Although hard disks weren’t a common feature yet in many home computers in the 1980s, they were becoming increasingly more affordable. For relative meanings of the word ‘affordable’, naturally. This is illustrated by the 12 MB HDD for the Radio Shack TRS-80 that [Clint] over at LGR recently took a peek at.
Costing a cool $3,495 in 1983 – or $11,932 in 2026 USD – this 12 MB storage wonder used a Tandon TM-603 full-height 5.25″ HDD inside. Lacking a working TRS-80 to try it out with, the video is limited to just a basic powering up and opening up of the unit, but [Clint] will be donating it to a computer museum who can hopefully put it to use again.
The connection to the TRS-80 computer is handled by a ribbon cable, while the HDD has its own built-in power supply, rated at 60 Watt.
On the main board for the external HDD controller there is a Signetics 8X300 microprocessor that forms the brains of what makes it into an external drive for the TRS-80. Despite its age, it still looks brand new inside, so despite the Rifa capacitors in the PSU, [Clint] decided to power it on. This resulted in an auditory experience that’s probably best compared to a very rusty jet engine spinning up after languishing for a decade prior to spooling up for take-off.
Hopefully we’ll find out whether this particular unit and its HDD are still working in 2026.
Blockstream has refused to pay a ransom for roughly 598.5 BTC that remains under the control of the actors behind the Liquid Network exploit after 3,400 BTC was returned earlier this week. Blockstream said in an X post on Sept.…
Trezor has warned that a data breach at the third-party marketing platform it uses for sending newsletters is leading criminals to target customers with phishing attacks.
The top hardware wallet manufacturer said Wednesday that an unauthorized actor got access to Brevo’s system and sent emails to 347,000 Trezor customers. Brevo is a platform businesses use to send customer communications.
Scammers managed to use Trezor’s domain name to send the email, making the phishing attempt all the more believable. The email contained a malicious link asking users to download an app and enter their wallet backup.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating…
The news comes after Trezor last month announced that data from 11,742 customers had been exposed after its third-party fulfillment partner, ShipMonk, was targeted.
It then said last week that an additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses and order numbers leaked in the breach.
“We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down,” Trezor said on Wednesday.
“These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched,” Trezor added.
“We have suspended the Brevo account to stop further email distribution.”
Trezor reminded users that it never asks customers to ask for their wallet backups.
Criminals have been targeting data this year, with scammers getting hold of customer information via crypto wallet Ledger’s payment processor Global-e to send phishing emails.
Crypto wallet provider SafePal last month also announced a data breach that involved unauthorized access to about 39,798 customers’ order information, including personal details such as names, addresses and purchase data.
A range-proof cache bug in the Elements codebase let an unknown actor mint unbacked L-BTC, drain 95% of the federation reserve through SideSwap, then negotiate its return on-chain via OP_RETURN messages. The network remains frozen, 598.5 BTC sits in the…
A U.S. federal court has ordered the forfeiture of roughly $212,700 in stablecoins linked to wages earned by North Korean IT workers, giving the Justice Department a partial victory in its attempt to seize more than $7.74 million in digital…
The “White hat” party that withdrew nearly 4,000 bitcoin from the Liquid Network federation wallet on Sunday returned 3,400 BTC to the wallet on Monday. About 598 BTC, or 15% of the consolidated pile, stayed at the same holder address as an implied bounty fee worth 48 million dollars.
The return transaction (bc49a46d), confirmed at 16:09 UTC on September 7. It returned exactly 3,400 BTC to the labeled Liquid peg script address and sent the 598.5 BTC change back to the “White hat” hacker address as change.
The transfer followed a day of messages written into Bitcoin blocks. The White hats first published transaction on chain with a message in the OP_RETURN arbitrary data field “contact us on chain”; the message came from the address holding the 4000 BTC taken from the Liquid Network.
A Blockstream-linked address answered with “Please contact security@blockstream.com”. Later notes from that sender carried Electrum-encrypted payloads and PGP signatures that can be verified against Blockstream’s published security key.
In block 965869, the White hats asked in the clear text whether sending “most” back to the federation script was acceptable. The 1,000-sat output on that transaction was only a message carrier.
Soon after, the White hats wrote “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.” followed by an encrypted blurb of text to Blockstream’s PGP key.
In the same block, a clear-signed reply from the Blockstream sender said “Yes, thank you.” Hours later, the same Blockstream posted another clear-text note: “Bridge nodes are patched, safe to return the funds”.
