Pudoo
BTC $64,967.2 +0.95%
ETH $1,916.43 +0.58%
SOL $74.77 +2.48%
BNB $594.5 +1.24%
XRP $1.04 +0.69%
DOGE $0.0703 +1.41%
ADA $0.2000 -1.38%
AVAX $6.52 +1.43%
DOT $0.8185 +0.13%
LINK $8.26 +0.82%
⛽ ETH Gas 28 Gwei
Fear&Greed
30

Coldcard's Broken Entropy: Alex Thorn Watches a $100 Million Fourth Wave Roll Through Self-Custody

Learn | CryptoLion |
We didn't see it coming. Not really. The first three waves were easy to dismiss as isolated hacks, unlucky seeds, maybe an old Android wallet's ghost. Then the fourth wave hit on August 3, and the narrative cracked open. A wallet that had quietly held Bitcoin for years suddenly woke up and pushed hundreds of coins through the network at a speed roughly 45 times faster than normal on-chain activity. Alex Thorn, Galaxy Digital's head of research, had been mapping the earlier waves. Now he had a name for the pattern: a coordinated, methodical sweep of addresses connected to Coldcard hardware wallets. This isn't a phishing attack. It isn't a cleverly planted malware. It's an entropy failure — a broken random number generator in a Coldcard firmware update from March 17, 2021. The same update that was supposed to add an in-house RNG accidentally wired it wrong. Key generation silently failed, the device fell back to a weak entropy source, and for the next three years, users kept generating seeds that looked safe but were actually sitting in a narrow, predictable mathematical space. The result: more than $100 million in Bitcoin stolen. Thousands of addresses drained. And the people affected were not novices. They were the most disciplined self-custodians in the ecosystem. — Root: The entropy source on that firmware was wired wrong. Everything else is just the aftermath. Coldcard is not a product for tourists. It's the hardware wallet of choice for Bitcoiners who treat keys like nuclear launch codes. Open source firmware. Air-gapped signing. A display with a physical number pad that feels like a bomb diffuser. The company behind it, Coinkite, has spent years cultivating a reputation as the "security maximalist" option in a market dominated by Ledger's sleek mainstream branding and Trezor's early-mover status. Coldcard users are the people who say "not your keys, not your coins" at breakfast. They are the ones who bought a hardware wallet because they refused to trust exchanges. They are also, according to Thorn, almost painfully careful. The Bitcoin taken from the known victim addresses had been sitting untouched for an average of nearly four years. That's not a hot wallet. That's not a gambler's stash. That's a retirement box in the basement of a security-obsessed holder. This is the cruelest part of the story: the victims did everything right. They stored the seeds properly. They kept the device offline. They checked the packaging for tampering. They read the QR codes through a magnifying glass. And none of that mattered, because the entropic heart of the device was broken from the moment that firmware flashed. Thorn's Demo arrives via the Bits + Bips podcast and a thread that reads like a detective's notebook. He doesn't just estimate from headlines. He shows the transactions. He shows the wallet ages. He shows the timing clusters. And he warns that the confirmed losses are likely only the tip of a much larger attack surface. Every hardware wallet depends on a simple question: where does the randomness come from? A Bitcoin private key is just a number. Any number in a staggeringly vast range. The security of that number depends entirely on its unguessability. If a device uses a strong random number generator, the key space is so large that brute force is meaningless. If the device uses a weak generator, the key space shrinks to a size that a motivated attacker with enough computing power can search. The March 17, 2021 firmware update introduced Coinkite's own random number generator. The goal was probably to reduce reliance on third-party components and strengthen the supply chain. But during manufacturing and integration, something went wrong. The "wiring" was wrong. The code path that was supposed to read truly random entropy from the hardware became misconfigured. Instead of failing loudly and refusing to generate a seed, the device failed silently. It fell back to a weak source. The user saw a perfectly normal 24-word seed phrase appear on the screen. In reality, that phrase was one of a tiny subset of possible phrases. The generation process looked correct. The cryptography didn't. This is the nightmare scenario for any security product. A loud failure would have triggered a patch and a warning. A silent failure gives the attacker an invisible advantage. Users kept depositing Bitcoin into addresses whose private keys were not as random as they seemed. And the attacker — whoever they are — eventually figured it out. Thorn's first three waves covered thousands of addresses. The confirmed figures are staggering: around 1,367 Bitcoin stolen, roughly $100 million at today's prices, across about 4,585 addresses. Wait, he says, there's more. Add the suspected fourth wave, and the address count jumps to roughly 5,294. The August 3 wave moved hundreds of coins in a burst of on-chain activity that was about 45 times faster than normal. The attacker wasn't being quiet anymore. They were sweeping. Let's pause on Thorn's quote: "These people didn't do anything wrong. In fact, they did everything right." That's the gut punch. The victims are the model citizens of Bitcoin self-custody. They are not the people who kept funds on a hot exchange and got hacked. They are not the people who screenshotted their seed phrase into iCloud. They are the people who bought the most respected hardware wallet, generated