Recently on X, a internet entrepreneur had all his cryptocurrency stolen, drawing widespread attention. “I did everything right, but none of it worked.” Canadian entrepreneur Jonathan Goodman posted on X on August 1, describing how hisBitcoinThe theft process: Between 9:36 PM and 9:43 PM on July 29, all of his wallets were suddenly emptied in one go, losing 18.25 BTC, worth more than 1.6 million Canadian dollars (approximately NT$38 million). The most shocking part is how he safeguarded his assets: the private keys were stored in Coldcard Cold walletInside, the device was locked in a bank safe deposit box, never connected to the internet, and the seed phrases were never leaked to anyone.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part’s nerdy, but here’s… pic.twitter.com/Lf9kJv9Jo4
— Jonathan Goodman 🇨🇦 (@itscoachgoodman) August 1, 2026
His experience is not an isolated case; according to Galaxy Research Tracing on-chain fund flows revealed that in the early hours of July 30, within just 41 minutes, 1,196 Bitcoin addresses were swept clean by an automated program, stealing 1,082.65 BTC. Approximately 27 hours later, a second wave of attacks appeared, sweeping away another 76.16 BTC. The two waves combined totaled 1,158.81 BTC, worth over $75 million (approximately NT$2.4 billion) at the then-current coin price, with as many as 2,673 addresses affected.
The source of the incident points to the Coldcard, produced by Canadian hardware wallet company Coinkite: starting in March 2021, the seed generation program in some firmware versions had a random number vulnerability, with effective entropy far below security standards. Attackers were able to use AI to analyze the open-source firmware, identify the weakness, and then brute-force seed phrases, completely shattering the myth of “never-connected” cold storage.

How could a wallet that has never been connected to the internet be stolen?
Jonathan Goodman is the founder of a fitness trainer training platform and considers himself a seasoned cryptocurrency user. In his post, he stressed that his Bitcoin was kept in cold storage, with the private keys stored on a Coldcard hardware wallet, the device placed in a safe, and never connected to the internet. He had never told anyone the seed phrase, and his assets were distributed across multiple safes and vaults. He originally thought this setup was watertight—until he logged into the Wasabi wallet software to check his balance and saw an entire row of red withdrawal records.
The Coldcard he used was at the heart of the vulnerability. Coinkite released on July 30Security AdvisoryAdmitted that an error occurred in March 2021 when integrating the third-party cryptographic library libngu: the seed generation process did not use the STM32 chip’s hardware random number generator (RNG), but instead fell back to MicroPython’s “Yasmarang” software pseudo-random algorithm. The algorithm uses the chip’s unique identifier (UID) and timer registers as initial values; neither the UID nor the timer values constitute a reliable source of randomness. Once an attacker has the device UID, boot time, and call history, they can reproduce the candidate sequence of seed generation offline.

Blockchain company Block’s bitcoin engineering and security team, working with an anonymous security researcher, published a technical analysis on July 30 that traces the root cause of the vulnerability to a single macro check: the production board configuration defines “MICROPY_HW_ENABLE_RNG” as 0, because Coldcard provides its own hardware RNG wrapper; however, the libngu library checks whether the macro exists rather than whether it is enabled, so compilation proceeds normally while actually binding to a software pseudo-random generator. Affected firmware covers versions 4.0.0 through 4.1.9 for Mk2 and Mk3, as well as early versions of Mk4, Mk5, and Q. Coinkite estimates that Mk3 retains only about 40 bits of effective entropy, Mk4, Mk5, and Q about 72 bits, whereas a standard 12-word seed phrase should have 128 bits of entropy.
AI code review uncovers vulnerability hidden for five years.
Coldcard’s firmware source code has always been public on GitHub, which became the entry point for the attack. In its technical explanation, Coinkite noted that one must assume someone used AI to review old firmware versions one by one before finding this flaw that had been lurking for nearly five years. Ironically, the company had used “one of the best AI models on the market” to review its own code just a few weeks earlier, yet failed to spot this issue or any critical vulnerabilities. “Attackers and defenders have the same AI tools, but today it didn’t help us—it only helped the bad guys,” Coinkite wrote in the announcement.