Minutes after the 3,400 BTC landed. The white hats sent back 85% of the funds, keeping 15% as an implied finder’s fee. The choice was celebrated by some on X as ‘better than keeping 100%’ while others were a bit shocked at the amount. While 15% might sound reasonable, the total sum is so large that it nears $50 million at today’s prices. Blockstream was clearly not happy about the finder’s fee, as four encrypted messages followed onchain a few hours later, likely after the main fires had been put out at the office and the lawyers had a chance to have a say in the matter. An hour later, one more encrypted message was posted from Blockstream.
The White hats replied with two encrypted messages. Blockstream replied once an hour later. Then the White hats published a simple yet meaningful “ ” sad face emoji. This emoji does a lot of work. It suggests that negotiations did not go well over reducing the size of the bounty. Blockstream wizards are clearly ‘big mad’ about the size of that finder’s fee. What exactly was said in those encrypted messages is not known and Blockstream has made no public statements on the matter. But we can only assume the saga is not over.
Liquid’s Sunday statement is still the network’s last official account post: purported whitehats withdrew about 4,000 BTC through the SideSwap peg-out path, the PAK itself was not compromised, other issued assets were unaffected, and the sidechain was paused. Liquid and Blockstream had not posted a new statement on the 3,400 BTC return as of this writing. SideSwap had said the L-BTC in the original peg-out “came from an Elements bug.”
The Liquid Network said Sunday that purported white-hat hackers withdrew about 4,000 bitcoin, worth about $320 million, from the federation wallet that backs L-BTC. Bridge nodes were disabled, and the sidechain was paused. Other issued assets, including USDT, DePix and RWAs, were unaffected, the official account said on X.
The Liquid Network is a federated sidechain of Bitcoin, founded by Adam Back’s Blockstream. The Liquid chain issues a variety of assets such as LBTC, which it backs with BTC on the Bitcoin main chain, held in a large multisig of 15 corporate and known members. 11 of the 15 members need to sign a valid multi-signature transaction to move coins from the treasury. Before the hack, the treasury held over 4200 BTC; after the hack, Blockstream’s proof of reserves page reports a little over 207 BTC left.
The hackers withdrew 4,019.4 BTC from the reserve address in a peg-out transaction using the SideSwap Peg-out Authorization Key. SideWap is a bridge exchange and a member of the Liquid Federation. While details on the mechanism of the hack are not confirmed yet, it appears an inflation bug on the LBTC side chain was exploited by the hackers to create over 4,000 LBTC that did not exist before, and cash them out for on-chain bitcoin from the federation. Because the transaction appeared as valid, given the consensus bug, the federation members’ HSM security servers signed the BTC withdrawal transaction, worth roughly 320 million at the time.
The hacker moved the funds to an address ending in 6gyqjlte, from which they quickly signed a new transaction with a message on the OP_RETURN arbitrary data field saying “we are whitehats. contact us on chain.” Those coins were still at that address at the time of writing.
A small mainnet transaction to the hacker address followed by an OP_RETURN saying “Please contact security@blockstream.com”, presumably from a Blockstream public address, though that remains unconfirmed. A later OP_RETURN spend from the hacker address carried “Please contact us on Signal @m671aw.70”, however, this may be spam and does not share a link to the address with the stolen funds.
In response to the breach, exchanges were told to pause L-BTC deposits and withdrawals. Bridge nodes on the Liquid Network have been paused, limiting access to the side chain, which continues to produce blocks.
JAN3 CEO Samson Mow said Aqua’s Liquid features were affected and that on-chain bitcoin still worked. Other wallets in the industry that use the Liquid Network are expected to be affected. Users holding LBTC now effectively have their savings at risk, since the underlying BTC is currently not redeemable. Given the private nature of the Liquid chain, user onchain analytics are scarce and not much public information is known about how much LBTC is held by retail users versus corporations of Blockstream itself. Nevertheless, should the funds not be returned, it would be a heavy blow to the Liquid Network’s user base.
Users of LBTC don’t have many options but to wait for conversations with the hackers to resolve. Given the size of the hack, it would be difficult for the hackers to get away with stealing all that bitcoin, though perhaps not impossible. What may happen is that the hackers ask for a finder’s fee and return the majority of the funds.
