Key Points
- Coldcard firmware flaw exposed weak seed entropy, leading to 1,367 BTC in confirmed losses.
- Incident highlights recurring crypto security failures tied to inadequate randomness generation.
A vulnerability in the firmware of Coldcard hardware wallets has been linked to the confirmed loss of 1,367 Bitcoin (BTC), valued at roughly $86 million as of August 2, 2026.
On-chain analysis published by Galaxy Research identified 4,585 affected addresses tied to the flaw.
The breach is considered the largest confirmed hardware wallet loss involving Bitcoin and reportedly did not require phishing, physical access, or user mistakes.
At the time of reporting, Bitcoin was trading around $62,250, down 1.4% on the day, following a volatile الأسبوع during which it fell from above $65,000.
Twenty-four-hour trading volume stood near $16.9 billion, compared with more than $20 billion the previous day.
How the Vulnerability Affected Seed Generation
According to engineering findings, the issue originated in Coldcard’s libngu library and dates back to firmware released in March 2021.
A configuration error involving a preprocessor macro disabled the intended hardware true random number generator (TRNG).
Because the guard condition only checked whether the macro was defined, a zero value was accepted, preventing the hardware RNG from operating as expected.
As a result, MicroPython relied on Yasmarang, a software-based pseudo-random number generator offering about 40 bits of effective entropy rather than the 128 bits typically expected for a BIP-39 seed phrase.
Later Coldcard models reportedly improved entropy levels to about 72 bits, though this remained below the standard 128-bit threshold.
On July 30, 2026, a security notice was issued shortly before approximately 594 BTC were drained from around 500 addresses.
Two additional waves of suspicious transactions followed, bringing total confirmed losses to 1,367.05 BTC across 4,585 addresses by August 2.
Blockchain data indicates that most of the stolen funds have not yet been moved.
Broader Crypto Security Implications
Security researchers note that the incident reflects a broader pattern of entropy-related failures in cryptographic systems.
In 2013, Android’s SecureRandom flaw led to repeated ECDSA nonces, exposing private keys across multiple Bitcoin wallets.
The 2022 Wintermute exploit involving the Profanity vanity address generator was also linked to limited entropy, reportedly seeded with only 32 bits.
In 2023, the Milk Sad disclosure revealed that Libbitcoin Explorer’s “bx seed” command used a Mersenne Twister seeded by system time, reducing expected entropy and exposing thousands of wallets.
Policy analysts at TRM Labs stated that infrastructure and key compromises accounted for a majority of total hack-related losses in the first half of 2026, despite representing a smaller share of overall incidents.
Galaxy Research reported that it shared approximately 600 suspected attacker-controlled addresses with investigators, compliance firms, and cybersecurity organizations, noting that its attribution is based on on-chain heuristics.



