Eight Years of Bitcoin Savings Lost in Fifteen Minutes. Hardware Manufacturer's Error Cost 1367 BTC

By: rootdata|2026/08/02 16:41:32

A user on the r/Bitcoin subreddit on the social media platform Reddit, using the pseudonym DuckDuckMoss, shared his story with the community. He writes that due to a software error in his hardware wallet, he lost his 2 BTC that he had saved for eight years. His post is one of hundreds of similar accounts that have emerged online since July 30, when an unknown perpetrator began draining wallets set up on Coldcard devices. According to calculations by Galaxy Research, 1367 BTC, worth approximately $88.6 million, has disappeared from victims' accounts so far.

Key Facts

  • The cause is an integration error in Coldcard's software, which since March 2021 directed the generation of seed phrases to a software-based, predictable pseudorandom number generator.
  • Instead of the intended 128 bits of entropy, seeds from the Mk3 model had about 40 bits, while those from Mk4, Mk5, and Q had around 72 bits.
  • Three waves of attacks targeted 4585 addresses. The haul amounts to 1367 BTC and has not been touched so far.
  • Coinkite released emergency software for all models, but the update does not fix previously generated seeds.
  • The debate has resurfaced about whether individual investors should even manage their private keys themselves.

A Line of Code from March 2021 as the Source of the Crisis

Coldcard is a hardware wallet from the Canadian company Coinkite, exclusively supporting Bitcoin and regarded for years as the hardware for the most demanding users. Its software runs on a modified MicroPython. In the board configuration, the manufacturer deliberately disabled the built-in support for the hardware generator because it had its own implementation. The problem is that the libngu library only checked whether the appropriate flag existed at all, not what its value was. The compilation passed without warning, and the randomness-fetching function ended up in the software backup path inherited from MicroPython.

This backup generator initializes once, at the first call, based on the chip's factory number and clock states. None of these values are cryptographic secrets. The serial number is fixed and partially visible even in the device's USB identifier, and the time registers can be narrowed down to a small number of possibilities. A detailed reconstruction was published by Block's security team in a technical report on the emergency generator in Coldcard's firmware.

The change entered the repository on March 1, 2021, and reached the released software on March 17 with version 4.0.0. All drained addresses were created after this date. The attacker did not need to touch any device. It was enough to recreate possible random streams, derive addresses from them, and compare them with the public blockchain.

Three Waves and 4585 Addresses

The first sweep of wallets lasted from 3:10 to 3:51 Polish time on July 30 and spanned nine blocks. Chainalysis estimated that over $30 million disappeared in the first ten minutes, with the largest single victim losing about $1.8 million. Initial estimates spoke of 594 BTC from nearly 500 wallets. Subsequent analyses by Galaxy Research raised this number to 1082, then to 1158, until August 1 when a third wave was detected, in which 207.73 BTC were extracted from 1912 addresses. This time, the perpetrator targeted balances in the range of a few thousand dollars, settling for "small change."

The stolen funds remain untouched at the attacker's addresses. Analysts note that all transactions had the same fee rate and did not generate change, allowing them to be grouped, but this in itself proves nothing. A batch transfer looks identical regardless of whether the coins are moved by the thief or the owner.

Coinkite issued a relevant warning on July 30, and the following day they released updated software for all models and both release paths. However, the manufacturer notes in an official security statement that the update only secures new seeds and does not fix those already created. Those who added at least 50 fair, unsaved dice rolls when setting up their wallet are safe. A strong, unique BIP-39 password creates a separate wallet and significantly complicates matters, but the manufacturer still recommends migration. Multisig only protects if the quorum does not consist solely of vulnerable devices. TAPSIGNER, OPENDIME, and SATSCARD operate on different code and are not affected by the issue.

Should the Average Investor Guard Their Own Key?

Rodolfo Novak, head of Coinkite, apologized to users and took responsibility for the error, admitting that internal code reviews did not catch it. He suggested that the vulnerability might have been discovered by artificial intelligence running through older versions of the open firmware. A few weeks earlier, the company had run the same code through one of the best available models and received no warning signals. However, some researchers believe that the AI thread distracts from a simple engineering mistake that a standard key generation audit should have caught years ago.

Industry reactions are sharp. Commentator Guy Swann called it the most painful blow in Bitcoin's history aimed at people who secured themselves correctly, as this time it is not about an exchange with hot keys, but about thousands of private wallets. Lorenzo Valente from ARK Invest stated directly that clients have swapped counterparty risk for software, hardware, supply chain, and their own mistake risks. Nick Neuman from Casa criticizes the manufacturer's recommendation itself, as adding fifty dice rolls is not feasible for the vast majority of users. David Lawrence from Amicus adds that after such incidents, new investors will choose ETFs and regulated custodians.

Exactly this conclusion was drawn by a Reddit post author who regrets not buying shares in the investment fund when they launched. No one publicly verified his individual case, as he did not provide either the device model or the software version. Galaxy Research warns that the list of affected individuals may still grow. The vulnerability is already public, and some owners of vulnerable seeds have yet to transfer their funds.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com