A hardware wallet sells one thing: distance. Keep the key on a device that never touches the internet, and there is nothing for an attacker to reach. That promise held. It was the wrong promise.
Galaxy Research mapped the full event Friday: between 01:10:20 and 01:51:26 UTC on July 30, an attacker drained 1,196 Coldcard-generated bitcoin addresses in full — 1,082.65 BTC, worth roughly $70.2 million. The proceeds sit in four addresses and have not moved. The total is nearly double the 594 BTC first reported Thursday, because early tracing caught only one of the four.
Nobody phished a laptop or breached an exchange. A wallet is supposed to draw a seed so unpredictable that guessing it is impossible; every key and address follows from it by public rules. Coldcard’s firmware was meant to pull that number from a dedicated hardware randomness generator. A build setting told it to skip that generator, and a library check tested only whether the setting existed, not whether it was on. Generation fell through to a software substitute seeded from the chip’s serial number and clock registers — factory metadata and timing state, neither secret.
The range of keys the device could ever produce collapsed from astronomical to countable: security teams put it at roughly four billion possibilities on the Mk4, Q and Mk5. A big number to a person, a rounding error to a computer. The attacker generated candidate seeds on his own hardware, derived the addresses each would produce, and checked them against the public blockchain. The victims’ devices could have been powered off in a safe on another continent, and were.
Our take: What got repriced this week is not bitcoin. It is the discount investors were applying to self-custody. Holding your own keys was supposed to swap counterparty risk for no risk; it actually swaps it for firmware, supply-chain, backup and human risk, and one of those just got a dollar figure attached. ARK Invest’s Lorenzo Valente drew the blunt conclusion — that most consumers are “better off today holding funds across several publicly-traded exchanges or ETFs.” He has an obvious interest in that answer, and $70 million is small against the market. The direction still holds: incidents like this push marginal retail bitcoin toward custodians and funds.
The part that matters if you have never owned a Coldcard
The bug shipped in March 2021 with Mk3 firmware 4.0.1 and sat in public code for five years. Coinkite CEO Rodolfo Novak apologized Friday, took “full accountability for the firmware bug,” and said the company’s review process failed to catch it. He also suggested the flaw may have been found using AI, calling it “a sober reality of the new AI paradigm.”
That is the generalizable part. The cost of reading old code carefully just fell by an order of magnitude, and defenders are not the only ones reading. Every dormant flaw in shipped, public, unmaintained firmware is now a live search problem — a shift that landed the same week Anthropic disclosed its own models breaking into three real companies using nothing more exotic than weak passwords and SQL injection. Storing a key safely was always the hard half. It just became the easy half.
What to watch
- Whether the four addresses move. Block’s Clay Garrett says the operator queried the source addresses through a paid account at a blockchain-data provider whose logs matched the workflow down to timing and sequence, and has passed that to authorities. Dormant coin with a trail attached is not clean coin.
- Spot bitcoin ETF flows next week. If the self-custody scare is more than commentary, it shows up as rotation into custodied exposure — the same tape that broke a seven-day institutional streak in late July.
- The scope disagreement. Coinkite says its newer devices are unaffected; Block’s report puts the Mk2, Mk4, Q and Mk5 in scope too. Galaxy warned of further waves, and no owner can test their own wallet to find out.
- Price, as the control. Bitcoin held just above $63,000 into the weekend, keeping a July gain near 7.5%. This moved the self-custody argument, not the tape — unlike Coinbase’s third straight quarterly loss, which moved the stock.
Cold storage promised that a key is unguessable. Everyone heard it as a promise that a key is unreachable. For 1,196 wallets, only one of those was true.
