Markets

$70 million left 1,196 cold wallets in 41 minutes. Nobody touched a device.

Galaxy Research mapped 1,082.65 BTC swept between 01:10 and 01:51 UTC on July 30 — nearly double the first count. A firmware build error let Coldcard skip its hardware randomness generator and fall back to keys seeded by a chip serial number, collapsing the range of possible wallets to something a computer can count. The attacker rebuilt the keys offline. The devices were never involved.

N Noah · The Sharp Brief · August 1, 2026 · 4 min read

A hardware wallet sells one thing: distance. Keep the key on a device that never touches the internet, and there is nothing for an attacker to reach. That promise held. It was the wrong promise.

Galaxy Research mapped the full event Friday: between 01:10:20 and 01:51:26 UTC on July 30, an attacker drained 1,196 Coldcard-generated bitcoin addresses in full — 1,082.65 BTC, worth roughly $70.2 million. The proceeds sit in four addresses and have not moved. The total is nearly double the 594 BTC first reported Thursday, because early tracing caught only one of the four.

Nobody phished a laptop or breached an exchange. A wallet is supposed to draw a seed so unpredictable that guessing it is impossible; every key and address follows from it by public rules. Coldcard’s firmware was meant to pull that number from a dedicated hardware randomness generator. A build setting told it to skip that generator, and a library check tested only whether the setting existed, not whether it was on. Generation fell through to a software substitute seeded from the chip’s serial number and clock registers — factory metadata and timing state, neither secret.

The range of keys the device could ever produce collapsed from astronomical to countable: security teams put it at roughly four billion possibilities on the Mk4, Q and Mk5. A big number to a person, a rounding error to a computer. The attacker generated candidate seeds on his own hardware, derived the addresses each would produce, and checked them against the public blockchain. The victims’ devices could have been powered off in a safe on another continent, and were.

Our take: What got repriced this week is not bitcoin. It is the discount investors were applying to self-custody. Holding your own keys was supposed to swap counterparty risk for no risk; it actually swaps it for firmware, supply-chain, backup and human risk, and one of those just got a dollar figure attached. ARK Invest’s Lorenzo Valente drew the blunt conclusion — that most consumers are “better off today holding funds across several publicly-traded exchanges or ETFs.” He has an obvious interest in that answer, and $70 million is small against the market. The direction still holds: incidents like this push marginal retail bitcoin toward custodians and funds.

The part that matters if you have never owned a Coldcard

The bug shipped in March 2021 with Mk3 firmware 4.0.1 and sat in public code for five years. Coinkite CEO Rodolfo Novak apologized Friday, took “full accountability for the firmware bug,” and said the company’s review process failed to catch it. He also suggested the flaw may have been found using AI, calling it “a sober reality of the new AI paradigm.”

That is the generalizable part. The cost of reading old code carefully just fell by an order of magnitude, and defenders are not the only ones reading. Every dormant flaw in shipped, public, unmaintained firmware is now a live search problem — a shift that landed the same week Anthropic disclosed its own models breaking into three real companies using nothing more exotic than weak passwords and SQL injection. Storing a key safely was always the hard half. It just became the easy half.

What to watch

Cold storage promised that a key is unguessable. Everyone heard it as a promise that a key is unreachable. For 1,196 wallets, only one of those was true.

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 Side-Hustle Playbook (PDF) lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.