Overview
- Security teams say attackers precomputed weak seeds and executed rapid scripted sweeps that emptied vulnerable single-signature Coldcard addresses on July 30, 2026.
- Initial tallies reported about 594 BTC drained in roughly 25 minutes but blockchain analysts later mapped larger coordinated waves with estimates ranging up to 1,367.05 BTC across multiple waves.
- Block’s engineers traced the root cause to a March 2021 firmware build setting that bypassed the hardware RNG and fell back to a predictable software routine seeded by non-secret chip data.
- Coinkite released emergency firmware fixes and warned that updating firmware does not secure seeds already created, so users must generate entirely new recovery phrases on fixed devices and migrate funds.
- The incident underscores practical defenses for self-custody: use multi-signature setups, add manual entropy (for example dice-generated seeds or strong passphrases), and demand stricter firmware build and audit controls.