Bussiness | Economy
JCI Turns Lower as June Trade Deficit Pressures Market
/index.php
Crypto News - Posted on 03 August 2026 Reading time 5 minutes
A hardware wallet can remain disconnected from the internet and still expose its owner’s Bitcoin.
That is the central lesson from a security failure affecting Coldcard devices. The problem did not require an attacker to steal the physical wallet or intercept its internet connection. Instead, researchers found that some firmware versions may have generated wallet seeds with substantially less randomness than users expected.
Every Bitcoin wallet begins with a secret. For many users, that secret is represented by a seed phrase—a list of words from which the wallet’s private keys and addresses can be reconstructed.
The protection offered by that phrase depends on how unpredictably it was generated. A phrase that looks random is not necessarily secure if it came from a limited or reproducible set of inputs.
Block’s Bitcoin Engineering and Security teams found that Coldcard firmware contained an RNG integration error. The affected code selected a deterministic MicroPython software fallback instead of the STM32 hardware random-number generator.
Some of its starting values came from chip-identification and timing information. These values can vary, but they are not equivalent to fresh cryptographic randomness. Once the relevant device state and call history are sufficiently constrained, an attacker may be able to recreate candidate outputs without touching the original hardware. Block Engineering
Block cautioned that its report reflected an early technical assessment and did not include complete end-to-end exploit testing.
Galaxy Research identified three suspected waves involving addresses believed to have been generated by vulnerable Coldcard firmware.
Its latest published estimate placed the observed total at 1,367.05 BTC, worth approximately $88.6 million, across 4,585 source addresses. The first major wave alone moved roughly 1,082.65 BTC from 1,196 addresses in 41 minutes.
However, 4,585 addresses should not automatically be interpreted as 4,585 individual wallets or victims. A single wallet can control multiple Bitcoin addresses.
Galaxy also described its conclusion as an assessment based on blockchain transaction patterns. The data does not definitively establish that the same operator controlled all three waves. Differences in the third wave could point to a revised method or a separate attacker exploring the same vulnerable key space. Galaxy Research, CoinDesk
The incident became personal for Canadian entrepreneur Jonathan Goodman.
Goodman said he had kept his Coldcard and backups offline and had never shared his seed phrase. After learning about the wider incident, he checked his wallet balances and discovered that approximately 18.25 BTC had left three wallets between 9:36 p.m. and 9:43 p.m. on July 29, 2026.
His account illustrates why an air-gapped device is only one component of self-custody security. If the seed was weak when it was created, keeping the device offline cannot retroactively strengthen it. Jonathan Goodman’s statement
Coinkite, the Canadian company behind Coldcard, has released fixed firmware for every affected model and release track.
Its advisory covers Mk2 and Mk3 seeds generated with firmware versions 4.0.1 through 4.1.9. Seeds produced on Mk4, Mk5, and Q devices before their respective fixed releases are also affected, although the technical exposure differs across generations.
The critical distinction is that the vulnerability follows the seed. Updating a device does not repair a seed generated under vulnerable firmware, and importing that same seed into another wallet carries the weakness forward.
Coinkite advises exposed users to install the appropriate fixed firmware, generate an entirely new seed, verify the new wallet, make a small test transaction, and then migrate the remaining funds.
A strong and unique BIP-39 passphrase may create an additional barrier, but Coinkite says it does not repair an affected seed. Coinkite Security Advisory
The Coldcard incident comes during an unusual year for crypto security.
TRM Labs recorded 207 hacks and exploits in the first half of 2026, the highest number it has observed in any six-month period. Those incidents caused approximately $972 million in losses, down from $2.3 billion during the first half of 2025.
The number of incidents nevertheless more than doubled from 83 a year earlier. The figures suggest that headline losses can fall even while the number of opportunities available to attackers continues to expand. TRM Labs, July 1, 2026
Cold storage remains an important security tool, but this case exposes a limit that is easy to overlook: isolation protects keys from online access, not from weaknesses created at the moment those keys are generated.
Source: bloombergtechnoz.com
What do you think about this topic? Tell us what you think. Don't forget to follow Digivestasi's Instagram, TikTok, Youtube accounts to keep you updated with the latest information about economics, finance, digital technology and digital asset investment.
DISCLAIMER
All information contained on our website is summarized from reliable sources and published in good faith and for the purpose of providing general information only. Any action taken by readers on information from this site is their own responsibility.