Cookie Settings

    We use cookies to improve your experience. Essential and analytics cookies are automatically enabled. View cookie preferences

    Skip to main content
    Coldcard keygen drain investigation 2026: cracked cold hardware wallet on a crime-scene table, violet entropy dice and cloned keys rising from a broken keygen while cyan bitcoin spills into RBF fee races — CryptoStrapon
    Critical Threat
    Wallet Security

    Coldcard Drain: $130M Walked Out Of Wallets Nobody Touched

    Published: August 15, 2026
    11 min read

    Not your keygen, not your coins.

    The victims did everything the manuals told them to do. Metal seed plates in a safe. Air-gapped signing. No browser extension, no phone, no cloud. Some of those wallets had not been plugged into anything for two years. On July 30 the coins moved anyway, in a window of about forty-one minutes. The bill started at roughly $38 million, passed $88 million within days, hit $114 million by the second week of August and settled near $130 million. Nobody has produced a phishing page, a fake support agent or a poisoned USB cable that explains it. What the numbers point at is uglier: the randomness that created those keys may never have been random.

    Why This One Is Different

    Almost every crypto theft we document needs you to make a move. Click a link, sign an approval, paste an address, answer a call. This one needs nothing. If the seed phrase was born predictable, the attacker does not have to reach your device at all. He generates the same key on his own machine, watches the address, and waits for it to hold enough to be worth sweeping. Your operational security was excellent and completely beside the point.

    You can guard a key forever. You cannot guard a key that somebody else can recreate from scratch.

    Two Years Offline, Empty In One Block

    One of the earliest reported cases reads like a bad joke. A holder set up a device in 2023, wrote the words on steel, put the steel in a bank box, put the device in a drawer, and went back to living. No transactions since. No apps connected.

    On August 2 the wallet paid out in full. One transaction, no partials, no test amount first. The signature was valid, which means whoever built it had the private key. Not access to the device. The key itself. A valid signature is the blockchain equivalent of a confession that names nobody.

    By the time the owner noticed, the coins had already been split across a dozen fresh addresses. He filed with the police, posted the transaction ID, and got the usual reply: the money is visible, the money is gone, those two facts are not related.

    Cold storage protects against people reaching in. It does nothing about a key that was weak on the day it was born.

    The Keygen Theory, In Plain Language

    A bitcoin private key is a very large random number. The whole security model rests on that word, random. If the number generator inside a device is broken, biased or seeded from something guessable, the space of possible keys shrinks from unimaginable to searchable. An attacker who works out the pattern can precompute millions of keys, derive the addresses, and check which ones ever received money.

    That is exactly the shape of what researchers are seeing. Victims share a vendor and, in several clusters, a rough window of device setup. They do not share an exchange, a country, a wallet app or a browser. When the only common thread is where the entropy came from, the entropy is the suspect. Coincidence stops being coincidence somewhere around victim forty.

    Coinkite did not do the usual dance. No lawyer noises, no blaming the customers. The company published an advisory, pulled and destroyed stock it could not vouch for, and said the weakness slipped through a code review that leaned on an AI assistant. A machine read the randomness code, decided it looked fine, and nobody sitting behind the machine checked it. Attribution is still being narrowed and nothing here is a verdict. But the only theory that survives contact with the evidence is a keygen problem.

    Every other explanation requires the victim to have done something. Forty of them did nothing. That is the part that should be keeping firmware engineers awake.

    Vocabulary Decoded

    Three terms are doing all the heavy lifting in this story, and two of them are usually explained badly.

    Entropy

    What it sounds like:

    Some physics word about disorder that got borrowed by people who want to sound clever at conferences.

    What it actually is:

    The raw randomness a wallet collects before it turns anything into a key. Good sources are chip noise, sensor jitter, timing wobble. Bad sources are a clock value, a counter, or a hardware RNG that quietly fails and returns something close to the same output every time. The device cannot tell you the difference, because a weak key looks identical to a strong one from the outside. It is the only part of your security you cannot inspect and cannot test.

    Deterministic derivation (BIP-39 and BIP-32)

    What it sounds like:

    Standards paperwork. Skippable.

    What it actually is:

    The rule that one seed produces every address you will ever use in that wallet, forever, in a fixed order. Wonderful for backups. Brutal here. If the seed is guessable, the attacker does not get one address, he gets your whole account history and every change address you have not spent yet. One weak number, the entire wallet.

    RBF, replace by fee

    What it sounds like:

    A convenience feature for people who set the fee too low and want to nudge a stuck transaction.

    What it actually is:

    In this campaign it became a weapon. When a victim spotted the theft mid-flight and tried to rescue the remaining coins by broadcasting his own transaction, the attacker simply rebroadcast the same spend with a higher fee. Miners take the richer version. The victim raised again. The attacker raised again. Whoever is willing to burn more sats wins the block, and the attacker was spending stolen money.

    Three ordinary building blocks. Chain them in the wrong order and a safe becomes a shop window. None of this required a single new exploit.