Galaxy Research’s flow analysis presents the full picture of the attack: the first wave occurred on July 30 from 01:10 to 01:51 UTC, spanning blocks 960,183 to 960,191. Each sweep paid a fixed fee of 30 sat/vB and made no change, while the median normal transaction fee that week was only 0.4 to 1.0 sat/vB—an overpayment of 30 to 75 times. The research team concluded that this was an automated tool consuming already-obtained private keys, not normal movement by the wallet owners. Of the emptied addresses, 1,183 were in native SegWit (BIP-84) format, consistent with multi-path scanning behavior. The second wave of attacks began on July 31 and lasted 3 hours and 42 minutes, stealing another 76.16 BTC. The victim addresses of the two waves showed no overlap at all, indicating that the attack tool was enumerating the entire keyspace. As of August 2, the stolen bitcoin remains concentrated in 7 attacker addresses and has not moved. Analysts believe the thieves may be waiting for the heat to die down, or lack the ability to launder such a massive amount of funds.
We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett
1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks… pic.twitter.com/q785paZvMQ
— Galaxy Research (@glxyresearch) July 31, 2026
On-chain analysis firm Chainalysis also noted that the attackers targeted high-value wallets from the outset, including one victim who lost $1.8 million, showing they had studied the distribution of the victim pool before striking. The victims were overwhelmingly individual holders: by count, most addresses had balances under 1 BTC, but the losses were concentrated in large-amount addresses—a typical profile of personally self-custodied assets, rather than exchange or institutional positions.
Coinkite released fixed firmware on July 31 for all affected models and distribution channels: Mk2/Mk3 upgrade to 4.2.0 or above, Mk4/Mk5 standard to 5.6.0 or above, and Q standard to 1.5.0Q or above. However, the company stressed that updating the firmware will not fix old seeds that have already been generated. Users must generate brand-new seeds on the updated device, migrate all funds to the new wallet, and keep the old backups until the migration is confirmed complete. CEO NVK urged in an open letter: “If you have generated seeds with a Coldcard, please move your funds first according to our updated best practices, and then continue reading.”
Coinkite also provides two exceptions: if the seed generation included at least 50 fair, independent, and undisclosed physical dice rolls, the dice alone can contribute over 128 bits of entropy; or if the wallet uses a high-strength and unique BIP-39 mnemonic passphrase, the attacker would still need to crack the passphrase. However, the company still recommends that all affected users migrate as soon as possible. Coinkite’s other products, TAPSIGNER, OPENDIME, and SATSCARD, use different codebases and are not affected by this vulnerability.
Cold wallet self-custody belief takes a heavy blow
This incident has reignited the debate over “self-custody” in the Bitcoin community. A core selling point of Bitcoin has long been that holders don’t need to trust banks or exchanges; yet this vulnerability allowed the private keys of thousands of individual investors who “did everything right” to be reconstructed out of thin air. Bitcoin commentator Guy Swann said bluntly: “This is the heaviest blow in Bitcoin’s history to the most technically savvy and most tightly secured Bitcoin holders. Thousands of people’s personal private keys were regenerated right under their feet.”
ARK Invest’s Director of Digital Asset Research, Lorenzo Valente, put it more bluntly: “The self-custody hardware space is a disaster right now. Consumers are essentially trading counterparty risk for software risk, hardware risk, supply chain risk, phishing risk, and backup risk, plus the possibility of losing everything with a single mistake. Honestly, spreading your funds across a few publicly traded exchanges or ETFs is actually better.” Casa CEO Nick Neuman criticized Coinkite’s suggestion to use dice to supplement randomness: “You can’t ask people to roll dice to safely self-custody. That simply won’t work for 99% of people.”
For the victim Jonathan Goodman, the loss is extremely heavy. At the end of his tweet, he wrote: “I’m only thinking about one thing right now—luckily I’m an entrepreneur, and my ability to earn is in my own hands. Mark my words, I’ll earn it back.” He has reported the case to the police and the Ontario Securities Commission, but does not expect to recover any funds.
Source: KOCPC Chinese