{"id":9269,"date":"2026-08-01T02:18:24","date_gmt":"2026-07-31T23:18:24","guid":{"rendered":"https:\/\/handoli.com\/index.php\/2026\/08\/01\/coldcard-attack-25-minutes-500-wallets-38m-in-btc-gone\/"},"modified":"2026-08-01T02:18:24","modified_gmt":"2026-07-31T23:18:24","slug":"coldcard-attack-25-minutes-500-wallets-38m-in-btc-gone","status":"publish","type":"post","link":"https:\/\/handoli.com\/index.php\/2026\/08\/01\/coldcard-attack-25-minutes-500-wallets-38m-in-btc-gone\/","title":{"rendered":"Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone"},"content":{"rendered":"<div><\/div>\n<p>Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed phrase exploit targeting Coldcard hardware wallets.<\/p>\n<p>The attack took just 25 minutes to move the BTC from 500 single-signature addresses into a single address, and <a href=\"https:\/\/x.com\/max_guise\/status\/2083007766202142832?s=20\" target=\"_blank\" rel=\"noreferrer noopener\">reports<\/a> suggest the exploit will likely continue.<\/p>\n<p><em>Coindesk<\/em> <a href=\"https:\/\/www.coindesk.com\/tech\/2026\/07\/31\/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep\" target=\"_blank\" rel=\"noreferrer noopener\">reports<\/a> that the affected BTC was dated between 2021 and 2026, and much had remained dormant for years. Of the 594 coins stolen, 562 remain in the same address at the time of writing.<\/p>\n<p>Coldcard maker, Coinkite, <a href=\"https:\/\/blog.coinkite.com\/coldcard-mk3-seed-generation-warning\/\" target=\"_blank\" rel=\"noreferrer noopener\">confirmed<\/a> hours after the exploit that seed generation within its Mk3 wallet, and its subsequently updated versions beyond March 2021 (version 4.0.1), may not have been random at all.<\/p>\n<p>Coldcard initially <a target=\"_blank\" href=\"https:\/\/x.com\/COLDCARDwallet\/status\/2082961993070247948?s=20\" rel=\"noreferrer noopener\">claimed<\/a> that its Mk3 devices were at risk, and that the Mk4, Q, and Mk5 are \u201cnot affected based on our early analysis.\u201d<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">The first post was the advisory and what users should  do.<\/p>\n<p>This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3\/Mk4\/Q\/Mk5, and what we changed.<a href=\"https:\/\/t.co\/HshUxevCl3\">https:\/\/t.co\/HshUxevCl3<\/a><\/p>\n<p>( current evaluating Mk3 firmware release ) <a href=\"https:\/\/t.co\/Yfdx4XcztA\">https:\/\/t.co\/Yfdx4XcztA<\/a><\/p>\n<p>\u2014 COLDCARD (@COLDCARDwallet) <a href=\"https:\/\/x.com\/COLDCARDwallet\/status\/2083081854597374168?ref_src=twsrc%5Etfw\">July 31, 2026<\/a><\/p><\/blockquote>\n<\/div><figcaption class=\"wp-element-caption\">Coinkite\u2019s updated analysis of the $38 million wallet exploit.<\/figcaption><\/figure>\n<p><em>Read more: <a href=\"https:\/\/protos.com\/credit-default-swaps-forecast-ai-bankruptcies\/\" target=\"_blank\" rel=\"noreferrer noopener\">Credit default swaps forecast AI bankruptcies<\/a><\/em><\/p>\n<p>Block, formerly known as Square, found different results in its <a href=\"https:\/\/engineering.block.xyz\/blog\/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware\" target=\"_blank\" rel=\"noreferrer noopener\">published<\/a> analysis while one of its team members, Max Guise, <a href=\"https:\/\/x.com\/max_guise\/status\/2083007814713373075?s=20\" target=\"_blank\" rel=\"noreferrer noopener\">found<\/a> flaws between Mk2 and Mk5 Coldcard models.<\/p>\n<p>The payments company traced the bug to a mis-written compile-time check. The newer devices, Block found, carry a smaller, but real, version of the same flaw.<\/p>\n<h2 class=\"wp-block-heading\">Coinkite believes AI was used to discover exploit<\/h2>\n<p>Coinkite\u2019s recent analysis <a href=\"https:\/\/blog.coinkite.com\/entropy-technical-backgrounder\/\" target=\"_blank\" rel=\"noreferrer noopener\">deduced<\/a> that, because Coldcard\u2019s source code is open and public, someone likely used AI to exploit it.<\/p>\n<p>It said that a few weeks before the attack, it couldn\u2019t spot the bug even with Coinkite\u2019s use of \u201cthe best available AI models.\u201d<\/p>\n<p>It added, \u201cBoth attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys.\u201d<\/p>\n<p>Pseudonymous owners of Bitcoin.org website, <em>Cobra<\/em>, also <a href=\"https:\/\/blog.coinkite.com\/entropy-technical-backgrounder\/\" target=\"_blank\" rel=\"noreferrer noopener\">expressed<\/a> that they have \u201cvery bad feeling AI was involved,\u201d and noted, \u201cFor whatever reason some addresses are only being partially drained despite the private key being compromised. Strange.\u201d<\/p>\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-protos wp-block-embed-protos\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"f1lsAeLKC1\"><p><a href=\"https:\/\/protos.com\/defi-loses-35m-in-a-day-are-bounties-inviting-more-hacks\/\">DeFi loses $35M in a day: Are \u2018bounties\u2019 inviting more hacks?