Overview
- On July 30 a rapid sweep tied by Galaxy Research to Coldcard weakness drained 1,082.65 BTC and two follow-up waves brought the observed total to about 1,367.05 BTC from roughly 4,585 addresses.
- A March 2021 firmware integration error caused affected builds to fall back from the STM32 hardware random number generator to MicroPython’s Yasmarang pseudorandom routine, producing far less entropy in BIP‑39 seeds.
- Coinkite released emergency firmware fixes on July 31 that stop future vulnerable seed creation but warned that seeds already generated remain insecure and must be replaced on patched devices.
- The public disclosure triggered mass migrations that spiked small‑output transfers, raised daily active addresses, and sent some funds to exchanges and peel chains while investigators trace stolen coins.
- The incident has hit long‑dormant cold‑storage holders, exposed limits of self‑custody, and follows recent research on weak PRNGs that together point to a wider class risk for wallet randomness.