Cold Storage Didn't Fail. Randomness Did

A hardware wallet whose keys were predictable from the moment they were created

Between 01:31 and 01:56 UTC today, across three Bitcoin blocks, roughly 594.48 BTC — about $38 million — was swept out of around 500 single-signature wallets. On-chain analysts counted some 1,324 UTXOs moved in about 500 transactions; roughly 562 BTC was then consolidated into a single address that has not moved since. Hours later, Coinkite published a security advisory warning that seeds generated on its Coldcard Mk3 hardware wallets running firmware 4.0.1 (March 2021) through 5.0.3 may put funds at risk.

If you own a Coldcard, skip straight to the checklist below — the analysis can wait.

If you hold a Coldcard, do this now

What actually broke

A 12-word BIP-39 seed is supposed to carry 128 bits of entropy — a number so large that guessing it is not a thing that happens. The reported flaw is that affected devices did not reseed their randomness securely: instead of using the hardware random number generator, the firmware fell back to software-based generation drawn from non-secret chip data — a predictable counter incorporating things like the device serial number and internal clock, according to Block's analysis.

Collapse the search space far enough and the attack stops being cryptography and becomes enumeration. Someone generates candidate seeds, derives the addresses, checks which ones hold coins, and then — at a moment of their choosing — signs 500 transactions at once. That's why the sweep took 25 minutes rather than months: the hard work happened offline, in advance, and the on-chain part was just harvesting.

Which is exactly why the popular framing on X today — "even cold wallets aren't safe" — gets the lesson backwards. Nothing about the air gap failed. No malware touched these devices; no seed was exfiltrated; the offline model did its job. The keys were guessable from the moment they were born, and an air gap cannot protect a secret that was never secret enough. Cold storage defends against key exfiltration. It has never defended against key predictability. Those are different threats and this one hit the second.

The defences that worked

Notice what protected people, because it's an unusually clean natural experiment. A BIP-39 passphrase worked, because it adds a secret the device never generated. Dice rolls worked, because they inject entropy from a source that has nothing to do with the firmware. Multisig with keys from different manufacturers worked, because a flaw in one vendor's RNG doesn't compromise a quorum. Every effective defence here has the same shape: don't let one implementation be the sole source of your randomness or your authority. That's the durable takeaway, and it applies to whatever hardware you own — this was Coinkite's bug, but weak-entropy bugs have hit many products over the years, and they will again.

Credit where it's due, too: Coinkite disclosed publicly and prominently, on its own firmware download page, within hours — not in a buried changelog. Compare that to the alternative, which is a vendor quietly patching and hoping. It doesn't undo anyone's loss, and the flaw sat in shipping firmware for years, which is its own serious failure. But the disclosure behaviour is the part other vendors should copy.

Three days, three layers

On Tuesday we wrote that self-custody's failure mode is software — the counterfeit-wallet lawsuit. This week two exchanges, BitMEX and BitMart, scheduled their own shutdowns. Today the hardware itself. It would be easy to read that sequence as "nothing is safe." The more useful reading is that every layer has a failure mode, and they differ in one crucial property: whether you can do anything about it.

When an exchange fails, you are a creditor. No amount of diligence on your part changes the outcome — you found out when the withdrawal button went grey. Today's flaw is brutal, and it cost people real money, but it is detectable and recoverable: there is a published affected range, a checklist, and a migration path, and the great majority of Coldcard holders will read the advisory and rotate without losing anything. One category of risk yields to attention. The other doesn't yield to anything. That asymmetry is still the whole argument for holding your own keys — stated honestly, including on the days when holding your own keys is what hurt.

For what it's worth on our side of it: TokensFund never holds your funds or touches your keys — swaps route from your wallet through THORChain, Chainflip, NEAR Intents, Changee or CCE.Cash to an address you control, no account, no KYC for standard swaps. That architecture removes a custodian from the picture. It cannot generate entropy for you, verify your firmware, or undo a predictable seed. Nothing can. Rotate first, swap later.

A note on risk

Nothing here is financial or security advice, and this is a developing story: figures and technical details reflect reporting and Coinkite's advisory as of July 31, 2026, and the company has said a formal technical review is still to come. Coinkite has not confirmed a definitive link between the sweep and the seed-generation flaw; researchers consider weak entropy the likely cause. Block researchers have also flagged an earlier set of transactions totalling roughly 488 BTC that may share the same fingerprint, which would raise the total materially — treat that as preliminary. Follow Coinkite's own advisory as the authoritative source for what to do with your device, verify everything twice, and be extremely suspicious of anyone who contacts you first about your funds.

Rotate first. Swap later.

Swap wallet-to-wallet →