In brief

A firmware bug meant Coldcard wallets generated seeds from a software pseudo-random generator instead of the hardware chip built to do the job.

The bug effectively shrank the search space from 128 bits to roughly 40 on older models.

Here's what all that means, and how it led to over $130 million in Bitcoin stolen.

Somebody has been emptying Bitcoin wallets that were never supposed to be reachable.The coins sat on Coldcard devices—hardware wallets from Canadian manufacturer Coinkite, the kind that never touch the internet. No phishing link. No malware. No stolen laptop. The attackers simply worked out what the private keys were.Galaxy Research has now tracked more than 1,596 BTC stolen across three confirmed waves, with a suspected fourth wave that would lift the total to roughly 2,055 BTC—about $130 million at current prices. One sweep moved $70 million in 41 minutes. Coinkite says at least 15 separate attackers have piled in.The company published a technical backgrounder on August 1 explaining what went wrong. It is an unusually candid document, and the short version is that the wallet was rolling loaded dice for eight years without anyone noticing.Zero is still somethingIn 2021, Coinkite moved Coldcard's cryptography onto libsecp256k1, the same library Bitcoin Core uses. Sound decision. The integration is where it fell apart.The migration quietly rerouted seed generation away from Coldcard's own hardware random number generator and onto MicroPython's software fallback—a small algorithm called Yasmarang that exists for devices with no randomness chip at all.