One of the fastest bitcoin thefts on record unfolded in roughly 25 minutes on Friday. Attackers drained 594.48 BTC — about $38.3 million at current prices — from approximately 500 Coldcard hardware wallets, exploiting a firmware flaw that had silently disabled secure random number generation for more than five years. According to CoinDesk, the sweep executed around 500 transactions on July 30–31, 2026, before consolidating 562 BTC into a single address that has not yet moved.

The theft landed on the very day Bitcoin closed out its best month in a year. BTC ended July up roughly 7.5% per CoinDesk — then slid 2.9% to about $62,929 by 4:30 p.m. ET Friday while the Nasdaq rallied 1%. As of Saturday, August 1, Bitcoin trades near $63,000, down about 2.7% over 24 hours, with a 24-hour range of roughly $62,473–$65,164.

A five-year-old bug that made 'random' predictable

The vulnerability was introduced in Coldcard firmware 4.0.0, released in March 2021. A broken check caused affected devices to skip their hardware random number generator and fall back to predictable, software-based key generation seeded by non-secret chip data. Per NewsBTC, effective entropy dropped from the intended 128 bits to roughly 72 bits — a range modern hardware can search. Coldcard maker Coinkite and Block's Bitcoin engineering team traced the bug together.

Crucially, attackers never needed physical access to any device. A visible on-chain address or an exported public key gave them a target to test candidate seeds against; once a guess matched, the attacker held the private key and could move the coins immediately. All wallets swept in Friday's attack were single-signature wallets holding more than 0.15 BTC, most of them dormant, with creation dates spanning 2021 to 2026 — matching the vulnerability window.

And the damage may be larger than Friday's headline number. Engineers at Block and analysts at Galaxy Research count 1,082.65 BTC that have disappeared from wallets linked to the flaw in total — roughly $70 million at current prices, per Bitcoin Magazine.

Which devices are affected — and what to do

DeviceStatus (Coinkite advisory, as of Aug 1, 2026)Action
Coldcard Mk2 / Mk3Confirmed exploit scope: seeds generated on firmware v4.0.0–v5.0.3Generate a brand-new seed on updated hardware and move funds immediately; Mk3 firmware fix is v4.2.0+
Coldcard Mk4 / Mk5Appear unaffected per preliminary analysis; precautionary update advisedUpdate to firmware v5.6.0 or later
Coldcard QAppear unaffected per preliminary analysis; precautionary update advisedUpdate to firmware v1.5.0Q or later

Coinkite's advisory centers on Mk3 devices whose seed was generated on vulnerable firmware, and the company initially said Mk4, Q and Mk5 appeared unaffected — before advising users of the later devices to take precautions as well on Friday. The consistent recommendation from Coinkite, per Bitcoin Magazine: any potentially affected user should generate a new seed on patched hardware and move funds right away. Sitting still is the one clearly wrong answer, because the attack requires nothing from the victim.

Markets: a security story colliding with a rotation story

Friday's slide had more than one parent. The July monthly options expiry and institutional month-end rebalancing were already pressuring price, per multiple analysts, alongside three hawkish Fed dissents from Wednesday's meeting, fading odds of the CLARITY Act passing this summer, and a stronger dollar. But the Coldcard headline added a distinctly bearish flavor: Forbes reported the attack sparked 'sudden price crash fears,' and CoinDesk argued the exploit shakes faith in self-custody and may push investors toward ETFs — an ironic twist in a week when US spot Bitcoin ETFs saw $265.4 million walk out the door on Friday alone.

Meanwhile equities boomed: the S&P 500 added 0.7% to 7,489.72, the Dow gained 277 points to 52,485.03, and Amazon surged 15.6% on its AWS blowout — a sharp one-day divergence from Bitcoin's red close that we analyze in detail in today's companion piece.

The uncomfortable AI subplot

How was a five-year-old bug found now? Per Cybernews, researchers suspect AI tooling may have helped the attackers locate the flaw, and Bitcoin Magazine framed the incident bluntly: AI is now auditing every open-source wallet — and it does not only work for the good guys. Coinkite has released fixed firmware. The 562 BTC consolidation address remains a key watch item: any movement toward exchanges would be the next chapter of this story.

As of August 1, 2026: BTC ~$63,000; the stolen funds have not moved.

Why this incident is different

Hardware wallet failures are rare, and most historical incidents required physical access, supply-chain tampering, or user error. This one required none of the three — which is why it lands harder than its dollar figure suggests. The 594 BTC taken Friday is small next to exchange hacks like Mt. Gox or Bybit, but those reinforced the case for self-custody; this attack strikes at self-custody's own foundation, the assumption that a reputable device generates unguessable keys. For holders deciding this weekend between patching a device and switching custody models entirely, our companion guide walks through entropy, dice-roll generation, multisig, and passphrases in practical detail.

Disclaimer: This article is for informational and educational purposes only and does not constitute investment, financial, legal, or security advice. Cryptocurrency investments are volatile and carry a high risk of loss. Always do your own research and consult a qualified professional before making investment or custody decisions.