in their autumn risk picture of September 23. What the paper says, which migration deadlines run to 2030, and three things you can check about your custody.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
More from CryptoTicker


