Fnalysis Fnalysis. Hardware Irony

Bitcoin's most trusted "cold" wallet had been generating weak keys for five years, and someone used AI to find it before its own maker did

On July 30, 2026, an attacker drained roughly 594 bitcoin (about $38 million) from nearly 500 Coldcard wallets in a 25-minute sweep, exploiting a firmware bug that had been active since March 2021: instead of using the device's own hardware random number generator, it fell back on a software one, cutting seed security from 128 bits down to as little as 40. By August 2, the stolen total had climbed to roughly 1,367 bitcoin ($88.6 million) across more than 4,500 addresses.

Rodolfo Novak, CEO of Coinkite, the company behind Coldcard, publicly apologized and admitted the company's own review process had failed to catch the bug; the attacker, according to the company itself, used AI to find it first. Because the flaw corrupts the seed itself, updating the firmware isn't enough: anyone with an affected Coldcard has to generate a brand-new recovery phrase and move their funds, since the old one remains permanently compromised.

Source: CoinDesk →

Its "cold" storage ran red-hot.

← See all weird crypto news on Fnalysis