Coldcard's Entropy Was 40 Bits. The Rest Was Theater.
Everyone is calling this a hardware wallet failure. It was an entropy failure — and until you can independently verify the randomness source in any signing device you own, you are in the same position Coldcard users were on July 29.

TITLE: Coldcard's Entropy Was 40 Bits. The Rest Was Theater.
BODY:
At 01:10 UTC on July 30, an attacker started sweeping Bitcoin wallets. By 01:51 UTC, 1,196 wallets were empty. Nobody's device was touched. Nobody's seed backup was stolen. Nobody clicked a phishing link.
The attacker drained 1,196 Bitcoin addresses in 41 minutes, taking 1,082.65 BTC worth about $70.2 million. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. The theft happened almost 30 hours before Coinkite publicly warned users anything was wrong.
The consensus narrative is that a trusted hardware wallet failed catastrophically. That framing is technically accurate and strategically useless. The real story is one level down.
The Flaw Was Not in the Hardware. It Was in the Randomness.
A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG). Block traced the fault to Coldcard's production config, which defines MICROPY_HW_ENABLE_RNG as zero because Coinkite supplies its own hardware-RNG wrapper. The libngu library checked whether the macro existed rather than whether it was enabled, binding the build to MicroPython's Yasmarang fallback. The fallback was initialized from the chip's unique ID and timer registers and collected no fresh entropy after initialization.
Translation: the device had a hardware random number generator. The firmware accidentally turned it off. Every seed generated after March 2021 was derived from the chip serial number and a clock reading — two values that are either public or reconstructible.
Coinkite estimates effective entropy at roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q, against 128 bits for a 12-word BIP-39 seed. Forty bits. The minimum acceptable for a Wi-Fi password.
Block says an attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. Candidate seeds can then be checked by deriving their addresses and comparing them with public blockchain data. The blockchain is public. The comparison step is free.
Galaxy Research said the incident did not target specific users but described it as a large-scale scan that systematically searched for vulnerable seeds. This was not a heist. It was a harvest.

Air-Gapping Fails When the Keys Were Already Weak
Air-gapping protects the key after it exists. It does nothing if the key was never cryptographically sound to begin with.
Many victims appear to have followed the standard security advice available at the time: buy a respected hardware wallet, generate the seed offline, protect the backup, and never enter it into an internet-connected device. They did everything right by the threat model they were sold. The threat model was incomplete because it assumed the device's entropy source was functioning.
The firmware containing the vulnerability was publicly available as open-source code for five years. Coinkite stated it had been unaware of the bug until the day of the sweep. Five years. Open source. Unaudited in the one place that mattered.
One group survived intact: Coldcard owners who rolled their own dice during setup ended up with seeds the attacker could not reproduce, and those wallets survived untouched. External entropy injection, performed manually, worked. The question is why it was optional.
Coinkite shipped emergency firmware for every affected model on July 31, but installing it does not repair an existing seed. Restoring the old seed to updated firmware or another wallet carries the weakness forward. Migration is the only fix.
What This Actually Costs the Ecosystem
The operational cost lands on you: every self-custody workflow that trusts a single device's onboard RNG is now an unverified assumption.
Security firms warn that more wallets could be hit because owners cannot reliably tell if their seeds were generated on vulnerable firmware. That uncertainty is the real accelerant. Users who are unsure have no forensic way to confirm safety without moving funds.
The beneficiaries are custody providers claiming audited entropy and multisig coordinators — Unchained Capital, Wizardsardine — whose architecture distributes entropy risk across multiple devices. Multi-signature wallets, which require keys from multiple devices or locations before bitcoin can move, were largely or fully protected when the vulnerable Coldcard seed represented only one part of the signing arrangement. Distributed key generation is not just a convenience. After July 30, it is a defense against a single vendor's entropy bug.
If your custody architecture depends entirely on one device's onboard RNG, you are one undiscovered firmware bug away from the same outcome.
What to Watch
Coinkite's forensic disclosure. If they publish a clear, timestamped account of how the RNG disable survived five years of code review, that signals credibility recovery. Silence or vague statements about "ongoing investigation" is a second blow.
Other hardware wallet vendors. Watch for pre-announced independent RNG audits from Ledger, Trezor, and Foundation Devices. If none appear within 30 days, draw your own conclusion about their confidence.
The stolen BTC on-chain. The stolen Bitcoin was quickly consolidated into several wallets, with researchers identifying one address that still holds more than 562 BTC. Other wallets contain 398 BTC, 89 BTC, and 32 BTC, with none of the funds moving after consolidation. When it moves, on-chain forensics become the centerpiece of every lawsuit that follows.
Litigation. Class actions against Coinkite are obvious. The sharper question: whether advisors, retailers, or publications that recommended Coldcard as gold-standard self-custody get named in follow-on suits.
Regulatory pressure on self-custody infrastructure. This incident hands regulators a concrete harm number — $70 million, documented on-chain — to attach to the argument that consumer-grade signing devices require mandatory entropy audits. Watch for that language in the next crypto legislation drafts.
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
- Coldcard's biggest security failure may have cost $70M
- Coldcard Wallet Flaw Exposed? Hacker Quietly Drains 1,082 BTC Before Security Warning
- How bitcoin cold wallets lost $70 million in an attack that never touched the devices
- Coldcard Hardware Wallet Hacked via Firmware Bug That Bypassed RNG for Five Years
- The Coldcard Exploit Explained: Who Lost Bitcoin and Who's at Risk
- COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED
- Coldcard Seed-Flaw Hack Drains 1,082 Bitcoin From 1,196 Cold Wallets
- Hardware Bitcoin Wallet Bug Puts Years of BTC Seeds at Risk
- Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep
- Coldcard Hacked for $70M: How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked? - 24/7 Wall St.
- Coldcard Hacked for $70M: How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked? - AOL
- Is Your Hardware Wallet Safe After the Coldcard Exploit? – Securities.io