seeds under carefully controlled conditions, and held for years. Those addresses are not speculative traders. The average Bitcoin in the known victim addresses had been unmoved for nearly four years. That kills another comfortable narrative: "It was probably someone who reused a seed or downloaded malware." No. The dormancy lines up perfectly with the 2021 firmware window. The weak keys were created after the bad update. Then they sat silent. Then the attacker started matching the addresses and reproducing the private keys offline. This is what makes the incident an "unprecedented attack against distributed self-custody," as Thorn puts it. It's not an attack on a vault. It's an attack on the concept of the vault. The whole promise of a hardware wallet is that the private key never leaves the device. With this bug, that promise collapsed. The attacker could reproduce the key outside the device. The device was a hollow fortress. Coinkite has now issued a fixed firmware. CEO Rodolfo Novak posted an apology on X, saying the company is "heartbroken" and taking "full responsibility." That sounds good. It is good, as far as corporate messaging goes. But the technical reality is brutal: the new firmware cannot protect the seeds that were generated under the broken firmware. An attacker could already have reproduced those seeds offline. Loading them into a patched device won't make them safe. The only safe choice is to generate a brand-new wallet with new firmware, on a clean device, and move the Bitcoin. That's not a patch. That's an evacuation order. Thorn is blunt: anyone holding Bitcoin on a single-signature Coldcard address should move the coins "as soon as possible." Not tomorrow. Not after the next firmware release. Now. Because the same weak-key space that produced the first three waves is still being probed. The fourth wave proves the attacker hasn't stopped. One small detail in Thorn's analysis caught my eye because it reveals how the attacker operates: some of the theft transactions used replace-by-fee, or RBF. RBF is a Bitcoin mempool feature that lets a sender replace an unconfirmed transaction with a higher-fee version. It's normally used to speed up stuck transactions. Here, the attacker used it as a tool to improvise. But there's a flip side. If you catch one of your own transactions in the mempool before it confirms, you can use RBF to outbid the thief by sending the same coins to a wallet you control with a higher fee. That's a narrow window, and it won't save most victims. But it shows that even in the middle of an entropy disaster, there are tactical maneuvers. It also reveals something else: the attacker is not a flawless automated machine. They are human enough to need flexibility. Everyone wants to ask: "Which hardware wallet should I buy now?" That's the wrong question. The real question is: "Why did a product that costs more, markets itself with paranoia, and carries an open-source reputation ship a firmware update with a broken RNG for years?" The uncomfortable answer is that the hardware wallet industry has been selling a story as much as a security guarantee. Coldcard means zero compromise. The company's entire brand is built on being the safest option for the most paranoid user. And yet, by Thorn's accounting, a single mis-wired entropy source produced a theft wave that dwarfs most exchange incidents. The brand was not enough. Open-source software was not enough. The user's own discipline was not enough. In my years of auditing blockchain systems, I've learned that the most dangerous bugs are not the ones you find in a code review. They're the ones that slip through because nobody thought to challenge the underlying security assumption. Here, the underlying assumption was: "Coinkite knows how to implement a hardware RNG." The evidence says otherwise. This should trigger a reckoning across the entire self-custody stack. It's not enough to open-source the firmware. You need independent third-party audits that specifically test the randomness source and the key-generation path, not just scan for buffer overflows and reentrancy. This event also puts a spotlight on the absurdity of the word "trustless." Self-custody was supposed to eliminate the need for trust. You don't trust a bank. You don't trust an exchange. You trust a metal box on your desk. But that metal box contains a microcontroller, a hardware entropy source, a firmware boot process, and a manufacturer that can ship updates. If any of those links fails, the trust is broken. Self-custody never meant zero trust. It meant replacing one set of trusted parties with another set that you pretend not to trust. The party doesn't stop when the exploit is disclosed. It stops when the last weak key is swept. And there are almost certainly more weak keys lurking in backup boxes and safety-deposit vaults. Thorn mentioned that he has identified 14 other recognizable attack patterns that are separate from the main waves but still have verifiable victims. Think about that. Four waves. More than $100 million. And now fourteen other patterns held in a researcher's dossier, not yet fully added to the public count. This changes the scale of the story. It's no longer just a Coldcard bug. It's an entropy apocalypse with multiple signatures. Some of those patterns might involve other devices, older firmware revisions, or even different wallet software that reused the same weak RNG component. If that's true, the number of affected addresses could be significantly larger. The 5,294 addresses are just the ones Thorn can pull together with confidence. This is also a reminder that our industry's habit of celebrating self-custody as an absolute good has a blind spot. Yes, self-custody