Lines of code. 1,596 BTC gone
News Source : Onekey.so
News Summary
- In March 2021 a COLDCARD firmware build stopped asking its hardware chip for random numbers and had ordinary software work them out instead.
- Nobody caught it for five years.
- In July 2026 attackers did the arithmetic and started emptying the wallets.
- A safety check that was there, and did nothing.
- A weak recovery phrase looks exactly like a strong one.
- Twenty-four ordinary words, the right checksum, a device that behaves normally.
- Nothing warns you on screen and nothing errors in the build.
- The source was public the whole time.
- Reading it still required somebody to open that particular file.
COLDCARD stopped drawing from that pool A 2021 firmware change quietly stopped the wallet asking its dedicated randomness chip for that number, and had ordinary software calculate one instead.
Never miss a story from us, subscribe to our newsletter