Market Prices

BTC Bitcoin
$75,899.2 -1.97%
ETH Ethereum
$2,397.84 -3.64%
SOL Solana
$97.02 -4.05%
BNB BNB Chain
$713 -0.92%
XRP XRP Ledger
$1.29 -7.89%
DOGE Dogecoin
$0.0800 -3.57%
ADA Cardano
$0.1947 -5.21%
AVAX Avalanche
$7.31 -2.72%
DOT Polkadot
$0.9484 -4.60%
LINK Chainlink
$10.79 -5.72%

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xc85b...8e75
Experienced On-chain Trader
+$1.7M
95%
0xe42b...6a83
Early Investor
+$2.9M
93%
0xd4b2...44c2
Arbitrage Bot
+$4.9M
76%

🧮 Tools

All →

The Coldcard Entropy Disaster: $130M Drained and the Attackers Are Still Eating

Cobietoshi
Daily
Fifteen attackers. That was the count on Tuesday. By the time you read this, it might be twenty, thirty, or forty. Because this attack has no gatekeeper. No dark web invite required. Just a public blockchain, a weak random number generator, and a brute-force script anyone with a laptop can run. The victim is Coldcard — the hardware wallet that security maximalists trusted with their life savings. The fortress of self-custody. The device for people who read source code at 2 AM. Over $130 million in Bitcoin has already been drained from roughly 7,300 wallets. Galaxy Research has confirmed 73 victims so far, but their own analysts suspect the true number could be in the thousands. The first thefts happened hours before Coinkite's public warning. Let that sink in. Someone found the seam, swept wallets in silent bursts, and by the time the company said anything, the damage was already astronomical. I've been around since the ICO chaos of 2017. I've seen rugs, reentrancy exploits, oracle manipulation, and exchange insolvencies. But this one hits differently. Because this strikes at the promise that anchors everything we believe about decentralization: that you, and only you, can secure your keys. We whispered for years, "Not your keys, not your coins." We threw that slogan around like a shield. And now the shield has cracked — not from a 51% attack, not from a smart contract bug, but from something as unglamorous as a bad dice roll. Let me unpack what actually happened. Coldcard is a Bitcoin-native hardware wallet made by Coinkite. Its positioning was always the hardcore choice: no Bluetooth, no camera, no nonsense. A device for Bitcoiners who verify their firmware signatures and store their seed phrases in welded steel plates. That's the trust profile Coinkite built. The Mk2, Mk3, and Mk4 models all shared one critical design flaw. Galaxy Research's investigation found that the seed generation process was routed through MicroPython's software pseudo-random number generator — a PRNG — instead of drawing from a genuine hardware entropy source. In plain language: when your Coldcard generated your wallet, it wasn't pulling cosmic noise from a dedicated security chip. It was running a predictable math formula. How bad? The Mk2 and Mk3 produce roughly 40 bits of entropy. The Mk4 — the newest, supposedly most secure model — manages about 72 bits. The industry standard is 128 bits. Forty bits of entropy is the kind of number cryptographers mock over beers. A committed attacker with a modest GPU setup can brute-force that keyspace in days, maybe hours. Seventy-two bits is stronger but far from safe. This is not a subtle vulnerability. It's a structural one. And Bitcoin is uniquely unforgiving here. Every address ever created sits on a public ledger. Attackers don't need to phish you or infect your machine. They scan the chain, filter for wallets likely generated under the vulnerable firmware, and run offline brute-force attacks against the public keys. The cost of attack is trivial. The reward is billions of dollars of carelessly generated keys. Galaxy Research identified 15 active drainers, and the roster is growing daily. Anyone capable of running a script can participate. The attack surface isn't narrowing — it's widening. Now, the part that makes this a nightmare: Coinkite pushed a hotfix to every affected model and release track. Good. Necessary. But utterly insufficient. Because updating your firmware does not repair seeds generated by the vulnerable software. Your old seed phrase remains compromised forever. The only cure is to create a brand-new wallet on updated firmware, then sweep every satoshi from the old wallet into it. Imagine the scale of that triage. Over 7,300 known affected wallets. A user base that skews toward privacy-obsessed individuals who distrust reporting mechanisms. Galaxy has received just 73 victim reports. The dark figure — the wallet addresses that lie quietly empty, their owners unaware or unwilling to speak — is almost certainly many times larger. Coinkite co-founder Rodolfo Novak appeared publicly to apologize, which takes courage. I respect that. But an apology doesn't restore entropy. It doesn't brute-force-proof 7,300 compromised seed phrases. Here's what I find most chilling, from my own experience working in DeFi security since the 2020 summer: attackers