Code is law until the wallet is empty.
On a Thursday in 2026, roughly 594 BTC moved out of about 500 dormant bitcoin wallets. The funds were not drained by malware on a phone. They were not pulled from a compromised exchange hot wallet. They were taken from Coldcard hardware wallets, the devices that many bitcoiners consider the gold standard for self-custody. The private keys never left the secure environment. The seed phrases were never typed into a computer. And yet the attacker walked away with approximately $38 million in bitcoin.
The explanation is worse than a physical attack. A firmware update in 2021 had quietly replaced a hardware true random number generator with a software pseudo-random number generator. The seed space became enumerable. The promise of air-gapped security did not survive contact with a predictable entropy source.
This is not an exchange hack. It is not a user error story. It is a supply-chain failure in the most trusted layer of bitcoin custody infrastructure. And it will be cited for years as the moment when transparency about firmware updates became as important as the firmware itself.
The Context: Who Found What
Block's bitcoin engineering and security team identified the root cause. Coinkite, the Canadian company behind Coldcard, confirmed the findings. The technical story is straightforward enough to summarize in one sentence: certain Coldcard firmware versions generated wallet seeds using an entropy source that an attacker could reproduce.
The affected devices include the Coldcard Mk3 running firmware v4.0.0 or later. That firmware shipped in 2021. A build setting introduced a code path that replaced the hardware random number source with a PRNG built from timer state, call history, and known unique identifiers. These are not secrets. A timer can be guessed if the approximate time window is known. Call history can be reconstructed if the code path is understood. A unique device identifier is only unique, not secret.
The result: the wallet seed was no longer a uniformly random 256-bit number. It was a value inside a much smaller, enumerable space. An attacker could reconstruct the seed by brute-force enumeration of the weak inputs.
Coinkite's disclosure notes that this is not limited to the Mk3. The Mk4, Mk5, and Q were also affected, though the report describes the impact as less severe but still serious. That distinction is important. It means the problem was not a one-off hardware bug in a single product. It was a systemic degradation in the way Coldcard firmware handled entropy across multiple product lines.
The affected wallets share common traits. They are single-signature. They hold more than 0.15 BTC. Many have been idle for years, with coin ages spanning from 2021 to 2026. These are long-term holders, not active traders. They set up a wallet, wrote down the seed phrase, and left it alone. That is exactly the use case Coldcard was designed for.
The Core: Entropy Is the Actual Product
A hardware wallet is not a safe. It is a computer with one job: protect a private key. The private key must be generated, stored, and used in a way that keeps it away from networked systems. The Coldcard product line goes further. It supports air-gapped QR code signing and is built for bitcoin users who do not trust general-purpose computers.
But the security of a hardware wallet does not begin with the secure element. It begins with the random number generator. If the key is generated from predictable inputs, the physical security of the chip is irrelevant. The attacker does not need to touch the device. The attacker does not need a USB cable. The attacker only needs the public addresses derived from the weak seeds, and the ability to enumerate the seed space.
This is what happened on that Thursday. Coinkite and Block have not yet provided a complete list of victim addresses, but the pattern is clear. The attacker identified a set of vulnerable wallets. The 0.15 BTC threshold is a targeting criterion, not a security floor. Wallets below that threshold were probably skipped because the cost of extracting and laundering them would outweigh the reward. The 594 BTC figure is therefore the visible harvest, not the full population of weak seeds.
From my own audit experience, this is the same lesson I learned in 2017. When I reviewed ICO token models, I did not ask whether the team believed in their project. I asked whether the liquidity assumptions survived a low-volume stress test. Market narratives always lag the mechanics. The same is true here. The Coldcard narrative was built on physical isolation and firmware quality. The mechanics, however, were undermined by an entropy source that could be enumerated. The brand promise and the code diverged. The code won.
This is a security regression, not an innovation. Hardware wallets have moved toward true random number generators, mixed entropy sources, and audited firmware processes. Coldcard was supposed to be at the front of that curve. Instead, a 2021 build setting walked the product backward. It did not cause an immediate failure. It created a standing vulnerability that waited five years to be exploited. That is the most dangerous kind of security bug: one that produces valid-looking seeds until the right attacker looks at the underlying construction.
The exposure was not a single path. Coinkite's disclosure also mentions that paper wallet private keys, seed split masks, and device clone keys were affected. These are advanced features of the Coldcard ecosystem. Users who generated paper wallets with a vulnerable device received weak private keys. Users who split their seeds across multiple shares received weak shares. Users who cloned device keys received weak clones. In each case, the downstream cryptographic material was polluted at the source.