    How The Attack Runs

    Four stages, and only one of them happens anywhere near you.

    Stage 1: Find the pattern

    The attacker gets hold of devices, firmware images or output samples and studies how the seeds come out. If a bias exists, this is where it is found. It is slow, boring, well funded work, and it happens long before anybody loses anything.

    The theft in August was the payout. The work behind it is probably a year old.

    Stage 2: Precompute at scale

    Once the space is narrowed, generating candidate seeds and deriving their addresses is a rented GPU problem, not a cryptography problem. The result is a list of addresses the attacker can already spend from.

    Nobody is brute forcing bitcoin here. They are brute forcing a mistake.

    Stage 3: Watch and wait

    The list gets checked against chain state on a loop. Empty addresses cost nothing to monitor. When a balance appears and crosses a threshold worth the risk, the address is queued. Some of the drained wallets had been funded years before the sweep.

    Patience is free when the key is already in your pocket.

    Stage 4: Sweep, then win the fee race

    The sweep goes out with a healthy fee. If the owner reacts and tries to move whatever is left, the attacker replaces his own transaction with a higher fee version and repeats until the victim gives up or runs out of balance to pay with. Several victims reported losing that race by a few sats per byte.

    You are bidding against a man who is paying with your money.

    The August Timeline

    What is publicly established, in order.

    July 30: forty-one minutes

    The first big block of sweeps lands inside a single window of about forty-one minutes. Dozens of wallets, one after another, funds landing in a small set of destinations including the cluster around bc1qq85v2c9...cu9r. Roughly $38 million by the time the mempool calms down.

    Forty-one minutes is not a burglar picking locks. It is a man reading a list he already had.

    August 1 to 6: the total triples

    Victims surface on forums and X with the same story and no phishing to confess. Reported losses pass $88 million as analysts tie older sweeps to the same destinations, same hop structure, same working hours.

    Same vendor, no shared exchange, no shared app. On-chain, that combination is a fingerprint.

    August 7: Galaxy Research publishes

    The report puts the weight behind a key generation failure rather than user error, maps the July 30 window transaction by transaction, and documents replacement spends broadcast at a flat 30.0 sat/vB against victims trying to rescue the remainder.

    A fixed fee rate across unrelated victims is a script with a man watching it. Fire and forget does not bother to outbid you.

    Mid August: $114M, then about $130M

    Coinkite publishes its advisory and destroys inventory it cannot vouch for. The count crosses $114 million and settles near $130 million as holders who had not looked at their addresses in years finally look.

    The attack is not accelerating. The census is catching up with what already happened.

    Nobody has produced a victim who clicked anything. Two weeks in, that is no longer a gap in the reporting. It is the finding.

    Signals Worth Acting On

    • Your seed was generated entirely on-device with no way to check itThat is normal and usually fine, but it means you are trusting one chip completely. Worth knowing which chip.
    • Funds move from an address you have never spent fromA wallet that has only ever received cannot leak a key through signing. If it drains, the key was compromised at creation or at backup.
    • Your rescue transaction keeps getting outbidThat is a live opponent replacing your spend, not congestion. Stop bidding, you are funding the miner and losing anyway.
    • Several wallets of yours from the same setup session are hitCorrelated losses across independently stored wallets point straight at how they were made.
    • Someone contacts you within hours of the theft offering helpThe victim list is public on-chain. So are you, now.

    The uncomfortable signal is the absence of one. If you cannot find the mistake you made, consider that you may not have made one.

    The Numbers

    Rough, public and still moving.

    $38M, $88M, $114M, about $130M

    The escalation of a public count, not of an attack. Most of the growth is older sweeps being reclassified into the same cluster.

    Zero confirmed phishing victims in the cluster

    Every reported case so far denies any interaction. That does not prove the keygen theory, but it kills the easy explanation.

    Years between key creation and theft

    Several drained wallets were set up in 2022 and 2023. Precomputed keys do not expire.

    Replacement spends at a flat 30.0 sat/vB

    The same fee rate across unrelated victims, high enough to win the race and low enough to keep the change. Losing the remainder cost some people the price of a coffee in fees.

    After The Theft, The Second Wave

    A public theft cluster is a mailing list for the recovery grifters. They read the same chain data the researchers do, and they get to you first.

    The forensics firm that found you

    A DM within a day or two, a dashboard screenshot, a percentage upfront. Real analytics firms do not cold message victims and do not take retainers in bitcoin.

    The vendor support impostor

    Email or call claiming to be the hardware maker running an emergency migration, with a link to move your remaining coins to a safe address. There is no such programme. Any migration you do, you do yourself, offline, to keys you generated.

    The class action recruiter

    A law firm wants you in a suit against the vendor and needs a fee to join. Litigation may well happen here, but nobody legitimate charges you to be added to a plaintiff list by direct message.

    Anyone who contacts you first about your stolen coins is working the second half of the theft. Real reports go one direction only: from you, to police and to the vendor, using addresses you looked up yourself.

