A total of 594.48 BTC worth approximately $38.2 million - with BTC trading around $64,324 - vanished from roughly 500 separate wallets in just 25 minutes. Between 01:31 and 01:56 UTC on Friday, July 31, 2026, the attacker split the theft across 1,324 UTXOs via 500 transactions swiftly confirmed within a three-block window on the network.
AnchorWatch CEO Rob Hamilton noted that all the drained addresses were single-signature wallets. Out of the stolen total, the attacker immediately consolidated 562 BTC into a single deposit address, where the funds have not moved since. Notably, the wave of hacks coincided with an alert from Canadian Coldcard maker Coinkite, which urged all Coldcard Mk3 users who generated seeds on firmware versions 4.0.1 through 5.0.3 to move their funds immediately.
While there is no definitive public evidence directly tying the 594 BTC heist to the Mk3 bug, the timing of both events closely aligns.
Why the Randomness Engine Was Bypassed
A report from Block identified the root cause: a bug in Coldcard’s firmware. A build setting within the system instructed the device to bypass its built-in hardware randomness generator. This was compounded by a supporting library that merely checked for the presence of the setting rather than verifying whether the feature was actually enabled.
Without the primary randomness engine, the key generation process silently fell back to backup software seeded by the chip’s serial number and clock registers. Neither of these elements is a secret. The serial number is merely factory metadata, and clock values are easily measurable timestamps. Block traced the bug back to a code commit on March 1, 2021, which shipped in firmware 4.0.0 that same month.
The vulnerability’s exposure extended far beyond standard wallet seeds. The same flawed generator also produced private keys for paper wallets, seed split masks, device clone keys, and Key Teleport transfers.
Brute-Force and a Single Layer of Defense
Wizardsardine CEO Kevin Loaec hypothesized that the issue stemmed from the low entropy of the flawed random number generator. He suggested the attacker used AI scripts to brute-force limited BIP-84 derivation paths, explaining why some wallets were only partially drained rather than completely emptied.
Coinkite promised a formal technical report, which remains unpublished at the time of writing, but confirmed that Coldcard Mk4, Q, and Mk5 series are unaffected based on initial analysis. For Mk3 users, the advice is clear: generate a new seed on an unaffected device, verify backups, send a small test transaction, and immediately transfer the remaining full balance.
Holders who secured their wallets with a BIP-39 passphrase from the start faced minimal risk. Coinkite emphasized that passphrases function independently of the device PIN. This single additional layer ultimately determined whether wallet assets were wiped out or remained safe.
Reported by CoinDesk.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




