NewsTechnical

$100M DRAINED From Crypto's Safest Wallet!

Coin Bureau

Over $100 million in Bitcoin was drained from Cold Card hardware wallets due to a 5-year-old firmware bug that weakened the random number generation used to create seed phrases. The bug reduced security from 128 bits to 40 bits on older models, making seeds guessable by ordinary laptops, though users who added extra security measures like dice rolls, passphrases, or multi-sig remained unaffected.

Summary

Between July 30-August 3, 2026, attackers drained approximately $100 million in Bitcoin from thousands of Cold Card hardware wallets through an automated attack that didn't require accessing the physical devices. The root cause was a firmware bug introduced on March 1, 2021, when Cold Card migrated to a new cryptography library called Libangu. A single line of code checked whether a hardware randomness setting existed rather than whether it was enabled, causing the firmware to skip the hardware random number generator and fall back to a weak software generator called Yasmarang that relied on the chip's serial number and startup timing—values an attacker could guess or enumerate. On Cold Card MK2 and MK3 devices, this reduced seed phrase security from 128 bits to approximately 40 bits (about one trillion possibilities), small enough for a laptop to crack offline in hours. Newer MK4, MK5, and Q models retained around 72 bits due to additional randomness from secure chips. The bug went undetected for five years because the hardware randomness generator was still present and functional elsewhere in the firmware, passing internal reviews, but the specific code path generating seed phrases bypassed it entirely. Victims included people who followed all recommended security practices, stored devices offline in safes and vaults, and never touched their wallets—some losing funds that had sat untouched for over three years. The attack affected not just seed phrases but also paper wallet keys, seed XR split masks, device cloning keys, USB encryption keys, and other sensitive cryptographic material. Three groups survived completely unaffected: users who rolled physical dice (at least 50 rolls) during setup to inject real randomness, users who added a strong BIP39 passphrase, and users in genuine multi-signature setups. No multi-sig wallets or Taproot addresses were hit, indicating the attacker's script was narrowly scoped. Cold Card CEO NVK responded quickly, taking full accountability and advising users to move funds immediately, but updating firmware only prevents new bad keys—it cannot fix already-generated compromised seeds. Cold Card's deliberate 120-day customer record purge for privacy prevented mass notification of affected users. The incident reflects a broader pattern in crypto: randomness bugs are recurring failure points across the industry that go undetected because weak randomness produces no visible symptoms. Similar bugs have caused major losses—the 2023 Milk Sad bug ($900K+), the 2022 Profanity vanity tool ($160 million), Trust Wallet's 2022-2023 browser extension flaw, and the July 2026 Ill Bloom bug ($5M+ across blockchains). The analysis concludes that survivors upgraded their security through additional safeguards they implemented themselves—not because they anticipated this specific bug, but from general paranoia about security. The incident demonstrates that verifiable self-custody (with dice rolls, passphrases, or multi-sig) now beats trusted self-custody, and that the open-source ecosystem's ability to find, patch, and transparently verify fixes within days exceeds traditional custodian transparency.

Key Insights

  • The bug reduced effective seed security from 128 bits to 40 bits on Cold Card MK2/MK3 devices by checking whether a randomness setting existed rather than whether it was enabled, causing firmware to skip the hardware random number generator entirely
  • The attack succeeded without any user interaction, phishing, or device compromise because the attacker could simply enumerate the shrunken seed pool offline on their own machine, check which addresses held coins, and sweep them automatically
  • The bug went undetected for five years because the hardware random number generator was still present and functional elsewhere in the firmware, creating the false appearance of proper security in internal reviews
  • Every survivor of the attack was someone who voluntarily added extra security layers—dice rolls, BIP39 passphrases, or multi-signature requirements—indicating that default setup offered no defense while optional safeguards saved all affected users
  • Randomness weaknesses are a recurring industry failure point across multiple wallets and tools (Milk Sad, Profanity, Trust Wallet, Ill Bloom) that produce no visible symptoms, making them difficult to detect compared to visible security breaches

Topics

Cold Card firmware bug and random number generation failureAttack mechanics and automated seed drainingRoot cause analysis of the Libangu library migrationSecurity impact and affected device modelsUser protections that prevented fund lossIndustry pattern of randomness vulnerabilitiesResponse and remediation stepsImplications for self-custody vs. exchange custody

Transcript

[0:00] If you hold your Bitcoin on a hardware wallet because you thought that it meant it's 100% safe, you need to watch this immediately. Over the past few days, attacker scripts have drained more than $100 million in Bitcoin from thousands of cold card wallets. The exact devices recommended by top security experts. So, today we're breaking down the 5-year-old bug that destroyed the gold standard of self-custody. How automated drainers swept 500 wallets in under 25 minutes. and the exact step-by-step emergency protocol that you must follow right now to secure your funds. My [0:35] name is Lewis and this is the Coin Bureau. Now, let's start with what happened on the night of the 30th of July…

Full transcript available for MurmurCast members

Sign Up to Access

More from Coin Bureau

Get AI summaries like this delivered to your inbox daily

Get AI summaries delivered to your inbox

MurmurCast summarizes your YouTube channels, podcasts, and newsletters into one daily email digest.