<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p><em>Read more: <a href=\"https:\/\/protos.com\/apple-threatens-sparrow-bitcoin-wallet-dev-with-app-store-termination\/\" target=\"_blank\" rel=\"noreferrer noopener\">Apple threatens Sparrow bitcoin wallet dev with App Store termination<\/a><\/em><\/p>\n<p>Crypto developer Stephen DeLorme <a href=\"https:\/\/x.com\/StephenDeLorme\/status\/2083015462107955282?s=20\" target=\"_blank\" rel=\"noreferrer noopener\">claims<\/a> he was able to use AI model Claude Opus 5 to sniff out the Coldcard vulnerability after cloning the firmware\u2019s repository. <\/p>\n<p>\u201cAll our software is insecure, and we\u2019re painfully figuring that out in realtime with AI agents,\u201d DeLorme said. <\/p>\n<h2 class=\"wp-block-heading\">The technicalities behind the Coldcard BTC theft<\/h2>\n<p>BTC wallets need genuinely random numbers to generate an unguessable private key. Coldcard\u2019s firmware was supposed to pull that randomness from a hardware generator built into its STM32 chip.<\/p>\n<p>According to Block, a codebase check tested only whether a macro called MICROPY_HW_ENABLE_RNG was defined, not what value it held.<\/p>\n<p>Coinkite\u2019s software build set that macro to zero on purpose. Because the character was set to zero, and not a variable symbol, the check was flawed.<\/p>\n<p>Despite this, the flawed check passed anyway during software operations. Firmware fell back to Yasmarang, a MicroPython pseudo-random number generator never meant for real-world cryptographic protection.<\/p>\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-protos wp-block-embed-protos\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"XSJ77z55nb\"><p><a href=\"https:\/\/protos.com\/project-eleven-paid-a-quantum-prize-for-a-random-number-generator\/\">Project Eleven paid a quantum prize for a random number generator<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p><em>Read more: <a href=\"https:\/\/protos.com\/the-number-of-btc-wallets-holding-more-than-0-1btc-hasnt-grown-in-two-years\/\" target=\"_blank\" rel=\"noreferrer noopener\">The number of BTC wallets holding more than 0.1 BTC hasn\u2019t grown in two years<\/a><\/em><\/p>\n<p>Bitcoin Core developer Gregory Sanders <a target=\"_blank\" href=\"https:\/\/x.com\/theinstagibbs\/status\/2082958675975553224?s=20\" rel=\"noreferrer noopener\">reproduced<\/a> the attack using setup button-press counts, and confirmed its impact on Mk3 and Mk2 models. His own <a target=\"_blank\" href=\"https:\/\/x.com\/theinstagibbs\/status\/2082959128834498894?s=20\" rel=\"noreferrer noopener\">response<\/a> to his findings was, \u201cSorry, this is the time to panic.\u201d<\/p>\n<p>Sanders first<a href=\"https:\/\/x.com\/theinstagibbs\" target=\"_blank\" rel=\"noreferrer noopener\"> wrote<\/a>, \u201cconfirmed. Mk2\/3 vuln, I don\u2019t think mk4 is but can\u2019t be certain,\u201d before following up an hour later with \u201cmk4 is probably not much better.\u201d<\/p>\n<p><em>Got a tip? Send us an email securely via\u00a0<a href=\"https:\/\/leaks.protos.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Protos Leaks<\/em><\/a>. For more informed news and investigations, follow us on\u00a0<a href=\"https:\/\/twitter.com\/protos\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>,\u00a0<a href=\"https:\/\/bsky.app\/profile\/protos.com\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Bluesky<\/em><\/a>, and\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqJAgKIh5DQklTRUFnTWFnd0tDbkJ5YjNSdmN5NWpiMjBvQUFQAQ\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Google News<\/em><\/a>, or subscribe to our\u00a0<a href=\"https:\/\/youtube.com\/protosmedia\" target=\"_blank\" rel=\"noreferrer noopener\"><em>YouTube<\/em><\/a>\u00a0channel.<\/em><\/p>\n<p>The post <a href=\"https:\/\/protos.com\/coldcard-attack-25-minutes-500-wallets-38m-in-btc-gone\/\">Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone<\/a> appeared first on <a href=\"https:\/\/protos.com\/\">Protos<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed phrase exploit targeting Coldcard hardware wallets. The attack took just 25 minutes to move the BTC from 500 single-signature addresses into a single address, and reports suggest the exploit will likely continue. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9270,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[147],"tags":[],"class_list":["post-9269","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-invest"],"_links":{"self":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts\/9269","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/comments?post=9269"}],"version-history":[{"count":0,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts\/9269\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/media\/9270"}],"wp:attachment":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/media?parent=9269"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/categories?post=9269"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/tags?post=9269"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}