protects you from exchange counter-party risk. But it transfers that risk to your pocket electronics. Every hardware wallet is a tiny hardware security module. It needs the same rigor as a bank-grade HSM: independent evaluation, tamper response, randomness testing, and continuous post-market monitoring. Very few hardware wallets actually meet that standard, no matter how cool the user interface looks. Now let's talk about the market fallout, because this is not just a forensic problem. It's a trust-premium collapse. Hardware wallets are commodities, but their price has always been inflated by an emotional premium: the promise of absolute safety. Coldcard charges more than a generic USB stick because it sells a feeling of invincibility. This event zeroes out that premium for an entire product category. If a Coldcard can be drained by a weak RNG, what is the hardware wallet actually worth? Maybe the encrypted metal seed plate. Maybe the chip. Maybe nothing at all. The economic ripple will be felt by every player. Ledger, Trezor, BitBox, Keystone — they all depend on the same narrative: hardware wallets are safer than exchanges and safer than software wallets. That narrative just took a direct hit. Some users will conclude that any self-custody hardware is too dangerous and move Bitcoin back to regulated custody. Others will go deeper into multi-signature setups, where no single device failure can drain the funds. The winners in the short term are likely to be multisig platforms and professional custody services. The losers are the hardware wallet makers who don't radically expand their security audits and disclosure transparency. And there is a deeper market irony here. For years, the crypto industry told retail users to take self-custody seriously. "Not your keys, not your coins" became a mantra. Exchanges were the villains. Hardware wallets were the answer. Now the answer has a $100 million hole in it. This is not a Bitcoin protocol failure — the chain worked exactly as designed. But the psychological damage falls on Bitcoin anyway. Every time a mainstream reader sees the headline "Bitcoin theft via Coldcard," they don't think "bad firmware." They think "Bitcoin is unsafe." That perception lag is a real cost, and it will show up in the slow-moving decisions of institutional allocators and first-time buyers. We should also talk about regulation. Not the SEC's token classification nonsense — this is pure product liability. Coinkite is a Canadian company. Its customers are scattered around the world, including the United States. If a manufacturer ships a product with a defect that causes financial loss, the legal system has a name for it: product liability. The CEO's apology is a good first step, but it won't stop class-action lawyers. The likely lawsuits won't be about whether Bitcoin is a security. They will be about whether Coinkite exercised reasonable care in developing and auditing the firmware that shipped with its $100+ device. Thorn's advice to victims is also a regulatory signal. He told them to file reports with the FBI's IC3 and local law enforcement, and to keep the compromised devices as evidence. That's not casual advice. It's the language of a crime scene. It means law enforcement is already aware, and it means future disclosures may be coordinated with ongoing investigations. If the FBI gets involved, Coinkite's internal decision-making around that 2021 firmware update will be examined under a microscope. Did they test the RNG against known randomness test suites? Did they have an independent auditor review the key-generation path? Did they receive any warning signs and ignore them? Those questions will determine whether this remains a civil matter or becomes something more serious. The regulatory angle also reaches the wider hardware wallet industry. Expect to hear more calls for mandatory security standards. In the same way consumer electronics need safety certifications for batteries and electrical wiring, hardware wallets need certifications for entropy sources and firmware integrity. If the industry doesn't self-regulate, regulators will do it for them. And the cost of that regulation — audit fees, compliance teams, certification delays — will be passed on to users. Ironically, the people who bought the most expensive and most paranoid hardware wallet may end up paying an even higher price for the next generation of safety theater. There's also a performance angle that barely anyone is talking about. The vulnerable firmware was not the only thing that failed. Coinkite's incident response timeline failed too. The bug was introduced in March 2021. The theft waves were apparently discovered by an outside researcher, not by the company's own monitoring. For three years, nobody inside the company noticed that a subset of its devices were generating keys from a dangerously small entropy pool. That's not just a coding bug. That's a quality assurance failure. It suggests that Coinkite did not have continuous monitoring for the statistical properties of the keys its devices generate. A strong random number generator should produce keys with a flat distribution. A weak one leaves fingerprints. Those fingerprints were present for years before Thorn catalogued them. I’ve spent enough time looking at on-chain data to know how easy it is to miss a pattern like this. Transactions from old dormancy addresses don't pull at your attention. There are millions of old addresses, and most of them are simply dead. It took someone with Thorn's specific expertise, and maybe a lucky break, to connect the dots. That's a reminder that the blockchain is not automatically secure just because everything is public. It takes active, adversarial thinking to turn transparent data into a warning system. What happens next depends on how many people take that warning seriously. Let me be practical. If you are a Coldcard user, here is what you need to do, in order. First, stop using any seed that was generated during the vulnerable firmware window. Second, update your device to the latest firmware, but do not assume that update makes your old seed safe. Third, generate a completely new wallet on the new firmware, or better yet, on a different device entirely. Fourth, move your Bitcoin in small test amounts first, then transfer the full balance. Fifth, if you find that your old address has already been drained, preserve the device and the transaction records. You may need them for the authorities. And if you don't think you are affected because you used a Coldcard after the fix, remember that the fix only prevents new weak keys from being created. The old weak keys are already weak. An attacker can run the numbers offline, quietly, at their own pace. The fourth wave may not be the last. Thorn's "14 other attack patterns" could easily become the next headline, and the next wave could be bigger than anything we've seen so far. The deeper lesson is about complexity. Bitcoin itself is elegantly simple, but the ecosystem around it has become staggeringly complex. Hardware wallets have bootloaders, secure elements, QR modes, USB stacks, and random number generators. Every one of those components is a potential failure point. Self-custody enthusiasts like to pretend that a hardware wallet is a single magical object. It's not. It's a miniature computer, and it has all the vulnerabilities of a computer. This is why the industry's obsession with "simple" self-custody is so dangerous. A single hardware wallet with a single signature is a single point of failure. The fact that it's offline doesn't matter if the key is mathematically weak. The correct response to this event is not to throw away all hardware wallets. It's to add redundancy. Use a multisig setup with two or three different manufacturers. Store keys in geographically separate locations. Add a passphrase that lives only in your head. Diversify your custody assumptions so that no single firmware update can bring down your entire stack. The other response is to demand better audits. Not just the kind of superficial security review that checks for TV-sized bugs and then slaps a badge on a website. Real audits. Independent labs that physically de-package the hardware, photograph the silicon, and test the entropy source with millions of generated keys. If a hardware wallet can't survive that kind of scrutiny, it shouldn't carry the label "secure." This event is a gift to the auditing industry, and it's a warning to every wallet manufacturer that treats the RNG as an afterthought. Coinkite's brand will probably survive in some form. The Bitcoin community is merciful to companies that communicate honestly and quickly. Novak's apology was the right move. But the damage to the category is permanent. We will no longer be able to say, with a straight face, that a hardware wallet is the end of the security conversation. It is only the beginning. Let's also be honest about the victims. They are not just random addresses. They are the people who believed in the ideology of self-custody. They took personal responsibility for their wealth. They rejected the convenience of exchanges in favor of a more difficult but more principled path. And the system that was supposed to reward that principle failed them. The psychological impact is going to be severe. Some will quietly move their next Bitcoin into an exchange wallet. Others will abandon the idea of going all-in on crypto. A few will become the loudest advocates for multisig and open-source security research. That emotional dimension is why this story will not fade quickly. The numbers are bad, but the human narrative is worse. We're not talking about anonymous speculators who gambled on a meme coin. We're talking about long-term HODLers who treated their cold storage like a treasure chest. They had the right beliefs. They used the right tools. And still, the coins left. The final wave may already be forming. Thorn is sitting on a cache of information about 14 other attack patterns. His research has the potential to turn this from a Coldcard scandal into a larger audit of the entire self-custody toolchain. If those patterns implicate other hardware wallets, the story will become systemic. If they are all Coldcard-related, Coinkite will face years of litigation and a gutted trust foundation. Either way, the next few months will be brutal. So here is where I land. Don't panic, but do act. If you have Bitcoin on a single-signature Coldcard address generated between March 2021 and Coinkite's fix, move it now. Don't wait for someone else to tell you you're affected. You either are or you aren't, and the cost of being wrong is too high. Use a fresh wallet. Use multisig. Use a different manufacturer. Just don't use an old seed that was born in a broken entropy pool. We didn't see it coming the first time. That's excusable. We won't see it coming the fifth time if we refuse to learn from the fourth. The chain is still the most beautiful ledger in the world. But cold storage isn't a product. It's a process. And when a process depends on a single source of randomness, it's not cold enough. This time, the price of cold was $100 million and counting. The next price might be the faith of everyone who still believes that a metal box can keep their dreams safe. The party doesn't stop when the exploit is disclosed. It stops when the last weak key is swept. Make sure your key isn't on the list.