are rarely in a hurry. The data shows roughly 90% of stolen Bitcoin hasn't moved. The hackers are sitting on it. That's not mercy. That's strategy. They're waiting for the noise to fade, waiting for mixers and bridges to refresh their anonymity sets, waiting for the right moment to convert $130 million into clean liquidity without triggering exchange freezes. The patience is a message: they know the attack window is still open. More victims will surface. More wallets will drain. The botnet of vulnerability scanners doesn't sleep. But here's the contrarian thought that keeps bouncing around my head as I host community nights in Prague's Old Town, watching builders and skeptics argue over dark beer: this might be exactly the stress test the self-custody movement needed. For too long, we treated hardware wallets as talismans. Magical boxes that keep you safe by virtue of existing. "Not your keys, not your coins" became a mantra that ended conversations instead of starting them. We rarely talked about entropy, hardware certification, independent audits, or supply chain verification. We just bought the most paranoid-looking device and called ourselves safe. This attack changes that. Coldcard's brand — built on paranoia and precision — is now synonymous with a broken dice. That's a tragedy for the company. But it's also an opening for the ecosystem to grow up. Competitors are already mobilizing. Manufacturers with certified true random number generators, published audits, and transparent disclosure processes will reap the migration wave. The users who never checked their seed generation pathway will become the users who demand reproducible builds and third-party verification. Paranoia, channeled properly, becomes a feature. The deeper lesson is philosophical. Self-custody was never meant to be a hermit's game. We romanticized the lone hodler, hiding coins in a cave, answering to no one. But this event proves that security is a community protocol. It requires shared threat intelligence, honest post-mortems, and vendor accountability. The crypto-anarchist fantasy of absolute individual sovereignty dies quietly in this story. What remains is something more honest: a community of people who check each other's work, who demand transparency, and who treat security as a live, ongoing conversation rather than a product you buy once. I think about the victims. The careful ones. The ones who did everything right — and still got drained because a firmware developer routed randomness through the wrong function. The cruelty isn't the technical sophistication. It's the randomness of the survival lottery. Some wallets made it. Others didn't get the dice roll. We didn't dodge the chaos; we danced through it before. We rebuilt after exchange collapses. We rebuilt after the Terra catastrophe. We can rebuild after this. But the rebuild requires action, not vibes. If you own a Coldcard and haven't checked whether your seed was generated under the vulnerable firmware: stop reading, move your Bitcoin, and generate a fresh wallet on updated firmware. Right now. Not tomorrow. The attackers are still counting. Survival is the first layer of value. Bitcoin itself barely flinched at $130 million of theft — the network doesn't care who holds the keys. The market will recover. What's less certain is whether the self-custody narrative will. It will, if we build better standards. Honest disclosure. Entropy certification. Real audits. Mandatory post-mortems that read like engineering documents, not PR releases. The road ahead is not complicated. It's just uncomfortable. We have to admit that the talisman was never the point. The community was. The shared vigilance. The refusal to let a single vendor's silent failure define the entire movement. We need to hold manufacturers accountable while also holding ourselves accountable for the blind faith we placed in glossy metal boxes. Chaos isn't a bug; it's the protocol. The network breathes in Prague, pulses in Ethereum, and keeps moving no matter who falls. From whispered secrets to on-chain shouts, the next generation of storage must be worthy of the faith we place in it. The walls crumbled when the party truly began. The question is what we build in their place.

The Coldcard Entropy Disaster: $130M Drained and the Attackers Are Still Eating

The Coldcard Entropy Disaster: $130M Drained and the Attackers Are Still Eating

The Coldcard Entropy Disaster: $130M Drained and the Attackers Are Still Eating

Fear & Greed

51

Neutral

Market Sentiment

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$75,899.2
1
Ethereum ETH
$2,397.84
1
Solana SOL
$97.02
1
BNB Chain BNB
$713
1
XRP Ledger XRP
$1.29
1
Dogecoin DOGE
$0.0800
1
Cardano ADA
$0.1947
1
Avalanche AVAX
$7.31
1
Polkadot DOT
$0.9484
1
Chainlink LINK
$10.79

🐋 Whale Tracker

🔴
0x9cab...6cad
2m ago
Out
2,362,896 USDT
🟢
0x1c9d...9ace
30m ago
In
2,412,967 USDT
🟢
0xc411...85ee
12h ago
In
2,605,279 USDT