A firmware update cannot repair seeds that have already been generated. The seed phrase is a backup of the original entropy. If the original entropy is weak, the phrase is only a reminder of a compromised number. Coinkite recommends migrating to a new seed generated on an unaffected device. Users can also use a BIP-39 passphrase to reduce immediate risk. But a passphrase only helps if it was used before the theft. It adds entropy outside the vulnerable generator. It does not make the old seed safe.
This creates a serious operational problem for affected users. They must identify whether their hardware was exposed. They must buy or borrow a trusted device. They must generate a new seed, move all assets, update their backup processes, and monitor the old addresses for years. For a group of dormant long-term holders, this is not trivial. Some will not learn about the incident in time. Some will not have a technical path forward. Some will remain on weak seeds until the attacker decides to collect them.
The most important clue is the 0.15 BTC threshold. It reveals an automated process. The attacker did not select 500 victims through personal surveillance. The attacker wrote a script, derived addresses from weak seeds, and filtered them by balance. The victims were not random. They were old, quiet, single-signature HODLers. This has the signature of a systematic chain-wide scan.
It also raises a dark possibility: the attacker may have known about the vulnerability long before Thursday. If the weak seed space was identified in 2022 or 2023, the attacker could have watched it fill up. The five-year coin-age span suggests many vulnerable wallets were created after the 2021 firmware release. An attacker with patience could accumulate a list of targets and wait. The Thursday theft may be the first harvest, not the only one. There may be hundreds of wallets below the 0.15 BTC threshold that remain technically exposed even if they were not stolen.
The Market: Liquidity Evaporates Faster Than Hype
The direct market impact of 594 BTC is small. The amount is less than one day's worth of normal bitcoin spot volume. It is not a macro sell signal. Bitcoin's consensus layer was not attacked. The protocol did not fail. The loss was concentrated in a hardware wallet product category. If the attacker dumps the 562 BTC that was consolidated into a single address, it could create temporary selling pressure. But it will not break bitcoin's supply-demand structure.
That said, the event will do measurable damage to the self-custody narrative. Coldcard's brand was built on the claim that serious bitcoiners could safely hold their own keys with a device that was simpler and more transparent than the alternatives. That claim has now been punctured. The vulnerability was not found by a hobbyist. It was found by Block's engineering team after watching funds disappear. The discovery process was forensic. The failure was not in a single chip. It was in a firmware update that should have been impossible to miss.
The market is now in a period of heightened hardware-wallet skepticism. The recent Zilliqa chain halt, tied to a vulnerability in a Ledger signing application, was already fresh in the collective memory. When two major incidents happen in a short window, the category effect overwhelms the company-specific analysis. Investors and users will start asking whether hardware wallets actually justify their premiums. This is rational. If a $150 device is marketed as a security requirement, a single entropy bug may be enough to erase the entire value proposition.
The competitive map is shifting. Coinkite's brand is directly damaged. Ledger is indirectly implicated because the Zilliqa incident reminded the market that hardware vendors can ship flawed signing logic. Trezor, if it remains outside this incident, gains a relative advantage. Block also gains credibility as a security research organization. Block's bitcoin engineering team did the forensics. That will matter in the next institutional discussion about bitcoin custody.
But the market reaction should not stop at brand preference. The event suggests a broader structural problem: no continuous audit mechanism exists for key generation quality in hardware wallets. Vendors publish code. Auditors review chips. But the output of a shipped RNG is not continuously monitored on-chain. A wallet vendor could ship a weak firmware for years without being caught. In this case, a large theft was required before the community looked backward and asked where the seeds came from.
The Regulatory Layer: Regulation Lags, But Penalties Lead
This is not a securities case. Bitcoin is not a security, and the Howey test has no meaningful role here. The regulatory consequences will come from financial crime and product liability.
The attacker has stolen a large amount of bitcoin. They consolidated a significant portion into a single address. That is an early step in a money-laundering process. Law enforcement agencies will trace the funds through any exchange, mixer, or bridge that touches them. If the attacker uses a regulated on-ramp, KYC and AML controls will create friction. If the attacker moves through CoinJoin or cross-chain protocols, the trail will become harder to follow but not impossible.
Regulators will also look at Coinkite. The company is headquartered in Canada. It faces potential product liability claims from affected users. Consumer protection law, contract law, and negligence law all apply. If Coinkite knew about the weak entropy source before the attack and did not disclose it, the legal exposure is worse. If the company responded quickly and publicly, the story becomes more sympathetic. The current disclosure includes a recommendation to migrate and a warning about passphrases. That is a start. It is not enough.
