rewrite this content using a minimum of 1200 words and keep HTML tags
A suspected attack targeting Bitcoin addresses created using 1,367.05 BTC drained 1,367.05 BTC, worth approximately $88.6 million, from 4,585 addresses, according to Galaxy Research. This development came after Coinkite announced an entropy flaw in older firmware versions used to generate seed phrases and urged affected users to move their assets quickly.
The flaw lies in how certain Coldcard firmware versions generated seed phrases with lower-than-required randomness, allowing an attacker to narrow the wallet brute-force search space significantly. Coinkite stated that new firmware versions have fixed the bug for future seed generation processes, but cannot “fix” weak seeds that were created previously.
COLDCARD Mk3 Security Advisory
If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.
Mk4, Q and Mk5 are not affected based on our early analysis.
Read the advisory and migrate carefully:https://t.co/3vgPHOjMS7
— COLDCARD (@COLDCARDwallet) July 30, 2026
Galaxy Flags Suspected Attack Waves
Galaxy Research stated that it detected three suspected attack waves targeting addresses believed to have been generated using Coldcard devices. The company emphasized that this analysis is based on blockchain data, so it cannot independently prove that every address drained was created from a weak-entropy seed. However, the timing of the transactions, the wallet scanning pattern, and the way funds were consolidated mean the incident is no longer just a technical warning from the manufacturer, but has become an ongoing security incident for hardware wallet users.
According to data published by Galaxy Research, the three suspected waves include:
Wave 1: Took place from 01:10 to 01:51 UTC on July 30, draining 1,082.6532 BTC from 1,195 addresses.Wave 2: Took place from 04:54 to 08:36 UTC on July 31, draining 76.1616 BTC from 1,478 addresses.Wave 3: Spanned from July 31 to August 1, affecting 1,912 addresses and taking 208.2377 BTC.

Three suspected Coldcard attack waves. Source: Galaxy Research
In total, these three waves involved 4,585 addresses and 1,367.05 BTC. Galaxy stated that the first two waves had fairly similar transaction patterns and could have been executed by the same party, although this has not been confirmed. The third wave showed more differences, which might reflect an adjusted tool or a different attacker targeting the same group of vulnerable wallets.
Alex Thorn, head of research at Galaxy, said the attacks appear to still be ongoing and urged affected users to move their assets as soon as possible if they have not yet migrated. According to him, the BTC taken in the three main waves remained in addresses controlled by the attacker and had not been moved at the time of the analysis. Galaxy also noted that the drained coins had been dormant for an average of 3.18 years, with a median of 3.55 years, indicating that many victims may be long-term holders.
Coinkite Explains the Entropy Flaw
Coinkite, the company behind Coldcard, stated that the flaw lies in how certain firmware versions generated wallet seed phrases. In its technical backgrounder, the company explained that the issue originated from a 2021 code migration, when the seed generation process was transitioned to a new random-number call route but inadvertently relied on a software pseudo-random number generator fallback instead of the intended hardware-backed source of randomness.
As a result, some seed phrases could be generated with lower entropy than expected. In crypto wallets, entropy represents how unpredictable a seed phrase is: lower entropy means a smaller brute-force search space, giving attackers a higher chance of discovering the seed under certain conditions.
For Mk2/Mk3, the affected group consists of devices that generated seeds using firmware 4.0.1–4.1.9; Coinkite estimates the effective search space for these seeds could be only around 40 bits under current attack conditions. For Mk4, Mk5, and Q, devices had additional entropy from secure elements, but affected seeds could still reach only about 72 bits, below the 128-bit threshold commonly considered a safe baseline.
Coinkite said the flaw has been fixed in newer firmware versions, including Mk2/Mk3 4.2.0+, Mk4/Mk5 standard 5.6.0+, Q standard 1.5.0Q+, Mk4/Mk5 Edge 6.6.0X+, and Q Edge 6.6.0QX+. The company also stated that TAPSIGNER, OPENDIME, and SATSCARD are not affected.
Who Is at Risk
The group at highest risk includes users who created seed phrases using affected Coldcard firmware versions and subsequently stored Bitcoin on addresses generated from those seeds. For Mk2/Mk3, the most notable group involves devices that created seeds using firmware 4.0.1–4.1.9, especially if users did not manually add sufficient entropy via dice rolls or use a strong BIP-39 passphrase.
According to Coinkite, users may have significantly reduced their risk if, during seed creation, they added at least 50 independent and private dice rolls. The company stated that 50–98 rolls can bring a seed to a minimum of 128 bits of entropy, while 99 or more rolls provide approximately 256 bits of dice entropy. Conversely, those who relied solely on the device’s flawed seed generation route may lack this protective layer.
The incident drew further attention when several victims claimed their assets were held in cold storage. Jonathan Goodman, a Canadian author and verified X account, stated that 18.25245043 BTC, worth over 1.6 million CAD, was drained from wallets associated with a Coldcard device kept in a safety deposit box and never connected to the internet. While this claim has not been fully independently verified, it illustrates why this incident is particularly sensitive for hardware wallet users.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part’s nerdy, but here’s… pic.twitter.com/Lf9kJv9Jo4
— Jonathan Goodman 🇨🇦 (@itscoachgoodman) August 1, 2026
Why Updating Firmware Is Not Enough
The most critical point in Coinkite’s warning is that new firmware only fixes future seed generation. It cannot add entropy to an already generated seed phrase. If the original seed was weak, addresses derived from that seed remain at risk.
This makes the incident different from many standard security patches. A user can update their device to safer firmware but remain unprotected if their Bitcoin currently resides on addresses created from an old seed. In its technical backgrounder, Coinkite also emphasized that hashing or deriving addresses from a weak seed does not introduce new randomness; cryptographic functions merely process input data and cannot compensate for entropy that was missing from the start.
This is why Galaxy’s on-chain findings add urgency to the situation. The suspected sweep waves appear to target old addresses that had been dormant for years, rapidly consolidating funds into collector addresses. If this analysis is accurate, the attacker does not need physical access to the victim’s device.
What Users Should Do Now
Coinkite recommends that users first check whether their current seed was created on an affected Coldcard firmware version. For Mk2/Mk3, the group needing the most attention includes those who generated seeds using firmware 4.0.1–4.1.9, particularly if dice rolls were not added during setup.
Following Coinkite’s guidance, affected users should update their devices to patched firmware and then generate a completely new seed. The company also recommends adding personal entropy via dice rolls during creation, with a minimum of 50 rolls to protect against this type of flaw and 99+ rolls for a larger safety margin.
After generating a new seed, users must transfer their assets away from addresses derived from the old seed. This process should be executed carefully, including a small test transaction before moving the entire balance. Old backups should also be retained until users confirm that all assets have arrived safely in the new wallet.
The urgency is even higher for wallets that still hold BTC on addresses that may have been generated from an affected seed. Galaxy’s analysis suggests the attacker may have scanned the vulnerable key space and swept funds immediately upon finding an address with a balance. For self-custody users, the core takeaway of this warning is that new firmware only protects seeds generated moving forward; assets residing on old seeds must still be migrated if that seed falls into the risk group.
and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website [http://defi-daily.com] and label it “DeFi Daily News” for more trending news articles like this
Source link









:max_bytes(150000):strip_icc()/Health-GettyImages-1475073083-0e23f86f9e544712b6a75da9cff59401.jpg?w=120&resize=120,86&ssl=1)







