A security failure tied to Coldcard has put fresh pressure on the idea that offline Bitcoin storage offers dependable protection. On July 30, 1,755.95 BTC was drained from thousands of addresses, worth more than $110 million at market prices. By the time Coldcard issued a public warning, the attacker had already completed the main transfers roughly 30 hours earlier.

The breach did not come from an external break-in. The core problem was a long-standing flaw inside the wallet’s firmware, and its impact quickly spread beyond the affected users. After the incident, on-chain small-value Bitcoin transfers surged, while some self-custody holders shifted assets to large exchanges or spot Bitcoin ETFs.
A firmware mistake from March 2021 sat undetected for years
The report traced the issue back to Coldcard’s v4.0.1 firmware update released in March 2021. During private-key generation, the development team mistakenly called a software pseudo-random number generator, or PRNG, instead of relying on a hardware true random number generator, or TRNG.
That distinction sits at the center of cryptographic security. A hardware-based random source depends on physical noise and is not predictable in the same way, while a software PRNG has a limited entropy pool and can expose patterns that become easier to model. In this case, the flaw opened a path for an attacker to brute-force and reconstruct private keys for affected addresses in a programmatic way.
The result was severe: wallets created under the affected firmware were left at risk for five years. The incident also challenged a common assumption in Bitcoin storage, showing that a dedicated hardware device cannot fully remove supply-chain risk or logic errors embedded in code.
The theft was fast, repeated and heavily automated
On-chain traces pointed to a high level of automation. Galaxy Research said that in the first two waves of attacks, the attacker emptied 1,196 victim addresses in just 41 minutes and moved more than $70 million before Coldcard’s emergency security warning went out, with the key transfers made about 30 hours ahead of that notice.
The campaign then continued in multiple rounds. In monitoring tied to the fourth wave, the attacker was seen draining wallets at a rate of as many as 13.8 transactions per block. The use of Replace-By-Fee, or RBF, gave those transfers a better chance of being mined first and left victims with little room to react.
The victim profile added another layer to the story. The stolen BTC had an average dormancy period of 3.18 years, with a median of 3.55 years, suggesting many affected users were long-term holders who had relied on cold storage for years.
AI was cited on both sides of the incident
The report said the case underscored growing concern around the weaponization of AI. Attackers were described as using AI to scale private-key cracking, a sign that automated cybercrime could become easier to execute and that aging codebases may face a more persistent class of threats.
At the same time, AI also accelerated the response. After the attack became widely known, a Reddit community developer ran a full scan of Coldcard’s open-source firmware using Claude Code and identified the hidden PRNG logic flaw in eight minutes.
The result was then cross-checked in an offline environment with Zhipu GLM 5.2 and the open-source model Kimi K3, both of which reproduced the finding. Galaxy Research’s security team also used open-source Chinese AI tools to cluster 218 RBF transactions from the fourth attack wave and identify the second-hop destination addresses for the stolen funds.

That sequence of work pointed to a narrower exposure window for zero-day flaws when automated code review tools are part of the process. In practice, it raised the importance of integrating real-time AI auditing into hardware wallet and smart contract development.
Users moved coins as on-chain activity neared post-FTX stress levels
Market fallout showed up quickly on-chain. CryptoQuant said daily active Bitcoin addresses rose from 645,000 on July 30 to nearly 1 million on July 31, the highest single-day level since Dec. 10, 2024.
Transfers involving less than 1 BTC also climbed to their highest level since November 2022. About 39,600 BTC moved on-chain that day, only around 300 BTC below the peak recorded days after FTX filed for bankruptcy.
CryptoQuant head of research Julio Moreno said the Bitcoin community had not faced such an intense self-preservation migration since the collapse of FTX. Once users begin to doubt even offline hardware wallets, the structure of crypto security itself comes under review.
Attention shifts to diversification, multisig and ETF custody options
Binance founder CZ said software bugs are unavoidable as long as code is written by humans. He pointed to a past Trust Wallet loss of $12 million tied to a PRNG flaw and argued against relying too heavily on a single hardware device or an old dormant wallet. In his view, diversified allocation and multisignature coordination offer a stronger way to reduce single-point failure risk.
Bloomberg senior ETF analyst Eric Balchunas said it was a clear warning sign that a company with a team of roughly five people was responsible for such an important Bitcoin storage function. He said larger organizations such as Coinbase and Ledger have stronger advantages in security investment and operating capacity, even if users may bear higher transaction-related costs. He also described spot Bitcoin ETFs as another option, giving investors access to the custody structure of large, professional and regulated financial institutions while keeping management fees low.
Joe Burnett, vice president at Bitcoin DAT treasury firm Strive, said self-custody will remain part of the market, but the Coldcard theft will permanently alter confidence in that model. A single key generated by one hardware wallet and used to protect a large amount of BTC, he said, carries too much concentration risk. He added that as long as Bitcoin itself remains secure, the failure of one custody method does not invalidate the underlying monetary system and may instead push the market toward better tools, higher standards and more resilient custody frameworks.
Stacks co-founder Muneeb Ali laid out a diversified approach: 20% to 30% of BTC in an ETF such as BlackRock’s IBIT, 40% to 50% in a multisig setup similar to Casa’s three-key model with keys spread across a security provider, a mobile device and a hardware wallet, and 20% to 30% in a more advanced self-managed structure that combines different hardware wallets and different entropy sources.
The Coldcard case has already broken the simple idea that offline storage alone equals safety. What follows is likely to be a wider move away from dependence on a single device and toward architectures built around multisig, MPC, social recovery wallets and regulated investment vehicles.

