$100M DRAINED From Crypto's Safest Wallet!
Over $100 million in Bitcoin was drained from Cold Card hardware wallets due to a 5-year-old firmware bug that weakened the random number generation used to create seed phrases. The bug reduced security from 128 bits to 40 bits on older models, making seeds guessable by ordinary laptops, though users who added extra security measures like dice rolls, passphrases, or multi-sig remained unaffected.
Summary
Between July 30-August 3, 2026, attackers drained approximately $100 million in Bitcoin from thousands of Cold Card hardware wallets through an automated attack that didn't require accessing the physical devices. The root cause was a firmware bug introduced on March 1, 2021, when Cold Card migrated to a new cryptography library called Libangu. A single line of code checked whether a hardware randomness setting existed rather than whether it was enabled, causing the firmware to skip the hardware random number generator and fall back to a weak software generator called Yasmarang that relied on the chip's serial number and startup timing—values an attacker could guess or enumerate. On Cold Card MK2 and MK3 devices, this reduced seed phrase security from 128 bits to approximately 40 bits (about one trillion possibilities), small enough for a laptop to crack offline in hours. Newer MK4, MK5, and Q models retained around 72 bits due to additional randomness from secure chips. The bug went undetected for five years because the hardware randomness generator was still present and functional elsewhere in the firmware, passing internal reviews, but the specific code path generating seed phrases bypassed it entirely. Victims included people who followed all recommended security practices, stored devices offline in safes and vaults, and never touched their wallets—some losing funds that had sat untouched for over three years. The attack affected not just seed phrases but also paper wallet keys, seed XR split masks, device cloning keys, USB encryption keys, and other sensitive cryptographic material. Three groups survived completely unaffected: users who rolled physical dice (at least 50 rolls) during setup to inject real randomness, users who added a strong BIP39 passphrase, and users in genuine multi-signature setups. No multi-sig wallets or Taproot addresses were hit, indicating the attacker's script was narrowly scoped. Cold Card CEO NVK responded quickly, taking full accountability and advising users to move funds immediately, but updating firmware only prevents new bad keys—it cannot fix already-generated compromised seeds. Cold Card's deliberate 120-day customer record purge for privacy prevented mass notification of affected users. The incident reflects a broader pattern in crypto: randomness bugs are recurring failure points across the industry that go undetected because weak randomness produces no visible symptoms. Similar bugs have caused major losses—the 2023 Milk Sad bug ($900K+), the 2022 Profanity vanity tool ($160 million), Trust Wallet's 2022-2023 browser extension flaw, and the July 2026 Ill Bloom bug ($5M+ across blockchains). The analysis concludes that survivors upgraded their security through additional safeguards they implemented themselves—not because they anticipated this specific bug, but from general paranoia about security. The incident demonstrates that verifiable self-custody (with dice rolls, passphrases, or multi-sig) now beats trusted self-custody, and that the open-source ecosystem's ability to find, patch, and transparently verify fixes within days exceeds traditional custodian transparency.
Key Insights
- The bug reduced effective seed security from 128 bits to 40 bits on Cold Card MK2/MK3 devices by checking whether a randomness setting existed rather than whether it was enabled, causing firmware to skip the hardware random number generator entirely
- The attack succeeded without any user interaction, phishing, or device compromise because the attacker could simply enumerate the shrunken seed pool offline on their own machine, check which addresses held coins, and sweep them automatically
- The bug went undetected for five years because the hardware random number generator was still present and functional elsewhere in the firmware, creating the false appearance of proper security in internal reviews
- Every survivor of the attack was someone who voluntarily added extra security layers—dice rolls, BIP39 passphrases, or multi-signature requirements—indicating that default setup offered no defense while optional safeguards saved all affected users
- Randomness weaknesses are a recurring industry failure point across multiple wallets and tools (Milk Sad, Profanity, Trust Wallet, Ill Bloom) that produce no visible symptoms, making them difficult to detect compared to visible security breaches
Topics
Transcript
[0:00] If you hold your Bitcoin on a hardware wallet because you thought that it meant it's 100% safe, you need to watch this immediately. Over the past few days, attacker scripts have drained more than $100 million in Bitcoin from thousands of cold card wallets. The exact devices recommended by top security experts. So, today we're breaking down the 5-year-old bug that destroyed the gold standard of self-custody. How automated drainers swept 500 wallets in under 25 minutes. and the exact step-by-step emergency protocol that you must follow right now to secure your funds. My [0:35] name is Lewis and this is the Coin Bureau. Now, let's start with what happened on the night of the 30th of July…
Full transcript available for MurmurCast members
Sign Up to AccessMore from Coin Bureau
Why Washington Won't Sign the Clarity Act
The Clarity Act, a major cryptocurrency regulatory bill, is stalled not by banks or Senate gridlock but by a single unsigned compromise document on the White House desk regarding ethics restrictions on federal officials' crypto holdings. With Trump's family earning $1.4 billion in crypto income in 2025, the ethics clause—which would bar officials from issuing digital assets—appears to be the unstated reason for the bill's blockage.
Bitcoin Just PROVED It Doesn't Need Saylor
Bitcoin rallied 14% from its June lows despite MicroStrategy ceasing purchases and briefly becoming a net seller, proving that Bitcoin no longer depends on Saylor as its marginal buyer. MicroStrategy implemented a new capital framework prioritizing cash reserves, preferred buybacks, and limited Bitcoin sales over continuous accumulation, while the buyer role shifted to dispersed institutional buyers and long-term holders.
Bitcoin's Next Big Move Depends On One Thing. FED PANIC
The video argues that despite the Fed's hawkish stance with three dissenting votes for rate hikes, historical patterns and current market stress signals suggest an imminent policy reversal. Bitcoin, as a liquidity-sensitive asset, could experience significant gains once the Fed begins emergency easing in response to credit market deterioration.
Tom Lee Proves ETH Is BETTER Than Bitcoin
Louis from Coin Bureau analyzes whether Ethereum's staking yield makes it a better treasury asset than Bitcoin, comparing Bitmine's $45.7M quarterly staking revenue to MicroStrategy's Bitcoin holdings. While ETH generates income, the analysis reveals this doesn't eliminate price risk, and the yield depends on reversible regulatory interpretations and protocol governance decisions.
Europe Just Made Tether ILLEGAL for 40 Million People!
Tether was effectively removed from European markets not through an outright ban, but through MiCA regulations requiring e-money token issuers to maintain 60% of reserves in EU bank deposits—a requirement Tether refused. This regulatory move simultaneously cleared the market for compliant alternatives like USDC and euro stablecoins, while European banks are launching their own consortium stablecoin (Quivalis) to compete for the digital payment layer.