Coldcard Entropy Flaw Drains $100M in Bitcoin Theft
Coinkite confirmed on 31 July 2026 that a coding flaw let hackers drain hardware wallets. Attackers moved out more than 1,596 Bitcoin, over $100 million (USD), from Coldcard devices. Anyone holding crypto on a hardware wallet should understand how this happened before trusting the next one.
What actually happened
Coinkite, maker of Coldcard, disclosed the entropy bug on 31 July 2026, as detailed by bonuz.xyz. Galaxy Digital researchers traced coordinated thefts of over 1,596 Bitcoin, worth at least $100 million (USD), to the flaw. Coinkite pushed firmware patches and urged owners to shift funds into freshly generated wallets. Core Lightning developer Dustin Dettmer points to a 2021 firmware change that switched off the hardware random number generator, leaving MicroPython's weaker Yasmarang generator to fill the gap. A Coinkite spokesperson told Cointelegraph that some firmware versions carried a fallback path capable of producing weak entropy on-device, without confirming Dettmer's full account. Wallets seeded manually, through dice rolls, escaped the bug entirely.
How we got here
A wallet's private key starts as a seed built from random data, called entropy. Weaker entropy shrinks the pool of possible keys, letting attackers rebuild them. Foundation chief executive Zach Herbert says this particular flaw sat hidden for more than five years. It is not an isolated case. Bitcoin researcher Jameson Lopp has flagged similar entropy failures before, in Blockchain.com's Android app and in Trust Wallet. Ledger, Trezor and Foundation each build entropy differently, some through certified chips, others by blending several random sources, yet none can promise a single failure point is impossible.
Why this matters for you
Coldcard owners on affected firmware should move funds now, following Coinkite's guidance, rather than wait. The wider hardware wallet market faces pressure to prove its randomness works, an idea Kraken security chief Nick Percoco has floated as a formal standard. Wallet makers may need to open firmware to outside audits, the route Foundation already takes. For bonuz.market readers, the episode is a reminder that seed-based hardware wallets put enormous trust in one generation event. MPC wallets, bonuz included, split private keys across a network and let people sign in with social login, skipping seed phrases altogether.
The bigger question
If a random-number flaw can hide inside purpose-built hardware for five years, how much testing is actually enough before anyone trusts a wallet with real money? Should regulators or independent labs certify every firmware release, or is the burden on users to understand the mechanics themselves? Coldcard's breach raises the question loudly. It offers no answer.
What to watch
Coinkite has promised a full technical postmortem, without a confirmed release date. Coldcard owners on vulnerable firmware should watch directly for Coinkite's migration steps. Percoco's proposed entropy and firmware certification standard remains informal for now. Expect closer scrutiny of Ledger, Trezor and Foundation's random-number practices in coming months.






