Invest1 distinct publisher3 min readUpdated
A 2021 seed flaw cut entropy from 128 bits to about 40, so no attacker needed to touch the hardware. Every seed generated before July 2026 now has to be replaced.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Air-gapping protects a seed after it exists; it says nothing about how the seed was born. A wallet that never touches a network still publishes a public key the first time it receives coins, and if the private key behind it came from a pool of roughly 1.1 trillion candidates rather than 2^128, every step of the attack happens off the device [1][8]. Cutting entropy from 128 bits to about 40 shrinks the search space by a factor of around 3 x 10^26 [2]. The physical isolation held. The secret it was guarding did not [8].
The tempo of the first wave says the same thing. Roughly 500 wallets emptied in 25 minutes works out to 20 a minute [3], and those 594 BTC were about a third of everything eventually taken [8], which reads as a list being worked through rather than a search being run. Galaxy Research called the campaign deliberate and programmatic, possibly orchestrated with a large language model [5]. Coinkite has suggested the attackers used AI to read older releases of its open-source firmware [15]. Both readings point at the archive: nothing a vendor has ever published stops being readable, and a volunteer Bitcoin Red Team has already run AI agents over hundreds of Bitcoin projects and surfaced thousands of candidate bugs [18].
The new seed requirement is calibrated rather than decorative. A run of 128 fair coin flips carries 128 bits; 50 rolls of a six-sided die carries about 129 [4]. Either option reconstitutes the full target on its own, before the device mixes in whatever its own generator produced [9]. That is a vendor conceding it should not be the only source of randomness, and the price is a buyer sitting there flipping a coin 128 times. Coinkite also replaced the Yasmarang backup PRNG with SHA-256 Hash_DRBG and added checks for hardware RNG failure [10].
The larger bill is the migration. Anyone whose seed came from affected firmware between 2021 and July 2026 has to generate a new one and move the coins [11], which is about five years of devices [7]. The first Galaxy tally averaged roughly $19,300 per address [5], the shape of ordinary self-custody rather than a handful of whales. The total also keeps moving: about $18 million, or 16 percent, has been added since the August 14 count [6], and Coinkite says the investigation is still open while customers relocate funds [19]. Treat $130 million as a running figure [7].
The most useful item in the release is the fix nobody was owed. Coldcard now re-checks a partially signed transaction immediately before signing, closing a path where a compromised USB host could alter a transaction between the user's review and the signature; Coinkite describes that as theoretical and does not say it was used [12][13]. Three weeks of concentrated outside attention also produced changes to USB data handling, firmware validation, Delta Mode and backups [14][2]. The seed bug was the one found first, not the only one there. Ledger CTO Charles Guillemet, a competitor with an interest in saying it, told Decrypt that a hardware wallet's security model lives or dies on randomness [16]. The checkable part of that is narrower and more useful: user-supplied entropy is the one input a vendor cannot quietly get wrong.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Coinkite released a security overhaul for its Coldcard Bitcoin hardware wallets after a seed-generation flaw allowed attackers to steal more than $100 million in Bitcoin, and in a blog post on Thursday urged Coldcard Mk4, Mk5 and Q users to upgrade to firmware 5.6.1 or 1.5.1Q.
The release followed a three-week review of Coldcard's systems that included outside security researchers and AI models including Kimi.
In July, attackers began draining Bitcoin from air-gapped Coldcard wallets after exploiting a firmware flaw dating to 2021 that generated some wallet seeds with too little randomness, making private keys easier to guess.
The first attack drained 594 BTC, worth about $38 million, from roughly 500 wallets in 25 minutes.
By early August, Galaxy Research had tracked roughly $88.6 million stolen across 4,585 addresses and said the attacks appeared deliberate, programmatic, and potentially orchestrated using a large language model.
By August 14, Galaxy Research said attackers had stolen more than 1,778 BTC, worth roughly $112 million at the time, across three major attack waves and dozens of smaller incidents.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Vendor disclosure plus named research, one outlet
The technical remediation details are specific and traceable to a Coinkite blog post (firmware versions, entropy thresholds, Hash_DRBG swap, PSBT re-check), and the loss escalation is attributed to Galaxy Research with dated figures. Evidence quality is limited by the cluster carrying a single publisher, by the headline roughly $130 million total being stated without attribution, and by the absence of any independent verification of the new RNG design or of the number of affected devices.
Fix shipped, migration mandatory but uptake unmeasured
Adoption is real rather than announced: firmware is released for three device lines, the entropy requirement is live in the shipping build, and affected holders are actively regenerating seeds and moving funds. It is capped because no upgrade-rate, device-count, or migration-completion data is reported, and because the counterfactual - roughly $130 million already drained across thousands of addresses - shows how much of the affected base was reached by attackers before the fix.
AI attribution runs ahead of proof
The core loss and remediation facts are concrete and, if anything, undersold in technical terms. The overstatement sits in the causal framing: Coinkite's suggestion that attackers used AI on older open-source firmware and Galaxy's 'potentially orchestrated using a large language model' are hypotheses, yet they anchor the story's larger AI-versus-Bitcoin narrative alongside the Boltz suspension and Red Team scans. The unattributed jump to roughly $130 million from the last sourced $112 million adds a modest further gap.
Vendor self-disclosure with rival commentary
Most technical detail originates in Coinkite's own post-incident blog, which has an interest in framing the flaw as narrow, the AI-assisted attacker as an unusually capable adversary, and the migration as well supported. The one outside voice is Ledger's CTO, a direct competitor in hardware wallets, whose randomness commentary doubles as positioning. Galaxy Research's tallies are the least conflicted input, and the publisher is a crypto-native outlet dependent on industry access.
Specific and verifiable, but single-publisher
Confidence is supported by the unusual specificity of the technical claims and by dated third-party loss tracking, and constrained by the cluster's single publisher, the unattributed current loss total, and the absence of exposure-scope and remediation-uptake data. The remediation facts are high confidence; the attacker-methodology and total-damage claims are materially softer.
invest
Touchmark opens a forwards market for tokens because finance cannot forecast them1 distinct publisher
security
The bottleneck moved: 622 CVEs in July, and no one left to write up the fixes1 distinct publisher
invest
Novig sues Wisconsin, and the swap question becomes the whole addressable market1 distinct publisher
invest
Israel's first licensed crypto broker becomes its most valuable identity target1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026