0x6595e3c76595…6595e3ca

ConfirmedSecurity716 vB99 sat/vB4 min decode

Coldcard Entropy Flaw Drives Bitcoin Losses Past $111M as Red Team Flags 85 Critical Bugs

Coinkite's Coldcard entropy flaw has drained 1,719 BTC (~$111M) with potential losses reaching 2,055 BTC (~$130M) as of August 8, 2026, while a parallel Bitcoin Red Team audit flagged 4,962 issues including 85 critical bugs across 390 open-source repositories in 27.5 hours.

Bitcoin Hacks Hit $130M as Red Team Finds 85 Bugs [2026] - shattered.io
WitnessBitcoin Hacks Hit $130M as Red Team Finds 85 Bugs [2026] - shattered.ioAI-generated

Outputs

  1. Galaxy Research confirmed 1,719 BTC (~US$111M) stolen as of August 8, 2026, with potential losses up to 2,055 BTC (~US$130M).

  2. The Coldcard entropy flaw traces to a March 2021 firmware release, present in code for over five years.

  3. Bitcoin Red Team logged 4,962 findings across 390 repositories in 27.5 hours, including 85 critical and 635 high-severity bugs.

  4. BTCPay Server shipped version 2.4.2 on August 7, 2026 to fix a separate critical vulnerability affecting Lightning node credentials.

  5. Coinsbuy lost more than US$8M in a cross-chain attack on August 9, 2026 across Tron and Ethereum networks.

$111M and Counting: A Five-Year-Old Bug Burns Bitcoin's Cold Storage

A firmware-level entropy flaw in Coinkite's Coldcard hardware wallets has drained 1,719 BTC, roughly $111 million, with potential total losses reaching 2,055 BTC, or about $130 million, according to Galaxy Research on-chain analysis dated August 8, 2026.

Coinkite CEO NVK told affected users directly: "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further."

What does the Coldcard entropy flaw actually entail?

Investigators traced the vulnerability to a March 2021 firmware release that relied on a software-based random number generator instead of a hardware entropy source. That cut effective seed randomness to roughly 40 to 72 bits, far short of the 128 to 256 bits users expect from cold-storage devices.

Security researcher Garrett framed the mechanics plainly in CBC coverage: "The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered."

Affected hardware spans Coldcard Mk3, Mk4, Mk5, and Q models, with some Mk2 units also implicated depending on firmware version. The weakness sat in publicly reviewable, open-source code for more than five years before weaponization at scale.

How large are the confirmed losses?

Forensics escalated steadily over ten days:

  • Late July: ~500 wallets and 1,324 UTXOs compromised, totaling ~594.5 BTC
  • Aug 2: 4,500 Bitcoin addresses hit, losses near $89 million
  • Aug 3: KuCoin's incident desk called it the largest Bitcoin theft of 2026
  • Aug 8 (confirmed): 1,719 BTC, ~$111 million
  • Aug 8 (ceiling): up to 2,055 BTC, ~$130 million

Galaxy Research confirmed the August 8 figures. The attacker ran automated sweeps completing in 25 to 41 minutes against hundreds to thousands of addresses at a time, per KuCoin's flash reporting.

What did the Bitcoin Red Team audit find?

In parallel, a volunteer initiative called Bitcoin Red Team, led by developer Calle alongside AnchorWatch CEO Rob Hamilton, completed an AI-assisted audit of open-source Bitcoin infrastructure. Within 27.5 hours the team logged 4,962 findings across 390 repositories, including 85 critical and 635 high-severity bugs.

Calle described the pace in stark terms to Cointelegraph: "We're averaging on the order of 1 critical exploit per hour per person." He added later: "27.5 hours in, we've filed 4,962 findings across 390 projects."

Even excluding medium and low-severity noise, the count undercuts the "don't trust, verify" assumption underpinning Bitcoin self-custody: enough reviewers and yet a critical bug persisted for five years.

What is the broader exploit wave hitting Bitcoin infrastructure?

Three incidents now define August 2026:

  • Coldcard firmware flaw (firmware patch shipped; no formal CVE issued)
  • BTCPay Server critical vulnerability, advisory published Aug 7, fixed in version 2.4.2, capable of draining connected Lightning nodes via exposed macaroon credentials
  • Boltz Lightning submarine-swap service disruption

None involve Bitcoin's base protocol. Each targets the surrounding software, firmware, and services users actually touch.

A separate cross-chain attack hit exchange Coinsbuy on August 9, draining more than $8 million across Tron and Ethereum networks, beginning with a 5 USDT probe before emptying eight TRON wallets of roughly $6.04 million in stablecoins, per blockchain investigator BlockWatchdog and CoinDesk reporting.

What is the business and operational consequence?

Coinkite has shipped a firmware patch and published an entropy remediation disclosure, emphasizing the bug lives in firmware-level random number generation rather than in Bitcoin's cryptographic primitives (SHA-256, ECDSA). That distinction preserves protocol-level confidence while doing nothing for affected users.

Wallet activity on the Bitcoin network hit a 2026 high as holders rushed to check and migrate funds, per KuCoin's flash desk, a pattern consistent with defensive wallet churn.

Competitor wallet makers, particularly Ledger and Trezor, which rely on certified secure element chips or dedicated hardware entropy sources, now have a clear marketing opening to lean into "certified hardware RNG" messaging.

The Coldcard incident will likely accelerate pressure on hardware wallet vendors to adopt formal CVE tracking and to fund ongoing security audits, and consumer protection regulators in jurisdictions already scrutinizing crypto custody practices will not ignore a nine-figure loss tied to a marketed security feature.

via coindesk.com (Original)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles