A timeline of Coldcard’s $85M bitcoin theft

NewsMon, 03 Aug 2026 13:25:34 UTC2 hours ago
A timeline of Coldcard’s $85M bitcoin theft

Last week, hackers discovered a five-year-old bug in Coldcard software and used it to drain over 1,158 BTC worth over $72 million from over 2,600 addresses.

By Sunday, the tally rose to 1,359 BTC and continues to rise today.

A rudimentary dashboard is charting the rising number of thefts, with many security experts warning of additional waves of attacks.

The essence of the bug is that, despite claims by Coldcard’s manufacturer and documentation, many of its devices didn’t actually use a true random number generator (RNG) with sufficient entropy to protect users trusting the device to generate private keys and seed phrases.

Instead, the device used a fallback, a pseudo RNG, with far lower entropy.

Unfortunately, trivial amounts of computation can guess these low entropy seed phrases generated by Coldcard devices.

Once in possession of these private keys, a quick scan of the blockchain reveals associated public keys holding BTC, and hackers then steal those funds.

The bug has existed since March 2021, but security researchers only publicly discovered it last week. As theft transactions began, customers and members of the community began to track the horrifying timeline of events.

… Continue reading the full article at the original source below.

Read from Source · protos.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (protos.com).

Related