Market Prices

BTC Bitcoin
$64,967.2 +0.95%
ETH Ethereum
$1,916.43 +0.58%
SOL Solana
$74.77 +2.48%
BNB BNB Chain
$594.5 +1.24%
XRP XRP Ledger
$1.04 +0.69%
DOGE Dogecoin
$0.0703 +1.41%
ADA Cardano
$0.2000 -1.38%
AVAX Avalanche
$6.52 +1.43%
DOT Polkadot
$0.8185 +0.13%
LINK Chainlink
$8.26 +0.82%

Fear & Greed

30

Fear

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$64,967.2
1
Ethereum
ETH
$1,916.43
1
Solana
SOL
$74.77
1
BNB Chain
BNB
$594.5
1
XRP Ledger
XRP
$1.04
1
Dogecoin
DOGE
$0.0703
1
Cardano
ADA
$0.2000
1
Avalanche
AVAX
$6.52
1
Polkadot
DOT
$0.8185
1
Chainlink
LINK
$8.26

🐋 Whale Tracker

🟢
0xf661...4250
12m ago
In
1,910,420 USDT
🟢
0xb405...5cc8
2m ago
In
3,020,473 DOGE
🔵
0xfe87...48a7
3h ago
Stake
2,528 ETH

💡 Smart Money

0xf581...121a
Early Investor
+$0.9M
80%
0x04e9...70c3
Early Investor
+$3.7M
87%
0xd4c9...85d1
Market Maker
+$4.4M
70%