A security failure tied to Coldcard has rattled one of Bitcoin’s most deeply held assumptions: that hardware wallets offer the final line of defense for self-custody. On July 30, 1,755.95 BTC, worth more than $110 million at market prices, was drained in bulk from thousands of addresses. Most of the funds were moved about 30 hours before an official warning appeared.
According to PANews, the problem did not come from an external breach of the devices themselves. It came from a flaw embedded in the wallet’s own foundation. The issue traces back to Coldcard’s v4.0.1 firmware update released in March 2021, when the development team mistakenly used a pseudo-random number generator, or PRNG, instead of a true random number generator, or TRNG, during private key creation.
That distinction is central to cryptographic security. True randomness sourced from hardware noise is designed to be unpredictable. A software PRNG, by contrast, relies on a more limited entropy pool whose underlying structure may be modeled or inferred. PANews said this gap gave attackers a path to systematically brute-force and reconstruct private keys tied to affected addresses, putting keys generated under the vulnerable firmware at risk for five years.
Attack waves moved fast and at scale
Galaxy Research said the first two attack waves emptied 1,196 victim addresses in just 41 minutes. More than $70 million was transferred before Coldcard issued its emergency warning, roughly 30 hours after the core fund movements had already begun.
The theft then continued in multiple rounds. In the fourth observed wave, attackers were emptying wallets at a rate of as many as 13.8 transactions per block. They also used replace-by-fee, or RBF, to improve confirmation priority and leave affected users with little time to react.
The victim profile adds another layer to the incident. Data cited in the report showed the stolen Bitcoin had been dormant for an average of 3.18 years, with a median of 3.55 years. Many of those hit appear to have been long-term holders who entered the market earlier and trusted cold storage as a durable security model.
AI showed up on both sides of the fight
PANews said the case also highlighted how AI is now being used in both offensive and defensive security work. On the attack side, the report described AI-assisted bulk private-key cracking as evidence that automated cybercrime is becoming easier to execute, especially against aging codebases.
On the defense side, the speed gains were hard to ignore. After the attacks became widely visible, a Reddit community developer used Claude Code to run a full scan of Coldcard’s open-source firmware and pinpointed the hidden PRNG logic flaw in just eight minutes.
The result was then cross-checked in an offline environment using Zhipu GLM 5.2 and the open-source model Kimi K3, both of which reproduced the same finding.
Galaxy Research’s security team also used Chinese open-source AI tools to analyze 218 RBF transactions from the fourth wave of attacks and identify the second-hop destination addresses tied to the fund movements. The broader takeaway from these AI-assisted investigations was that automated code auditing may sharply reduce the exposure window for zero-day vulnerabilities.
On-chain flight to safety accelerated
The fallout quickly spread beyond Coldcard users. CryptoQuant data showed Bitcoin daily active addresses jumped from 645,000 on July 30 to nearly 1 million on July 31, the highest single-day level since Dec. 10, 2024.
On the same day, transfers involving less than 1 BTC rose to their highest level since November 2022. About 39,600 BTC moved on-chain, only around 300 BTC below the record set in the days following FTX’s bankruptcy filing.
CryptoQuant head of research Julio Moreno said the Bitcoin community had not seen such an intense wave of self-directed migration since the collapse of FTX.
Single-point custody risk is back under scrutiny
Binance founder CZ said software written by humans will inevitably carry bugs. He noted that Trust Wallet had also suffered losses of $12 million years ago because of a PRNG flaw. His conclusion was straightforward: users should not place blind trust in a single hardware device or an old dormant wallet, and should instead consider diversification and multisig coordination to reduce single-point failure risk.
Bloomberg senior ETF analyst Eric Balchunas made a similar point from another angle. He said it was an obvious warning sign that a company with only about five people could be responsible for storing such an important share of Bitcoin wealth. In his view, larger organizations such as Coinbase and Ledger have stronger security budgets and operating capacity, while spot Bitcoin ETFs offer another route for investors who want custody arrangements backed by large, professional, regulated financial institutions and relatively low management fees.
Joe Burnett, vice president at Bitcoin treasury company Strive, said self-custody will remain part of the ecosystem, but the Coldcard theft will permanently change how users think about it. Protecting a large Bitcoin position with a single key generated by one hardware wallet, he said, creates too much concentration risk. He added that the failure of one custody model does not invalidate Bitcoin itself, but it does push the market toward better tools, higher standards, and more resilient custody structures.
More attention turns to distributed storage setups
Stacks co-founder Muneeb Ali outlined one possible allocation model. He suggested putting 20% to 30% of BTC into ETFs such as BlackRock’s spot Bitcoin ETF, IBIT, for professional custody and regulatory protection; 40% to 50% into multisig arrangements similar to Casa’s three-key model, with keys split across a security firm, a mobile device, and a hardware wallet; and another 20% to 30% into more advanced self-managed setups that combine different hardware wallets and different entropy sources.
The direction of travel is clear in the report. Cross-vendor multisig, multi-party computation, social recovery wallets built on smart contracts, and even ETFs are increasingly being discussed as ways to avoid a full collapse caused by a single point of failure.
The Coldcard incident may stand as a turning point in crypto security. What it punctured was not only one firmware implementation, but also the broader belief that offline storage alone is enough to guarantee safety.

