So how do you rob thousands of hardware wallets without touching one? That's the question the Bitcoin world has been asking since July 30th, when an unknown attacker began emptying ColdCard wallets — starting with roughly 594 BTC from about 500 wallets in the opening 25-minute sweep, then continuing across three further waves. The running total now stands at roughly 1,816 BTC, worth about $116 million, drained from more than 5,200 addresses. The answer has nothing to do with clever hacking of the network — and everything to do with a single word: randomness.

What actually happened

Every Bitcoin wallet begins life as a seed phrase — those 12 or 24 words you write down when you set up a device. Those words aren't chosen; they're meant to be drawn at random from a pool of possibilities so astronomically large that guessing someone's seed should be about as likely as picking one specific atom out of the entire planet. That randomness — engineers call it entropy — is the real foundation of Bitcoin security. Not the metal case. Not the PIN. The randomness.

The ColdCard, made by Canadian firm Coinkite, is one of the most respected hardware wallets in the world — partly because it contains a dedicated chip whose only job is generating true randomness. But a firmware bug, sitting quietly in the code since March 2021, meant that on affected devices that chip was being skipped. Seeds were instead being built from predictable ingredients. The lock looked identical. The key was guessable.

Five years later, someone noticed. They worked out which wallets had been created with weak randomness, identified the ones holding the most Bitcoin, and emptied them — methodically, largest first.

25 min

That's how long it took the opening wave to sweep ~594 BTC (about $38 million USD at the time) from roughly 500 wallets on July 30th, 2026 — the first of four waves that followed, none of which required the attacker to touch a victim's device or computer.

Who lost nothing — and why it matters

Here's the part worth pinning to your wall: not everyone with an affected ColdCard was robbed. Users who supplied their own randomness when creating their seed — instead of trusting the device to do it — were untouched. So were users protecting their wallet with an added passphrase, an extra secret the bug couldn't reach.

"Don't trust, verify" is the oldest saying in Bitcoin. Most of us apply it to the money supply. This hack proved it applies to your own hardware too.

At Bitcoin Bendigo, the way most of us do this is with entropy pills — a jar of small tokens covering the seed word list. Instead of letting the device pick your words, you shake the jar and draw them yourself, one by one, and enter them into the wallet (the device helps with the final word, which acts as a built-in checksum). Your randomness comes from your own hands and the physics of a shaken jar — something no firmware bug can ever compromise. Rolling dice achieves the same thing, and it's what the official security advisories reference, but let's be honest: the pills are easier, and far more likely to actually get used.

Our group keeps a shared jar that members borrow at meetups for exactly this purpose. We suspect demand for these is about to go through the roof everywhere — so we're 3D-printing extra sets from an open-source design for members who'd like their own. Ask about them at the next meetup.

If you own a ColdCard: four steps

1️⃣

Update your firmware now

Coinkite has released fixed firmware for every model — 4.2.0 for Mk2/Mk3, 5.6.0 for Mk4/Mk5, and 1.5.0Q for the Q. Update every device you own, regardless of how your seed was made. Mk3 owners in particular should treat this as urgent — entropy on affected Mk3 devices dropped to as little as ~40 bits, weaker than the ~72 bits on Mk4/Mk5/Q.

2️⃣

Know how your seed was born

This is the crucial question. If you supplied your own entropy (pills or dice) or use a passphrase, the advisory does not consider you at risk. If the device generated your seed on affected firmware, treat it as compromised.

3️⃣

Migrate — a patch can't fix a burned seed

Updating firmware does not rescue a seed that was created with weak randomness. If yours was device-generated on affected versions, create a brand-new seed on patched firmware — with your own entropy this time — and move your coins to it.

4️⃣

Never re-use the old seed

Don't import a compromised seed into another wallet or device — the weakness lives in the seed itself, forever, wherever it goes. Retire it completely.

For larger holdings: the multi-vendor multisig standard

There's one more lesson here, and it's for anyone securing serious value. This hack was survivable by good habits — but it was only possible at all because each victim's Bitcoin depended on one device from one manufacturer. There's a setup that removes that single point of failure entirely: multisig.

What multisig means — and why mixed vendors matter

A multisig wallet requires signatures from multiple separate devices — say, 2 of 3 — before coins can move. If those devices come from different manufacturers, then no single company's bug, however severe, can ever cost you your Bitcoin. An attacker would need two independent vendors to fail inside the same wallet at the same time.

It's more setup, more discipline, and one extra thing to back up properly (ask us about "output descriptors" at a meetup). It's not the beginner's first step — a single hardware wallet with your own entropy and a passphrase is already excellent security. But for larger holdings, multi-vendor multisig is where the gold standard now sits, and July 30th is the reason why.

The bigger picture

It would be easy to read this story as "Bitcoin got hacked." It didn't. Bitcoin's cryptography wasn't broken, the network wasn't touched, and the price barely blinked. What failed was one implementation of one step, in one product line. And the defence that worked wasn't exotic or expensive — it was a jar of printed tokens, ten extra minutes at setup, and healthy scepticism. Tools available to every single person reading this.

Self-custody is still the point of Bitcoin. This week just reminded us that it's a skill, not a purchase — and skills are exactly what a community is for.

Come and dig into this further.

Our next meetup is Monday 14th September 2026, 6:00pm – 9:00pm. In person in Bendigo or join us remotely. All welcome — no experience needed.

Find out more →