$116M left cold storage without touching a single device
What happened
Starting July 30, 2026, attackers drained roughly 1,816 BTC — about $116 million — from more than 5,200 Bitcoin addresses, in four waves. Every one of those wallets was "cold storage": keys held on Coldcard hardware wallets, never exposed to the internet. No device was touched, no phishing link clicked, no seed phrase typed into anything.
The cause was a firmware bug from March 2021 (version 4.0.1). A build configuration error made some devices fall back to a weak software random number generator instead of the hardware entropy source when creating a wallet seed. Instead of the intended 128 bits of randomness, some seeds carried as little as 40 bits — few enough that attackers could simply guess seeds by brute force, five years later, from anywhere on earth (TRM Labs, TechCrunch, Fortune).
The uncomfortable lesson is not "hardware wallets are bad." They remain the right way to hold keys. The lesson is that cold does not mean watched. These coins sat still for years; when they finally moved, most owners found out from a news article.
Are you exposed?
If you generated a seed on a Coldcard between March 2021 and the recent patch, treat that seed as compromised — regardless of the firmware you run today. Updating firmware protects seeds you create from now on; it does nothing for a seed born under the buggy version.
Three steps, in order:
1. Migrate. Generate a fresh seed on patched hardware, verify the new wallet fingerprint and a receive address on the device itself, send a small test amount, confirm it arrives, then move the rest.
2. Watch the old addresses until they're empty. The drains came in waves — being in a later wave means there may still be time to move first. A watcher on the old addresses that writes you the moment anything moves is the difference between reading about wave five and being in it.
3. Check the wallet's standing state below. The free check reads any public address — Coldcard or not — and reports what's visible on-chain: recent outflows, dust, planted lookalikes. It takes ten seconds and never asks for keys.
What a watcher can and can't do here
Honesty first: no on-chain monitor could have prevented this. The flaw lived in device firmware, and detecting a weak seed from the outside is exactly as hard as the attack itself. What a watcher does is shrink the gap between "your coins moved" and "you know your coins moved" from days — or a news cycle — to minutes. For funds sitting at rest, that early warning is the whole game: it's the difference between racing to move the rest of your funds and finding an empty wallet a month later. Canary is an early-warning service, never a guarantee — here is exactly what we check, and what we can't see.