With this exploit, the original Quest hardware can now be officially divorced from any reliance on Meta's servers or services to be useful. That means enterprising Quest owners should be able to sideload apps without needing to register for a Meta Developer account and activating Developer Mode through Meta's mobile app. It also means users should be able to go through the initial setup and login steps for a fresh Quest headset even if and when Meta decides to shut down the servers that currently support this process.
Like a lot of us [Liam Kloppers] had a problem with doomscrolling. Unwilling to go cold-turkey because he does find some utility in social media. He tried a number of things before deciding to say “Screw it” and just go full Pavlov on himself with some old-fashioned classical conditioning. Who needs willpower when you have electric shocks to dissuade you?
The key here was finding an electric-shock dog collar that could be controlled via a smartphone application, which meant he could reverse-engineer its Bluetooth protocol and get it linked up to his own software. The initial implementation ties his quick-and-dirty Python control program with a web server living on his laptop, which he’s configured MacroDroid to call on when his personal criterion for ‘doomscrolling’ is met.
With the shock collar wrapped around his leg, [Liam] was ready to test. It turns out dogs are a lot tougher than people, because even when set to a low level, the shock from the device made him toss his phone across the room and had him hesitant to even pick it up again.
Since he couldn’t bring himself to put the shock collar back onto his leg, he’s now thinking of an audible alarm, something we’ve seen work before. If you’re as unhappy with your habits as [Liam], perhaps consider a device like Commodore’s social-media-free phone before resorting to self-electrocution.
Feds have hit 17 Iranians with criminal charges for allegedly conducting a years-long campaign of cyber attacks — including trying to extort HBO for $6 million in bitcoin.
The U.S. Department of Justice said Tuesday that the 17 individuals were working with the Mabna Institute, which carried out hacking campaigns on behalf of Iran’s Islamic Revolutionary Guard Corps and other Iranian government and university clients.
Hundreds of U.S. and international universities, dozens of companies, and at least five state and federal government agencies were targeted in the campaign.
Part of the indictment mentioned Behzad Mesri, who was previously charged with hacking entertainment giant Home Box Office — HBO — and stealing proprietary data. The crime then saw Mesri try and extort approximately $6 million worth of Bitcoin.
Prosecutors added that five other defendants — Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian — were directly involved in the hack.
The State Department’s Rewards for Justice program is now offering up to $10 million for information on the location of the defendants.
“Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,” U.S. Attorney Jamie McDonald for the Southern District of New York said in a statement.
Founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi, the Mabna Institute allegedly worked at the behest of Iran’s Islamic Revolutionary Guard Corps and other Iranian clients.
The stolen research didn’t just go to Tehran’s intelligence services. Prosecutors say it was resold through two websites, Megapaper.ir and Gigapaper.ir, the latter renting out hijacked professor logins so Iranian customers could walk straight into foreign university libraries.
U.S. institutions had spent some $3.4 billion acquiring the material in the first place. Separate victims racked up more than $20 million cleaning up the breaches.
Law enforcement may already know who emptied more than a thousand Bitcoin from Coldcard wallets in the first and largest wave of the July 2026 drains. Block’s investigation believes they traced the attacker’s on-chain sweeps to a paid account at a major blockchain data provider whose internal logs matched the theft pattern with “extraordinary specificity.”
PSA: The attack is ongoing, targeting weak private keys generated on devices as old as the MK2 with firmware 4.0.1 onwards. If you may have one, double-check and move funds asap. See Coinkite advisory and status page.
The coins from that wave—1,082.65 BTC—still sit untouched in the attacker’s address, leaving hope that a clawback may be possible to the victims and rightful owners of that first wave of stolen bitcoin. The question now is, who is the hacker and whether the same lead points to a sophisticated outsider, or whether the five-year-old entropy bug that made the theft possible was something closer to the insider “retirement attack” Coinkite itself once warned about.
What We Know
On July 30, 2026, an attacker began systematically draining Bitcoin from Coldcard hardware wallets that had generated seeds under vulnerable firmware, a bug that was undiscovered for years. The first and largest wave alone moved 1,082.65 BTC. Subsequent waves followed, with estimates over 2k BTC. Alex Thorn at Galaxy Research has tracked the activity through a combination of on-chain pattern analysis and voluntary victim reports. As of early August, confirmed and estimated losses across multiple waves exceeded 1,800 BTC from more than 5,000 addresses, though exact final totals continue to be refined as new reports arrive. In dollar terms, roughly $118 million has been confirmed stolen.
