Between blocks 960,778 and 960,792, about two and a half hours of chain time, 218 transactions carried 388.9 BTC out of 462 addresses and into wallets their owners had never seen. Galaxy Research's Alex Thorn clocked the burst at 13.8 transfers per block, roughly 45 times the baseline rate for the addresses involved. Nobody was breached in the sense that word usually carries. No phishing link, no malware, no seed phrase photographed on a kitchen table. The private keys behind those addresses were guessable from the moment they were created, and somebody finally finished guessing.
That was the fourth organized wave in a week against Coldcard hardware wallets. Cumulative losses now sit above 1,100 wallets and somewhere close to $90 million, and the waves keep arriving because the underlying flaw has no expiry date.
Seventy-Two Bits and Why That Number Decides Everything
Coinkite's own security advisory reads less like a bug report and more like a chain of small failures that each looked survivable in isolation:
- The device ships with a hardware true random number generator, which is precisely what a buyer is paying for over a software wallet.
- A code path inside libngu, the cryptographic library, fell back to a software pseudo-random generator called Yasmarang when the TRNG contribution failed to land.
- Nothing surfaced the fallback. The device displayed a normal seed, the user wrote down twelve or twenty-four words, and the setup screen looked identical either way.
- Seeds generated on Mk4, Mk5 and Q units before the fixed releases carried roughly 72 bits of entropy in place of the intended 128. Mk2 and Mk3 units on firmware 4.0.1 through 4.1.9 fared worse still.
The distance between 128 bits and 72 bits reads as a 44% haircut, which badly understates it. Entropy is exponential, so the search space shrank by a factor of about 72 quintillion. A 128-bit seed sits beyond the reach of every computer that will ever exist. Seventy-two bits sits inside the budget of anyone willing to rent GPUs for a few weeks.
That distinction is the whole story, and it is also why the usual reassurances do not apply. Firmware updates protect seeds generated after the patch. Every seed generated before it stays exactly as guessable as it was on day one, forever, on any device, in any wallet software, with any balance.
The Two Exits Most Coverage Skipped
Nearly every write-up of this closed on the same instruction: move your coins immediately. Correct, and incomplete. The advisory documents two conditions under which an affected device still produced a sound seed, and both describe large groups of real users.
The first is dice. Users who entered 50 to 98 private rolls through the Add Dice Rolls flow had that input hashed into the seed alongside the device's own contribution, and the dice alone supply at least 128 bits. Those seeds were never weak. The second is a BIP-39 passphrase. A strong, unique passphrase creates an independent barrier that reduced seed entropy does not touch, so an attacker grinding the keyspace lands on an empty wallet unless they also recover the passphrase.
Read those two exemptions together and the pattern is uncomfortable. The users holding compromised keys are the ones who trusted the hardware to do the single job it advertises. The users who added friction, who did not believe the marketing, who rolled dice on a kitchen counter like it was 2014, are fine. Security theater got punished; security paranoia got paid.
The Waves Arrive in Batches for a Reason
Four waves in a week, each dense and brief, each separated by quiet days. That rhythm is diagnostic. Continuous scanning of the blockchain for weak keys would produce a steady trickle of thefts. Bursts of 200-plus transactions inside a fifteen-block window point to attackers grinding candidate seeds offline, accumulating a batch of confirmed hits, and then sweeping the entire batch at once to minimize the warning any single victim gets.
Which means there is no all-clear coming. Each completed batch is a new wave, the keyspace keeps yielding, and the economics improve every month as hardware gets cheaper. The one deadline that matters already passed, for every affected user, on the day their device generated the seed.
The LeveX Take
The industry has spent a decade telling people that self-custody removes trust from the equation. It relocates trust. A hardware wallet asks you to trust a build pipeline, a random number generator you cannot inspect, and a firmware release process, and it gives you no way whatsoever to verify any of them. You cannot look at a seed phrase and determine whether it came from 128 bits or 72. Neither can a security researcher, in the general case. Entropy is the one layer of the custody stack that produces no evidence of its own quality, which is why this flaw sat undetected across years of firmware releases while the devices were being reviewed, torn down and praised.
That is the argument for treating verifiable claims as a separate category from credible ones. LeveX publishes 1:1 Proof of Reserves through a Merkle tree specifically so users can check a balance claim rather than accept it, currently 111% on BTC, 149% on ETH and 160% on USDT. The point is not that custodial storage beats a hardware wallet. The point is that a claim you can test yourself belongs in a different risk bucket from a claim you can only believe, and most people running self-custody have never asked which bucket their entropy sits in.
There is a market wrinkle here that has gone almost entirely unremarked. These sweeps are forced supply, arriving in concentrated bursts, at times that are visible on-chain the moment they begin, into a Bitcoin market already trading with thin summer depth around $63,000. Roughly 389 BTC in one afternoon is not a market-moving figure by itself. Four waves in a week, with stolen coins that eventually need laundering through mixers and OTC desks, is a supply overhang with a schedule nobody publishes but everyone can watch.
What a Compromised Seed Costs After You Move
The instinct after reading a story like this is to move funds and consider the matter closed. Moving funds ends the exposure of that balance and nothing else. Every address ever derived from an affected seed remains permanently reachable, which matters for anyone who reused an address for payroll, donations, an exchange withdrawal whitelist, or a multisig cosigner key that is still live. Audit what that seed ever touched, and assume the attacker has more patience than you do.
Watch two things over the coming weeks: whether wave five arrives on the same batched cadence, which would confirm the offline grinding model, and whether any other hardware vendor issues an entropy advisory. A silent PRNG fallback in a shared cryptographic library is rarely a one-vendor problem.
Traders who want exposure to Bitcoin without holding the key material can trade it on spot or perpetual futures at LeveX, and the Crypto in a Minute series covers the custody and key-management basics this incident just made expensive to ignore.
