The safe had been open for five years, nobody had noticed
A little over 1,000 bitcoins, or around $70 million, left hardware wallets that had never been connected to the internet. The thief did not touch any device. He did not enter anyone's home. He did not send any malicious message. He simply guessed the keys. They had been guessable since March 2021.
This is the scenario that the bitcoin community had been presenting as impossible for ten years. The so-called “cold” wallet, that device which keeps your keys offline in a drawer, was supposed to be the last line of defense. It has just fallen without anyone touching it.
What happened, in order
During the night of July 30 to 31, 2026, someone emptied around 500 bitcoin wallets in less than an hour. In total, 594.5 bitcoins, or roughly $38 million, were moved in rapid succession across a few blocks of the chain. Many of these wallets had been dormant for years, without the slightest movement.
Analysts then dug through the history. Clay Garrett, a security engineer at Block, found 695 older transactions with exactly the same signature. They represented an additional 488 bitcoins. In all likelihood, the same perpetrator had already struck without anyone noticing.
The most discreet theft is the one at the top. Nobody had spotted it. It is probably the more worrying of the two.
As of August 1, the recorded total reaches 1,082.65 bitcoins. Researchers warn that this figure remains provisional. The largest part of the haul, 562 bitcoins, was gathered on a single address. It has not moved since. Everyone can see it, permanently, but nobody can touch it. This is one of the ironies of this story.
Update of August 31: the count is complete, and it has almost doubled
One month later, we know the real scale. The analysis firm TRM Labs, which tracks movements on the chain, arrives at 1,816 stolen bitcoins, or around $116 million, spread across more than 5,200 addresses. The total of 1,082 bitcoins announced above on August 1 therefore did not even represent two-thirds of the haul.
Something else we did not know at the time: it did not happen in a single night. There were four waves spread over four days. The one on July 30, the only one spotted at the time, was the first.
Public counts range from $88 million to $130 million depending on the sources, because each one stops at a different wave and converts using a different price. The exact figure does not matter: it is the biggest theft of the year targeting hardware wallets, and the third-biggest crypto theft of 2026 across all types combined.
The bug comes down to one poorly chosen word
Here is how one line of code can make $70 million disappear.
A hardware wallet creates your 24 secret words from pure randomness. To do this, it uses a dedicated chip that produces randomness from physical phenomena. This is what is called a hardware generator. This component is essential. It is also the one the software never called.
In March 2021, Coinkite, the manufacturer of the Coldcard, migrated its code to the Bitcoin Core cryptographic library. During this operation, the function responsible for producing randomness changed its name. The developers had planned to disable the software fallback generator by setting its value to zero.
But the test written in the code did not ask “does this setting equal zero”. It asked “does this setting exist”. The setting did exist, even with the value zero. The test therefore passed. The compiler quietly connected the fallback generator instead of the real one, without producing the slightest alert.
It is the difference between asking someone whether they have a driver's license and asking them to show it. The chip's code was indeed present in the device. It simply was never executed.
The result, plainly
On the left, the lock you were sold. On the right, the one that was actually protecting your savings.
A 24-word secret phrase must provide 128 bits of randomness. That represents a 39-digit number of combinations. Even with all the computers on the planet for the age of the universe, nobody can try them all.
On the affected Coldcard Mk3 devices, only about 40 bits remained. On more recent models, about 72 remained. Forty bits represent a trillion possibilities. The number looks enormous. For an ordinary machine, though, that only represents a few hours of work and the price of a pizza in electricity. The backup generator did not really produce randomness. It started from the chip's internal state and its clock, two values the attacker could recalculate.
The safe was not forced. The lock only had three digits, and the attacker counted them.
The three numbers are written out in full, it is more striking than a power of two. Between the first line and the last, the gap is such that no image can represent it to scale.
What the viral thread gets wrong
The message that has been circulating everywhere since last night contains real information, but also at least three errors. It is passing through the messaging apps of people who have money at stake. We might as well correct the damage before the summary becomes more dangerous than the bug.
- “The Mk4, Mk5 and Q are safe.” This is false, and it is the most serious error. These models are affected too. They resist better because they mixed in randomness from their secure chip. According to Coinkite, this raises the level to about 72 bits. The attack remains possible. Taking into account the values the attacker could guess, Galaxy Research estimates that around four billion combinations remained to try. Coinkite published corrected firmware for all models, not just the Mk3.
- “Your words came from the rhythm of your button presses.” The explanation is a nice one, but it is not the one in the official analysis. The generator used the device's state and the time, including the clock registers and the chip's serial number. None of these values is secret. That is more than enough to cause the disaster.
- “With a passphrase you are safe.” This is half true. Coinkite explains that a strong and unique passphrase adds independent protection. That is correct, but the manufacturer still recommends migrating. A weak passphrase no longer protects against anything since the seed is now public.
One point is completely correct: dice rolls protect you. Coinkite confirms that 50 to 98 private rolls provided at least 128 bits on their own, and that 99 rolls or more provided about 256. If you spent an evening rolling a die to create your seed, you can breathe easy. The other brands, Ledger and Trezor, are not affected. Their devices and their code are different.
Are you affected, and what should you do?
The rule is simple and brutal. What matters is not the model you own today. It is the software version used on the day you created your seed.
- Mk3: versions 4.0.1 to 4.1.9 affected. Fixed in 4.2.0.
- Mk4 and Mk5: affected before version 5.6.0, or 6.6.0X on the Edge branch.
- Q: affected before version 1.5.0Q, or 6.6.0QX on the Edge branch.
Here is the hardest piece of information, the one you need to understand before touching anything: updating the firmware does not repair a seed that has already been created. The firmware is the device's internal software. Updating it fixes the creation of future keys. Yours were made only once, sometimes years ago, with the wrong die. They will remain guessable forever.