    The first robbery did not know your name. The second one does.

    Why Careful People Got Cleaned Out

    None of the usual explanations apply, and that is the point worth sitting with.

    The trust was delegated, not removed

    Buying hardware moves your trust from a browser to a manufacturer. It is a better trade, but it is still a trade, and most people forget they made it.

    Entropy is unverifiable by design

    You can check a signature, a fingerprint, a firmware hash. You cannot check whether the number you were given was actually random. There is no test for it after the fact.

    Air-gapping solves the wrong half

    Isolation defends the key from the network. It does nothing about the moment of creation, which happened before any isolation existed.

    Nobody rotates a cold wallet

    Rotation is annoying, costs fees, and feels paranoid. So keys sit for five years, which is exactly the timeline a precomputation attack needs.

    The lesson is not that hardware wallets are bad. It is that a key has a birthday, and the birthday matters as much as the vault.

    What To Actually Do

    In order of how much it helps.

    • Add your own entropy. Most serious devices let you roll dice or supply your own words. If the device offers a dice or coin flip seed, use it. That single step removes the vendor from the trust equation.
    • Use a passphrase on top of the seed. A BIP-39 passphrase you chose yourself means a compromised seed alone is not enough. Store it separately from the words and accept that losing it loses the coins.
    • Rotate anything generated on a device you now distrust. Generate fresh keys on different hardware or with your own entropy, then move funds in one go. Half measures leave change addresses behind on the old seed.
    • Split the stack across vendors. Two makers, two seeds, split balances, or a multisig quorum spanning both. A keygen flaw at one vendor then costs you a fraction instead of everything.
    • Do not fight an RBF race. If a sweep is already in the mempool, bidding against it usually just donates fees. Move whatever sits on unaffected keys instead, and preserve the transaction IDs for the report.

    Checks Worth Running This Week

    None of these take long, and all of them are things people skip.

    Verify firmware provenance

    Confirm the version and signature against the vendor's published hashes, from a link you typed yourself.

    Set up address watching

    A watch-only wallet or a block explorer alert on your cold addresses tells you about an outgoing transaction in minutes rather than months.

    Test your restore

    Restore the seed on a second device and confirm the first address matches. Silent backup failures are a bigger cause of loss than theft.

    Write down the setup date

    If a vendor eventually publishes an affected production or firmware window, the date is what tells you whether you are in it.

    Consider multisig for the long tail

    Two of three across different manufacturers turns a single vendor failure into an inconvenience.

    Ownership of a key is not a purchase. It is maintenance. Most people bought the device and skipped the job.

    Cold Storage Checklist

    Pin it somewhere you will see it before your next transfer.

    1

    Generate the seed with your own entropy where the device supports it.

    2

    Add a passphrase you chose and stored separately.

    3

    Verify firmware signatures from a manually typed vendor URL.

    4

    Restore on a second device before funding anything meaningful.

    5

    Split large balances across two vendors or into multisig.

    6

    Watch your cold addresses with alerts, even if you never spend.

    7

    Record setup dates and firmware versions for every device.

    8

    If drained, save transaction IDs first and ignore anyone who contacts you.

    Got a Suspicious Message?

    Use our AI-powered detector to analyze potential scams instantly.

    Key Takeaways

    1. 1Roughly $130 million in bitcoin left offline wallets between July 30 and mid August 2026, with no evidence of user error at any point.
    2. 2The surviving explanation is weak key generation, which lets an attacker recreate keys without ever touching the device.
    3. 3The vendor did not deny the problem. Coinkite published an advisory, destroyed unvouched stock and pointed at an AI-assisted code review that missed the flaw.
    4. 4Attackers used replace by fee to outbid victims who tried to rescue the remainder mid theft.
    5. 5Air-gapping and steel backups protect the key after birth. They do nothing about the moment it was created.
    6. 6User entropy, a passphrase, vendor diversity and multisig are the four things that actually blunt this class of attack.

    They never touched the safe. They rebuilt the key.

    The safe was flawless. The dice were loaded.

    Frequently Asked Questions

    Share This Article

    Sources & Citations

    Research for this investigation compiled from publicly available blockchain data, security reports, and community documentation.

    Verification: All blockchain transactions and addresses referenced in this article can be independently verified through the linked blockchain explorers. We encourage readers to conduct their own verification.

    Methodology: Every case requires at least three independent sources plus verifiable on-chain evidence before publication. Full standards: /methodology

    Legal notice: This assessment is based on publicly available data, including on-chain records, official statements and reported incidents. It is journalistic and educational analysis, not legal advice, an accusation of criminal conduct or a court finding. Named companies, projects, domains, wallets and individuals are described as reported by the cited sources; a company name may appear because fraudsters impersonated it, not because the company did anything wrong. If you believe something is inaccurate or out of date, write to cryptostrapon@proton.me and we will correct it and log the change. Editorial policy