Bitcoin’s ‘Safest’ Wallet Backfires — $89M Vanishes

In less than an hour, a “safe” offline bitcoin wallet turned into a $70 million trap door, and the fallout has now climbed toward $89 million across thousands of addresses.

Story Snapshot

  • About 1,082 bitcoin vanished from 1,196 addresses in a 41-minute sweep tied to Coldcard wallets.
  • Three waves of attacks now total about 1,367 bitcoin stolen, worth nearly $89 million.
  • Researchers blame a firmware bug that quietly weakened seed generation on Coldcard hardware.
  • Self-custody fans just watched their “safest” storage fail, raising hard questions about trust and responsibility.

How One Bug Turned Cold Storage Into A Hot Target

The attack began where many bitcoin holders felt most secure: inside Coldcard hardware wallets made by Canadian company Coinkite. These devices are marketed as “air-gapped” safes, designed so keys never touch the internet. But a hidden flaw in the code that creates wallet seeds turned that strength into a weakness.

Researchers say a firmware error dating back to March 2021 weakened the randomness used to generate seeds, which are the master keys for bitcoin addresses. That mistake let attackers recreate those keys offline and drain funds without touching a single physical device.

Security teams at Galaxy Research and others traced the root of the problem to the way Coldcard firmware handled random number generation. Instead of fully using the hardware random number generator, affected versions sometimes fell back to a predictable software generator.

When randomness turns predictable, encryption turns guessable. Attackers appear to have used heavy computing power to brute-force seed phrases tied to vulnerable wallets. Once they derived a seed, they could sign transactions as if they were the rightful owner and empty the wallet at will.

The Three Waves That Emptied Thousands Of Wallets

The first visible wave hit fast and hard. Galaxy Research says that between about 01:10 and 01:56 Coordinated Universal Time on July 30, 2026, an attacker swept 1,082.65 bitcoin from 1,196 addresses in just 41 minutes.

At the time, that haul was worth about $70 million and mostly came from larger balances. Fox Business reported that this blast targeted wallets whose seeds had been generated on affected Coldcard devices and shocked users who thought long-dormant addresses were safer, not more exposed.

Forbes coverage of the same window added fuel to market fears, calling it a “massive surprise bitcoin attack” as traders watched funds move at machine speed.

The story did not stop there. In the following days, researchers saw a second and third wave that looked like smaller follow-up sweeps. Galaxy Research and CoinDesk now estimate total losses of about 1,367 bitcoin, nearly $89 million, across roughly 4,585 addresses.

Later waves hit many more wallets but often drained smaller amounts from each, suggesting the attacker shifted from whales to everyday holders once the first strike succeeded.

Social media posts from analysts and victims describe life savings disappearing in minutes, adding human faces to what might otherwise look like just numbers on a blockchain.

What Went Wrong Inside The Firmware

The painful part for technically minded readers is that this was not a complex zero-day involving exotic malware. It was a basic failure of randomness.

Coinkite’s own advisories and independent writeups say a March 2021 firmware build for Coldcard Mk3 devices introduced a bug that disabled the hardware random number generator on some units.

When that happened, seed generation quietly relied on a software fallback using non-secret chip data. That data does not have enough unpredictability for strong cryptography.

Researchers from Block’s Bitcoin engineering team and others concluded that a patient attacker could reverse-engineer those seeds with enough computing power.

They chose self-custody over trusting big exchanges, accepted personal responsibility, and followed the rules. A single misstep in firmware turned that responsible behavior into exposure.

Coinkite has since pushed patched firmware and warned users whose seeds were generated on affected versions to rotate to new, safe wallets. That response is necessary, but it does not erase the damage for those already drained.

Self Custody, Trust, And The New Reality For Bitcoin Holders

This crisis hits a core belief in the Bitcoin world: “not your keys, not your coins.” Many on the right like that saying because it rewards discipline and independence. However, this event shows that “your keys” only matter if the tools that create and store them truly work.

A hardware wallet built on flawed code can fail just as badly as a sloppy centralized exchange. The difference is that when self-custody breaks, there is no customer service line and usually no refund. You are the bank, and the bank eats the loss.

For future Coldcard users and anyone holding bitcoin offline, the lesson is simple but harsh. Do not trust the brand or the marketing alone. Trust the process.

That means checking firmware versions, following security advisories quickly, and, when possible, using methods that add real-world randomness—like rolling physical dice—to seed generation instead of relying only on device software.

Security researchers warn that every vulnerable wallet created since the flawed firmware appeared will likely be emptied sooner or later, because attackers can keep grinding through seeds until they find them. In other words, if you are at risk and do nothing, the next wave may include you.

Sources:

foxbusiness.com, thehackernews.com, techspot.com, cryptopolitan.com, youtube.com, crypto.news, reddit.com