Coldcard RNG Flaw Drives $88.6M Bitcoin Drain as Third Wave Hits Long-Dormant Wallets
Galaxy Research tracks 1,367 BTC stolen across 4,585 single‑sig Coldcard wallets after a 2021 firmware entropy bug, including a fresh 207.73 BTC sweep. Funds remain idle as the attack continues.

Because Bitcoin
August 2, 2026
The target isn’t your vault—it’s your randomness. Another coordinated sweep has hit Bitcoin wallets generated by affected Coldcard devices, pushing observed losses to about 1,367 BTC (roughly $88.6 million) across 4,585 addresses. Galaxy Research identified a third wave removing 207.73 BTC and warned the operation is still active. The guidance is blunt: if you hold single‑signature funds on Coldcard‑generated addresses tied to the faulty era, migrate now.
Here’s what’s been mapped on-chain. According to Galaxy’s Alex Thorn, the thefts appear deliberate and programmatic—likely assisted by an LLM—systematically emptying vulnerable addresses. The stolen coins had sat idle on average for 3.18 years, signaling that long‑term holders were the primary casualties. Despite the aggressive sweeps, the funds from the three documented waves remain parked at attacker-controlled addresses and have not yet been laundered. Galaxy says it has flagged about 600 suspected attacker addresses to federal investigators, compliance shops, and cross‑industry cyber responders—work made faster by victims who shared transaction data.
The hinge of the entire episode is a March 2021 firmware build error on Coinkite devices that produced seed phrases with insufficient entropy. Weak randomness means the private keys become guessable with enough compute and clever heuristics. Air gaps don’t help when the root secret is statistically compromised at creation. Thorn cautioned that every single‑sig Coldcard address created after that 2021 update will likely be emptied over time; the attacker appears willing to wait and sweep in batches.
The behavioral fallout flips a core crypto narrative on its head. Many affected users are rushing coins off self‑custody and back to centralized exchanges like Coinbase or Binance, or into freshly generated addresses—an inversion of the “not your keys, not your coins” mantra. That reaction is understandable under pressure, but hurried migrations can compound risk if new addresses are derived by the same flawed stack, or if change outputs aren’t verified.
One case illustrates the pain. Canadian coach Jonathan Goodman reported losing 18.25 BTC—about C$1.6 million—in seven minutes on July 29. His keys lived in a safety deposit box and never touched the internet, which underscores the point: cold storage protects against online compromise, not defective entropy. He said he’s filing reports with police and the Ontario Securities Commission.
What actually matters now is reinforcing the trust root. This isn’t a generic hardware‑wallet scare; it’s an entropy failure that collapses the entire tree above it. In practice, that argues for: - Key diversity: consider multi‑sig with keys generated on independent vendors or stacks to avoid single‑point RNG failure. - Verifiable generation: prefer reproducible builds, independent review, and external entropy options (e.g., dice) that can be validated rather than assumed. - Deliberate migrations: sweep to new addresses not generated by the affected firmware; test with small amounts; confirm derivation paths and change outputs; keep watch‑only monitors to validate movements. - Patience over panic: if using an exchange as an interim safe harbor, weigh custody, withdrawal, and jurisdiction risks consciously—not reflexively.
From a market structure lens, this episode will likely accelerate demand for audited RNG, deterministic builds, and cross‑vendor multi‑sig defaults. It also highlights how adversaries now combine on‑chain analytics with automation—potentially LLM‑driven—to sequence attacks for maximum yield and minimal noise. That hybrid capability is becoming table stakes on both sides of the ledger.
The attack is ongoing. If your Bitcoin sits on single‑sig Coldcard addresses created after the March 2021 firmware, assume exposure and move—carefully—to freshly generated, independently verified destinations. In self‑custody, the strongest fortress still crumbles if the foundation of randomness cracks.