COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

How bitcoin cold wallets lost $70 million in an attack that never touched the devices

coindesk-70m-no-device-touch

https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices

Organisation
CoinDesk
Evidence role
Reporting
Published
2026-08-01
Source changes
0
Detected differences
17
Unreviewed
0
Copies held
18

CoinDesk's 1 August report on the COLDCARD entropy incident, cited by the coldcard-hack-tracker community monitor. Held as a dated press account of the drain and the devices-not-touched framing. The figures and attribution are the outlet's own, not verified here.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held
    seen · Captured here 9,984 chars
    Extracted text as captured
    Search
    /
    News
    Video
    Prices
    Research
    Events
    Data & Indices
    More
    Sponsored
    Search
    /
    en
    Sign In
    Sign Up
    Tech
    How bitcoin cold wallets lost $70 million in an attack that never touched the devices
    Galaxy Research said weak seed generation let an attacker recreate likely private keys offline, sweep more than 1,000 BTC from nearly 1,200 wallets and continue searching without ever accessing the devices.
    By Shaurya Malwa
    7 days ago
    4 min read
    Make preferred on
    Share
    Share this article
    Copy linkX (Twitter)LinkedInFacebookEmail
    Make preferred on
    Bitcoin cold wallet Coldcard. (Coldcard/Coinkite)
    Summary
    Show
    More than 1,000 bitcoin, worth about $70 million, were drained from 1,196 Coldcard wallets in a 41-minute span on July 30, nearly double the loss first reported.
    Researchers say a firmware flaw in certain Coldcard hardware wallets made supposedly unguessable seed phrases computationally enumerable, allowing attackers to reconstruct private keys without ever touching the devices.
    Security firms warn that more wallets could be hit because owners cannot reliably tell if their seeds were generated on vulnerable firmware, even as investigators trace the attacker through logs from a blockchain data provider.
    More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced.
    Galaxy Research mapped the full event on Friday, finding 1,082.65 BTC swept between 01:10 and 01:51 UTC across six blocks, with three intervening blocks containing nothing, which suggests the transactions were broadcast in batches rather than continuously.
    The proceeds sit in four addresses and have not moved. Early reporting captured only one of those addresses, which is why the figure has grown.
    The size of the attack is much smaller than some of the bigger attacks this year, but the mechanism is what makes this unusually — and why the attack is such a big deal.
    Why the Coldcard wallet exploit is a bigger deal than most exploits
    Most crypto theft involves getting to something. An exchange is breached, a contract is tricked, a key is phished off a laptop. The defence has always been distance, which is precisely what a hardware wallet sells. Keep the key on a device that never connects to the internet and, theoretically, there is nothing for an attacker to touch.
    Most crypto thefts require reaching the key. This one rebuilt it. (Shaurya Malwa/CoinDesk)
    When a wallet is created, the device is supposed to pick a number so large and so unpredictable that guessing it is impossible.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

17 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
  • +11 -12 Only the article's relative-time labels and the live cryptocurrency ticker values in the site navigation changed.
  • +23 -22 Only rotating related-content cards, live cryptocurrency ticker values and relative-time labels changed; the incident article text was unchanged.
  • +23 -23 Only rotating related-news headlines and live market-ticker values changed; the incident article text was unchanged.
  • +21 -21 Only relative-time labels, live cryptocurrency ticker values, and rotating related-content headlines changed. The article body was unchanged.
  • +24 -24 Only the rotating Latest Crypto News headlines and the live cryptocurrency ticker footer changed; the article text was unchanged.
  • +30 -30 Only the rotating related-content headline list and live cryptocurrency ticker values in the site chrome changed; the article text was unchanged.
  • +25 -25 Only rotating related-story headlines, live cryptocurrency ticker values and relative-time labels in the site chrome changed; the article body was unchanged.
  • +24 -24 Only the rotating Latest Crypto News headlines, their relative timestamps and live cryptocurrency ticker values changed; the article text was unchanged.
  • +26 -26 Only the rotating Latest Crypto News headlines, their relative ages, and the live cryptocurrency ticker footer changed; the incident article text was unchanged.
  • +21 -21 Only rotating related-story cards, live cryptocurrency ticker values and relative-time labels changed; the article text was unchanged.
  • +27 -27 Only relative timestamps, rotating related-story headlines, and the live crypto price ticker changed; the article text was unchanged.
  • +27 -25 Only relative-time labels, rotating related-story headlines and live cryptocurrency ticker values changed.
  • +18 -18 Only the rotating latest-news list and live market-ticker values changed; the article text was unchanged.
  • +18 -18 Only rotating related-news headlines, relative timestamps, and live cryptocurrency ticker values changed. The article body was unchanged.
  • +21 -21 Only relative timestamps, live cryptocurrency ticker values, and rotating related-story cards changed; the article text was unchanged.
  • +10 -10 Only relative timestamps and live cryptocurrency ticker values in the page chrome changed; the article text was unchanged.
  • +21 -21 Only rotating related-story ages, live market tickers and site navigation chrome changed.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.