Coldcard hardware wallet over $115 million lost; the root cause isn’t user carelessness, but a “random-number collapse” at the firmware layer. Starting in March 2021, Coinkite mistakenly downgraded its seed generation from the hardware true random number generator (TRNG) to a software pseudo-random path in a firmware update, causing the effective entropy of the private keys to drop sharply from 128 bits to just 40–72 bits. Since July 30, 2026, the attacker has conducted distributed “chain sweeping”; it has been confirmed that 1778.84 BTC (about $112.7 million) were stolen from more than 8,600 addresses. If the suspected fourth wave is included, losses could reach 2417 BTC (about $153 million). Ledger characterizes this as a typical risk of “weak randomness being amplified in the AI era”—AI greatly reduces the cost of vulnerability scanning and automated attacks.
This incident forces the self-custody community to re-examine the assumption that “cold storage = absolute security,” driving a surge in demand for multisig setups and independent code audits.
From a market perspective, amid the trust shock and macro disturbances, the BTC perpetual long/short ratio remains mildly bullish (longs 53.65%), but on August 14, the single-day liquidations exceeded $86 million. The share of liquidations hitting BTC and ETH longs was 83.93% and 70.75%, respectively—pressure mounts in the short term 📉; BNB is also dragged by derivatives deleveraging. In the short run, with security fears stacking on top of leverage stampedes, mainstream coins are likely to remain weak and range-bound 📉. In the long run, the BTC “digital gold” narrative, ETH smart-contract foundation, and BNB exchange-ecosystem fundamentals remain intact—each security “reset” instead strengthens self-custody standards, and the long-term outlook is still 📈.
For coin holders, the immediate priority is to check firmware versions, migrate old seeds, and upgrade from single-signature to multisig. The “entropy” used in private-key generation has always been more worth scrutinizing than the hardware itself.#Coldcard硬件钱包损失超1.15亿美元
$BTC
$ETH
$BNB
This incident forces the self-custody community to re-examine the assumption that “cold storage = absolute security,” driving a surge in demand for multisig setups and independent code audits.
From a market perspective, amid the trust shock and macro disturbances, the BTC perpetual long/short ratio remains mildly bullish (longs 53.65%), but on August 14, the single-day liquidations exceeded $86 million. The share of liquidations hitting BTC and ETH longs was 83.93% and 70.75%, respectively—pressure mounts in the short term 📉; BNB is also dragged by derivatives deleveraging. In the short run, with security fears stacking on top of leverage stampedes, mainstream coins are likely to remain weak and range-bound 📉. In the long run, the BTC “digital gold” narrative, ETH smart-contract foundation, and BNB exchange-ecosystem fundamentals remain intact—each security “reset” instead strengthens self-custody standards, and the long-term outlook is still 📈.
For coin holders, the immediate priority is to check firmware versions, migrate old seeds, and upgrade from single-signature to multisig. The “entropy” used in private-key generation has always been more worth scrutinizing than the hardware itself.#Coldcard硬件钱包损失超1.15亿美元
$BTC
$ETH
$BNB