The deeper regulatory issue is firmware trust. The hardware wallet industry is lightly regulated because it has not yet been treated as a systemic financial infrastructure layer. That could change. A supply-chain event that allows an attacker to reconstruct private keys is precisely the kind of incident that prompts regulators to demand minimum security standards. The question is not whether this will be used as a justification for new rules. It will. The question is whether the rules will be useful or performative.
In my work as a cross-border payments researcher, I have seen how a single custody failure ripples through emerging-market remittance corridors. Users who self-custody bitcoin in Latin America are not trading Bitcoin. They are saving across borders. They do not have easy access to legal remedies or vendor support. A Coldcard vulnerability is not an abstract Silicon Valley problem. It poisons confidence in the entire instruments that the unbanked use to escape weak local currencies.
The Contrarian Angle: The 500 Wallets Are Not the Whole Story
The market will treat this as a Coinkite incident. The contrarian view is that it is a warning about the entire hardware wallet category.
Every hardware wallet is a small computer with a trusted vendor. The vendor signs firmware updates. The user installs them. The user cannot easily verify that the RNG output remains unpredictable after an update. The Coldcard incident shows that the trust boundary was broken by a build setting. The same class of issue could exist in any device. Open source firmware helps, but it does not guarantee that the compiled artifact matches the published source. Audits help, but they are point-intime exercises. The entropy output of a device is not continuously tested.
The industry must move from a model of telling users to trust a vendor to a model where key generation can be verified after the fact. One possible path is a commitment scheme at wallet setup. A device could publish a public fingerprint of its RNG state before private keys are used. If a vulnerability is later discovered, the fingerprint would allow affected users to be identified without waiting for a theft. This would have privacy costs, and it would require careful design. But it is better than the current model: wait until someone loses millions, then reconstruct the vulnerability from blockchain data.
Another uncomfortable conclusion is that self-custody has an expiry date. Users treat hardware wallets as permanent safes. They buy a device, write down a seed, and forget about it. A hardware wallet is software. Software ages. Firmware updates introduce bugs. Entropy sources degrade. The safe is only as strong as its latest firmware and its original seed generation. Long-term holders need a schedule for revisiting their storage assumptions, just as institutions need a schedule for reviewing counterparty risk.

There is also the issue of silent victims. The current disclosure covers wallets with balances above 0.15 BTC. The attack may have skipped smaller wallets because they were not worth touching. Those wallets are now marked with an invisible vulnerability. Their owners may never notice. A post-mortem of this incident should not stop at the victims whose funds moved. It should attempt to alert every wallet that could have been derived from the weak generator. Without that, the attacker can return later and collect the crumbs.
The phrase “code is law until the wallet is empty” applies here in a precise sense. The code created a predictable seed. The wallet was empty. The owner no longer controls the key because the attacker can reconstruct the same key. That is not a breach of the secure element. It is a breach of the random number generator. Secure elements are designed to protect secrets. They cannot protect a secret that is no longer secret at the moment of creation.
The Takeaway: Assume Nothing, Verify the Generator
Coldcard users who generated seeds with firmware v4.0.0 or later should assume those seeds are compromised until proven otherwise. The only safe path is migration to a fresh wallet on a device with a known-good entropy source. A BIP-39 passphrase is a useful bridge, but it is not a destination. The old seed remains weak. The passphrase only adds a layer on top of the weak material.
The broader lesson is for every bitcoin user, not just Coldcard owners. Security claims must be stress-tested at the level of input randomness. A hardware wallet is only as strong as the entropy that feeds it. If the RNG is a software PRNG with guessable state, the device is not a hardware wallet. It is an expensive paperweight that produces addresses an attacker can later open.
I have spent years auditing systems that fail after long quiet periods. The pattern is always the same. Somewhere in the construction, a small assumption was too convenient. The entities involved did not want to see it. The market did not want to price it. Then the system collapsed and everyone asked why. The Coldcard incident is not a black swan. It is an ordinary entropy failure with extraordinary consequences.
The industry needs on-chain hygiene for key generation. Vendors should publish entropy source specifications. Independent auditors should test shipped devices, not just reference code. Users should rotate critical storage equipment on a regular schedule. And when a vendor says a device is secure, the correct response is not a nod. It is a question: where does the entropy come from, and how do I know it was not predictable?
Volatility is the fee for entry. Predictability is the exit. The 594 BTC left through the exit. The rest of the industry should check its doors.