The procedure published by Coinkite has six steps. You need to update the device, create a new seed, write down the backup and verify it, check a receiving address on the device's screen, send a small test transaction, then move the rest. You need to keep the old backup until everything has been transferred.
One last point, urgent too: fake support accounts are swarming through private messages. No serious manufacturer will ever ask you for your 24 words. None will send you a link to “secure” your wallet either. Those who did not lose their bitcoins last night risk losing them this week, through a much more ordinary scam.
Open source has not kept its promise, and we need to say so
The Coldcard's code is public. It always has been. The industry's slogan, “don't trust, verify,” has been repeated like a prayer for ten years. The bug remained visible for five years. It took a thief exploiting it for someone to notice.
That is the real lesson of this affair. Open code is not necessarily reviewed code. “Thousands of eyes” is a figure of speech, not an audit. And nobody, let's be honest, gets up on Sunday morning with an urgent desire to review the compilation options of firmware.
One last tasty detail, at least for those who haven't lost anything: Coinkite thinks someone used artificial intelligence to comb through its old firmware versions. The company says it had itself run “one of the best models available” over its code a few weeks earlier, without finding anything. The security community greeted this explanation with one eyebrow raised. The idea remains chilling: machines can patiently reread twenty years of open-source code to find the line nobody looked at.
So, is keeping your bitcoins in a bank safer?
That's the question everyone has been asking since yesterday. It deserves better than a fanboy's answer.
There is no perfect answer. There are two different ways to lose everything. The choice is deciding which one scares you less.
When you buy bitcoin in a bank or broker's app, you do not hold your keys. The company keeps them for you. You own a line in its ledger and a promise. In jargon, this is called counterparty risk. If the company goes under, disappears or gets emptied out, you become a creditor waiting for your turn. Those who had left their coins with FTX or Celsius did not lose their keys. They lost their counterparty.
In Europe, the situation has changed. It is no longer the Wild West. Since July 1, 2026, the end of the transition period for the European regulation on crypto-assets requires providers to have a licence. Above all, it requires them to strictly separate customers' assets from the company's assets. That is precisely what was missing during the bankruptcies of 2022. This does not make bankruptcy impossible. It makes the boss looting the vault much more difficult.
But there is still a trap that many people are unaware of: these crypto-assets are not bank deposits. The European guarantee of €100,000, which protects the money in your current account, does not apply to them. Seeing a “bitcoin” line in the same app as your salary gives you an impression of protection. That protection does not exist.
What this means for a normal family
Here's how I would present the choice to someone who doesn't feel like spending their evenings on it.
If you invest 500 or 2,000 euros to try it out, your bank's app or that of a regulated broker is very probably the right choice. Not because it is safer in absolute terms. But the overwhelming majority of losses among individuals come from lost backups, words written on a misplaced piece of paper, moves or deaths without anyone passing the information on. Exotic cryptographic bugs come a long way behind. A forgotten password can be recovered. A lost seed can never be recovered.
If you hold an amount that would change your life, the right answer is neither one nor the other. You must not put everything in the same place. This week, those who had spread their assets between two wallet brands and a regulated account lost a third of something. Those who had put everything in the same device lost everything. It is the most boring advice in the world. It is also the only one that has worked during every catastrophe over the past fifteen years.
If you insist on keeping your own keys, which remains a perfectly defensible choice, the lesson is concrete: add your own randomness. In this case, the dice were the only effective protection. Fifty rolls, one evening, and you no longer depend on someone else's generator.
And if you don't have a satoshi, does it concern you anyway?
Yes. And not in ten years, today, in your living room.
That little padlock closed in your browser's address bar, when you pay for your groceries online? It relies on a random draw made by your phone or PC when the page opens. The password for your internet router when it is delivered? Drawn at the factory. The code your bank sends you by message? Drawn at random. Your bank card itself contains a small source of randomness. Everything that protects you online starts with the same question as in this story: is the number drawn at the start really unpredictable?
Nothing in this room works without a good random draw. It is probably the most important component that nobody ever talks about.
And this isn't the first time it has broken. In 2006, a developer at Debian, one of the major Linux distributions, removed a line from encryption software because an analysis tool was complaining about it. For almost two years, all the keys generated on these machines could only take 32,768 values. Thirty-two thousand! We discovered it in May 2008, and the keys for half the servers on the planet had to be regenerated. Twenty years later, we find exactly the same story again, in a device whose sole and only job that is.
There is still something I find reassuring in all this, and I say it because nobody points it out: this time, we were able to count everything. The 5,200 addresses, the 1,816 bitcoins, the time of each wave. A vulnerability of this size in a conventional banking system, you find out about it in a three-line statement six months later, if you ever find out. Here, anyone can go and check for themselves. It doesn't get the money back, but it prevents the lie.
What I think about it
What stays with me isn't the $70 million. It's a message from a man on a forum. In a few lines, he explains that eight years of savings have disappeared. He is 39, had hoped to build up a nest egg before 50 and no longer knows whether he still believes in all this. He adds that he had chosen this device precisely because its code was open and verifiable by anyone. He had done his homework. It's this detail that makes this story so painful.
Bitcoin's promise was not to depend on anyone. This week, we discovered that everyone depended on a compilation option written one day in March 2021. Someone had written “exists” instead of “has a value”. There is no customer service to fix that, no guarantee fund, no recourse. The transaction is valid, final and visible to everyone, forever.
This is not the end of the hardware wallet. Those who announce it are generally selling something else. It's the end of a naivety: believing that an object is safe because its code is public and someone else, surely, must have checked it.





Join the conversation
You need an account to comment on this article. Creating one is free and takes under a minute.
No comments yet.