Overview
- Security researchers and Coinkite found a March 1, 2021 firmware build that caused the device to skip its hardware random-number generator and fall back to a predictable software method seeded by chip serial numbers and clock data.
- Attackers reconstructed vulnerable private keys offline and executed automated sweeps on July 30, 2026, with public analyses giving contested loss totals of roughly 594 BTC (~$38M) and about 1,082.65 BTC (~$70M) depending on the addresses and methodology counted.
- Block’s engineering team traced the operator’s activity through logs at a blockchain-services provider and shared findings with authorities while the stolen funds were consolidated into a few addresses that have largely not moved.
- Coinkite released emergency firmware updates and warned that patched firmware does not fix already-generated seeds, urging affected users to create new seeds on fixed devices and migrate funds after verifying receiving addresses with small test transfers.
- The incident has renewed calls for stronger self-custody practices, including using BIP-39 passphrases or dice-generated seeds, multisignature setups, and splitting holdings to limit single-signature exposure.