Thorn has publicly discussed the possibility that law enforcement already holds a concrete lead on the operator behind the largest tranche. In a Bitcoin Policy Institute segment hosted on the Bitcoin Magazine YouTube channel, Thorn stated: “Wave one’s identity, attacker identity, may be known to law enforcement.” He added that Wave 1 remains the biggest single chunk identified so far, with the coins still sitting in the attacker’s address, and noted that Wave 2’s pattern looks similar enough that it could involve the same actor. Wave 2 adds another 76 or so bitcoin to the total.
The primary source for the claim that the hacker’s identity might be known is Clay Garrett, engineering lead at Block working on Bitkey. On July 31, 2026, Garrett posted the findings from Block’s investigation:
“During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.”
“We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.” Garrett said, and added that; “We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.”
Thorn and others have noted that later, smaller waves show different operational patterns—some rapid, opportunistic drains followed by quick laundering—suggesting additional actors may have reverse-engineered the same weak seed space after the initial public disclosure. Self-reported confirmed drains appear to have slowed sharply after August 6, though many potentially vulnerable seeds generated on the affected firmware between 2021 and the July 2026 patch remain at risk until users migrate.
A Retirement Attack?
The nature of the failure has led to conspiracy theories about insider attacks that Coinkite itself once discussed publicly. In October 2021, the official COLDCARD account defined a “retirement attack” as the scenario “when the project makers could have a ‘bug’ in the entropy generation for later retrieval.” The post is still available here. The 2026 vulnerability produced exactly that outcome: seeds generated with far less entropy than intended, leaving them searchable years later. Some in the Bitcoin space now believe that the hack may have been an inside job at Coinkite, though others disagree and the evidence in the public record remains too scarce to know anything definitive. Further evidence will likely not come out for years, until litigation exposes it.
It’s when the project makers could have a “bug” in the entropy generation for later retrieval.
The critical change entered the codebase on March 1, 2021, in a commit titled “First pass w/ libNgU” (b18723dd). That commit replaced remaining Trezor-derived cryptography and BIP-39 code with a new library, libngu, and rewired seed generation. The intended result was that the call for randomness resolved to the STM32 hardware’s true random number generator. However, the bug redirected the call to MicroPython’s software Yasmarang PRNG instead, resulting in an effective entropy collapse to roughly 40 bits on older models and around 72 bits on newer ones. That meant the Bitocin private keys generated were effectively guessable by modern computing hardware. This swap of cryptographic libraries was pushed to the codebase by Doc-Hex, also known as Peter Gray, the Chief Technical Officer of Coinkite.
The move was arguably driven by licensing pressure, according to Foundation Devices CEO and founder Zach Herbert, though Coinkite has denied this as a primary motivation for the code change, saying, “COLDCARD had to make this change to move to libsecp256k1; the license change is irrelevant to this. libsecp256k1 is the standard library used by Bitcoin Core.”
Coldcard had been using Trezor-derived code under the GPLv3 open source license. After Foundation Devices forked related material, Coinkite sought to move remaining components to a more restrictive MIT + Commons Clause arrangement that limited commercial reuse. The rewrite was large and carried complex engineering goals; it was this integration that arguably left the silent failure in the entropy path.
Skepticism about the migration away from the Trezor crypto library emerged as early as April 7, 2021, by a member of the Coinkite Telegram group, who wrote: “do we really want to replace the many-years-old TrezorCrypto code that has been heavily scrutinized by white hatters like Johoe and penetration tested by wallet.fail”, adding “switch may be a talented pseudonymous coder, but their commit history sucks.” The criticism, however, was insufficient and quickly waved away by NVK, who criticized the Trezor library as a “shitcoin shitshow.” Ironically, sharing that codebase with the broader crypto market, under an open license meant that Trezor’s crypto library had much deeper code review than Libngu would ever get, even years later.
Switch and Peter Gray aka Doc-Hex
The swap of cryptographic libraries that introduced the bug was pushed to the codebase by Doc-Hex, the Chief Technical Officer of Coinkite, also known as Peter D. Gray. He replaced the GPLv3 Trezor cryptography library with Libngu, a little-known codebase created by so-called “Switch”, a nym that, up until the creation of Libngu, had no obvious previous history. The Switch account appeared on X on August 3, 2019 with a mention of DEFCON, the international hacker’s conference, an event normally attended by cybersecurity engineers of all kinds.
