So, for me this is really one of the weirdest hacks in Bitcoin history, because the more I dig into it, the stranger it gets.
So, if you don't know anything about it then there is a Canadian entrepreneur who did everything by the book. He never shared his seed phrase with anyone (A seed phrase is a list of 12 or 24 simple words that acts as the master key to your crypto wallet. Anyone who has those words can access and control all the coins inside, so you keep them secret and never lose them).
So, his devices never touched the internet. His Coldcard, one of the most respected hardware wallets on the planet, sat locked inside like a bank safety deposit box. And then, on July 29, almost 18 bitcoin, about $1.6 million, got debited from his wallet. He tweeted about it online and the entire internet lost its mind. That tweet has now been seen something like 7.6 million times or even more, and honestly, I get why. If his coins were not safe, whose were?
So I tried to connect the dots and also today I saw on Twitter there are some new things that are coming out on what actually happened, because this is not any usual "someone clicked a phishing link" kind of a hack.
So, the whole thing goes back to a single code change made on March 1, 2021. One commit. Coinkite, the Toronto company behind Coldcard, was migrating to a new cryptographic library, and somewhere in that process the firmware quietly stopped using the device's dedicated hardware randomness chip when generating seed phrases.
Now, that chip is the most important thing. A hardware true random number generator embedded into the STM32 processor is one of the main reasons you pay a premium for a device like this. It exists to pull genuine, physics-grade unpredictability so that your seed phrase is impossible to guess. Instead, the firmware fell back to a software pseudo-random number generator, a little algorithm that only pretends to be random. And this fake randomness was seeded with predictable stuff: the device's serial number, an internal timer at power-on, and the history of previous calls. The firmware hashed all of it with SHA256, which sounds impressive, but hashing can only scramble what you feed it. It cannot generate randomness that was never there in the first place.
I mean what I am trying to say here is that a properly generated Bitcoin seed is supposed to be picked from a pool so vast that it has 128 bits of entropy, a number with 39 digits in front of it. The affected Coldcard Mk2 and Mk3 devices collapsed that pool down to roughly 40 bits. That is about a trillion possibilities. Sounds like a lot until you realize a determined hacker with decent hardware can chew through a trillion combinations in under two weeks. The newer Mk4, Mk5 and Q models fared a little better at around 72 bits, but "better" is doing heavy lifting there. The point is, the front door was never really locked.
This is the detail that separates the Coldcard hack from almost every other crypto theft you have read about. There was no malware. No stolen device. No remote takeover. No brute-forcing Bitcoin's actual cryptography, which remains perfectly intact, by the way.
The attackers just sat at their own computers, reproduced that weak randomness process offline, generated millions of candidate seeds, turned each one into Bitcoin addresses, and then checked those addresses against the public blockchain to see which ones had money sitting in them. When one lit up, they swept it. Cold, patient, and completely invisible until the coins started vanishing. The safety deposit box, the offline setup, the OPSEC discipline, none of it mattered, because the weakness was baked into the keys themselves the moment they were born.
Once I start analyzing this on-chain and before me or anyone like us, Galaxy Research has been the loudest voice mapping it. They counted at least three confirmed waves, with a suspected fourth. The first wave on July 30 was brutal and fast: 1,082 BTC drained from 1,196 wallets, and get this, the whole sweep was broadcast inside 41 minutes. Later waves went after smaller, harder-to-trace balances, sometimes just a few thousand dollars a pop.
Add it all up and the confirmed damage sits around 1,596 BTC swept from roughly 7,300 addresses, with total losses widely estimated at 2,055 BTC, or about $130 million depending on the day's price. The typical stolen coin had been sitting untouched for around three and a half years. These were long-term holders, the exact people who bought a Coldcard precisely because they wanted to lock coins away and forget about them.
And I also believe like many investigators that this was not one hacker. I mean possibly a dozen different actors piled into the same vulnerable key space once the flaw became known. The disclosure itself may have started a gold rush, with multiple parties racing to scan the weak range before anyone else got there.
For weeks after the theft, the story went quiet in a very specific way. Roughly 90 percent of the stolen bitcoin just sat there, frozen in place, untouched in the very wallets it landed in. The largest single stash, about 1,159 BTC spread across seven addresses, has not budged since the initial consolidation. When money sits still like that, everyone holds their breath.
Then yesterday, August 7, the silence broke. On-chain tracker Lookonchain flagged that a wallet tied to the hack moved 30.185 BTC, worth about $1.94 million, into a freshly created address. It is the attacker's first movement since the theft, and it is only about 1.5 percent of the haul, but on-chain analysts treat a dormant thief's first stir as a classic early signal of an attempted cash-out. As of this morning, that is exactly where things stand: everyone is watching that destination wallet, waiting to see if it feeds into a mixer, hops across chains, or breaks into smaller pieces headed for an exchange.
Some funds have already touched Wasabi Wallet's CoinJoin service, and Chainalysis has been tracing distinct laundering fingerprints. But mixers do not equal invisibility. Timing, output sizes and later consolidation all leave crumbs, and Galaxy says it has already handed attacker and victim addresses to US law enforcement and exchanges.
Coinkite's CEO owned the mistake candidly, admitting he set a config flag to zero thinking neither randomness source was needed, "but that's not what it does." A patched firmware is out, but the most disturbing thing is that updating does nothing for a seed already born weak. If your keys came from an affected device, the only real fix is generating a fresh seed on patched firmware and moving everything.
So, if you ask me the Cold storage protected these people from every threat they were told to fear, and none of it mattered, because the danger was never outside the box. It was inside the keys the whole time.