logo
  • Consent
  • Details
  • [#IABV2SETTINGS#]
  • About
This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
[#GPC_BANNER_ICON#]
[#GPC_TOAST_TEXT#]
Consent Selection
Show details
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
    • Pexels
      1
      Learn more about this provideropens in a new window
      _cfuvidThis cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators.
      Maximum Storage Duration: SessionType: HTTP Cookie
    • ambcrypto.com
      benzinga.com
      bitcoinmagazine.com
      coingape.com
      decrypt.co
      image.coinpedia.org
      pexels.com
      7
      __cf_bm [x7]This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • newslayer.com
      1
      CookieConsentStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 1 yearType: HTTP Cookie
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • newslayer.com
      3
      __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cross-domain consent[#BULK_CONSENT_DOMAINS_COUNT#]
[#BULK_CONSENT_TITLE#]
List of domains your consent applies to: [#BULK_CONSENT_DOMAINS#]
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
LatestDaily BriefMarkets
NewsLayer PulseLIVE₿BTC$64,304+0.20%ΞETH$1,911+0.93%◎SOL$76.89+1.61%✕XRP$1+0.57%ÐDOGE$0.07+0.34%₳ADA$0.1749+1.14%Total Cap$2.30T+0.32%24H Vol$386.5BLayer Index44 Neutral
Crypto·DeFi
BreakingExternal ReportingVeröffentlicht vor 28 Minuten

Coldcard Vulnerability: 1,367 Bitcoin Stolen Due to Predictable Private Keys - News and Statistics

Coldcard, a hardware wallet built for dedicated Bitcoin users, supports only Bitcoin, operates offline, relies on open-source code, and is put together in Canada. However, starting in March 2021, certain Coldcard units produced private…

Coldcard Vulnerability: 1,367 Bitcoin Stolen Due to Predictable Private Keys - News and Statistics
Publisher IndexBox 5 Min. Lesezeit
NewsLayer editorial artwork
Übersetzung…

Market Context

₿

Bitcoin

BTC

$64,304

+0.20% 24h

Layer Index

44

Neutral

Layer Index

↓ 1 pts in 24h

Aug 19, 2026

Coldcard Security Flaw: How a Hardware Wallet's Randomness Failure Led to a Massive Bitcoin Theft

Coldcard, a hardware wallet built for dedicated Bitcoin users, supports only Bitcoin, operates offline, relies on open-source code, and is put together in Canada. However, starting in March 2021, certain Coldcard units produced private keys for customers by relying on the device's serial number and its internal clock, instead of the specialized chip meant for generating random numbers. This made those keys considerably simpler to anticipate.

On July 30, a hacker took 594 Bitcoin from roughly 500 dormant wallets within a 25-minute window. Galaxy Research has connected the broader theft to 1,082 Bitcoin spread across 1,196 addresses. By August 2, the figure had climbed to nearly 1,367 Bitcoin, valued at around $88.6 million.

The attacker required no physical access to the wallets. Coldcard's source code is openly accessible, as is data on the Bitcoin blockchain. The attacker seemingly invested several weeks in figuring out the potential keys that the flawed software might have generated. Those keys could then be matched against Bitcoin addresses containing funds. After pinpointing the exposed wallets, the attacker moved the Bitcoin. The actual theft lasted only 25 minutes.

The flaw is more severe than the term bug might imply. Coldcard is wary of the general-purpose randomness in its underlying software, so it encloses the chip's own hardware generator and disables the built-in one. Yet a safety check in a supporting library failed to notice that the built-in generator was turned off. Seed generation fell back to the software alternative, which pulled whatever randomness it could from the serial number and the clock, never collecting new data afterward. A seed is supposed to hold 128 bits of entropy. On the Mk3, it held roughly 40.

In physical terms, a lock maker advertises a million combinations. A manufacturing flaw means one batch can only ever settle on about a thousand of them. The lock still functions and appears identical to every other lock on the shelf. The owner cannot tell the difference. The thief only needs to know which thousand.

Reach crypto's most engaged readers — advertise mid-article on NewsLayer
Sponsored

Reach crypto's most engaged readers — advertise mid-article on NewsLayer

NewsLayer

Ad

The elliptic-curve math underlying Bitcoin has never been cracked. The randomness that fed it was.

The impact extends beyond the stolen coins. A seed is not a Bitcoin-specific object; it is pure entropy. It can also create addresses and keys for other systems. Anyone who brought a Coldcard seed into a multi-chain wallet was using the same defective dice at a different table.

Coinkite, the Canadian company behind the device, has released its own explanation of the incident. A few weeks before the theft, the firm ran one of the top available AI models over this exact code, searching for security issues. The review found nothing. The company also thinks that is how the attacker discovered the flaw, since the firmware has always been open source. Both sides had the same tool. It worked for only one of them.

This event underscores a key issue with AI-assisted security. A defender asks a model to examine a codebase and needs it to catch every serious vulnerability. An attacker asks it to find one exploitable route and can tolerate any number of failed attempts because only one correct answer is needed. Defense must be right everywhere. Offense must be right once. Inexpensive code review does not reduce that imbalance; it speeds it up.

That brings us to the well-known saying. Not your keys, not your coins. The oldest phrase in Bitcoin. It was directed at exchanges, and last week it worked exactly as stated. The victims held their own keys. So did the attacker. The protocol does not care which one was the true owner.

That is why recovery here is more than just difficult. Bitcoin is a bearer instrument. Anyone who can produce a valid signature can move the coin. The network does not check whether you are entitled to the funds. It only checks whether the signature is valid.

After that, the matter goes to the courts. You must locate the person, in a jurisdiction willing to hear your case, then demonstrate that the wallet was yours and that the transfer was theft rather than authorized. From the blockchain alone, those scenarios can appear identical.

Some years ago, a Bitcoin whale visited the office to learn about the digital asset products we offered. He asked about custody within 90 seconds, then made a show of distrusting every name on the list. Enterprise-grade, ISO-certified, audited, insured—and, to him, irrelevant, because someone else held the keys.

My answer then is the one I would give now. A regulated custodian is the part of the structure that can be held accountable. If client assets are mishandled, there may be insurance, contractual liability, auditors, and regulators to pursue. None of these guarantees recovery, but someone is responsible.

He chose otherwise, as was his right. The problem is that the choice was made by a slogan. Six words settled a question about a very large sum of money that deserved a discussion about failure modes, insurance, and exactly who you would sue.

None of this is an argument for buying the ETF and turning off your brain. Self-custody did not fail here. One vendor's build pipeline failed, and every user who provided his own dice rolls at setup came through unaffected. But the flaw was hidden for five years, and it sat inside the very ritual the practice tells you is safe.

That leaves the uncomfortable part. There is no self-test. You cannot run anything against your own wallet to find out whether your seed fell within the reproducible set, because a compromised seed and a sound one look the same. The only honest approach is to assume you are affected and move the assets to a newly generated, secure wallet.

The lesson is not that self-custody does not work. It is that it shifts responsibility. The key question is not just who holds your keys, but who bears the loss when those keys fail.

Yevgeny Bebnev is an investment professional and multi-manager fund specialist based in Dubai. He is also the founder and CIO of Alaris Capital.

Eilmeldung

Verpassen Sie keine Eilmeldung

Auf X folgen Telegram beitreten

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Related Intelligence

External ReportingColdcard theft: FBI may know 1,082 BTC attackerExternal ReportingBitcoin Falls Amid Low Volatility, Limited Market Liquidity -- Market TalkExternal ReportingU.S. long-term yields shock hits bitcoin, raising liquidity pressure risk
View More
#bitcoin#crypto#defi

Sourced by

Originally reported by IndexBox

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

Market Context

₿

Bitcoin

BTC

$64,304

+0.20% 24h

Layer Index

44

Neutral

Layer Index

↓ 1 pts in 24h

Eilmeldung

Verpassen Sie keine Eilmeldung

Auf X folgen Telegram beitreten

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Related Intelligence

External ReportingColdcard theft: FBI may know 1,082 BTC attackerExternal ReportingBitcoin Falls Amid Low Volatility, Limited Market Liquidity -- Market TalkExternal ReportingU.S. long-term yields shock hits bitcoin, raising liquidity pressure risk
View More

Ähnliche Artikel

How a hidden flaw in Coldcard wallets led to an $88.6m Bitcoin theftWALLET WHODUNIT

How a hidden flaw in Coldcard wallets led to an $88.6m Bitcoin theft

The article examines an alleged hidden flaw in Coldcard wallets that was linked to the theft of $88.6 million worth of Bitcoin. It focuses on how a security weakness in a hardware wallet could contribute to a major crypto theft.

vor 2 Stunden

5 Min. Lesezeit
Why BlackRock Is Still Bullish on Bitcoin After Its 50% Crash
Eilmeldung
MARKET SHOCK

Why BlackRock Is Still Bullish on Bitcoin After Its 50% Crash

Why BlackRock Is Still Bullish on Bitcoin After Its 50% Crash Cryptonews.net

vor 3 Minuten

3 Min. Lesezeit
BlackRock says Bitcoin's 50% drop since 2025 pe...BIG MONEY

BlackRock says Bitcoin's 50% drop since 2025 pe...

BlackRock says Bitcoin's 50% drop since 2025 pe... Pluang

vor 15 Minuten

1 Min. Lesezeit
NewsLayer.com

The front page of the onchain economy. Crypto, Web3 and regulation intelligence — live prices, original research and policy tracking in one layer.

Follow on XTelegram

News

  • Latest News
  • The Daily Brief
  • Crypto
  • DeFi
  • Web3
  • Blockchain
  • Policy
  • Explainers

Markets & Tools

  • Market News
  • Live Charts
  • Layer Index
  • Regulation Tracker
  • Regulation Radar
  • Research
  • NewsLayer Originals
  • My Feed
  • Search

Company

  • About NewsLayer
  • Go Premium
  • Advertise
  • PR Publication
  • Become an Author
  • Create Account
  • Sign in

© 2026 NewsLayer.com — The front page of the onchain economy·Privacy Policy·Terms of Service

NewsLayer

Get the signal, not the noise.

Markets, regulation and onchain intelligence in a 5-minute morning read — plus breaking alerts and Layer Index flips as they happen.

The Daily Brief

Breaking alerts

Index flips

Free · No spam · Unsubscribe anytime