However, here is where it gets weird. According to research by Bitcoin core contributor James O’Beirne, Switch and Peter D. Gray have signed code commits with the same GPG keys. O’Beirne demonstrated through GPG commit signatures that dozens of commits authored as switck were signed with the personal key of Peter D. Gray, Coinkite co-founder and CTO, who also operates as DocHex. Zach Herbert also claimed that phone numbers ending in the same two digits were tied to both the DocHex and switck X accounts (post). Additional researchers pointed to matching DNS registration patterns.
Neither Gray nor Coinkite has publicly addressed the GPG-signature findings as of this writing, and they did not respond when asked to comment on the topic. The Switch account is still active to this day, having merged code changes to Libngu as recently as August 17th, 2026.
Many in the Bitcoin industry are taking this as some sort of tangential evidence of wrongdoing. Why go out of your way to create a nym just for a particular cryptography library? This has been taken as some kind of evidence of malintent; however, a deeper analysis begs to differ. Had Gray really intended to rug Coldcard users with this RNG bug, would he really have been signing commits with his personal GPG key? Could someone be so cunning that they would hide a bug for years, waiting for its adoption to spread; yet at the same time forget to create a dedicated GPG signature for the throwaway nym? I don’t think that tracks.
It is more likely that this was a random identity created at DEFCON by Gray, probably in a random bout of paranoia. An identity which he continued to use for certain projects over the years. Pseudonymous identities are not unusual in Bitcoin developer circles after all. Satoshi himself remains the most famous example. And so on its own, this connection between Gray and Switch arguably does not amount to much in the hunt for the Coldcard hacker.
MicroPython Contributors
A handful of other open source developers have also been recently identified as having touched or influenced code that played a role in the Coldcard RNG bug.
Data Analyst LaurentMT has examined the MicroPython side of the RNG path. MicroPython is a lean and open-source implementation of Python 3, designed to run on microcontrollers and resource-constrained computers. The Coldcard firmware ultimately called MicroPython’s Yasmarang pseudo-random number generator (PRNG) fallback as a result of the bug, leading to low-entropy generation.
The code changes to the PRNG logic in MicroPython began on August 20, 2020, with issue (#6347) opened on GitHub by a user named ‘mirko’. He complained that his ESP32 hardware was always returning the same result when calling the ‘random.choice()’ function in the code in a certain way. Mirko expected random results instead. The GitHub issue logs a discussion over the following months about the proper way to handle the related logic and expected behavior, which Mirko revealed to have a counterintuitive design.
Laurent points out that “robert-hh initialized a [Pull Request] implementing the PRNG seeding change” on August 22, 2020. Dpgeorge, a maintainer of MicroPython, later on October 29, 2020, merged a slightly modified version of that pull request to the master repository, implementing “the (UID+SysTick+RTC) to address some limitations in robert-hh’s solution.”
The changes to this critical RNG-related code were thus on the master repository of MicroPython when Coldcard forked it to be used by Libngu, yet before MicroPython had made an official new version release of the library. Apparently, it is considered risky to build on top of the master version of a software repository, which is likely to be evolving with code changes, rather than build on top of an official, stable release version. The new release of MicroPython did not come until February 3, 2021, with version v1.14. To top it off, the RNG logic change was only briefly mentioned in the release announcement, saying “the urandom module will randomize its seed on import on stm32, esp8266, esp32 and rp2 ports.”
In an interview with Bitcoin Magazine, Laurent concluded in no ambiguous terms that “without this modification the bug in Coldcard code would have been immediately detected.” Commenting on the series of events that led to the bug, he also said that “there are a lot of ‘coincidences’ in this timeline,” adding that “while they don’t prove anything, I don’t see how an official investigation may completely ignore them.”
It is important to note that there is no evidence any of the developers mentioned above were intentionally trying to introduce the Coldcard RNG bug with these changes, and ultimately, it is Coinkite, the hardware wallet company, that is responsible for their implementation of the critical code. MicroPython is a large, widely used open-source project. Nevertheless, there are likely many lessons to be learned from what we might as well call — for the time being anyway — a tragic comedy of errors.
Why an Inside Job Appears Unlikely
Several factors cut against a deliberate, long-planned insider retirement attack. The ‘switck’ identity was poorly compartmentalized; the shared GPG key and other overlaps made attribution to Doc-Hex aka Peter Gray, relatively straightforward once researchers looked. The account had been largely abandoned for years. The MicroPython contributors operate in the open on a high-visibility project.
Hodlonaut’s Citadel21 investigation and other technical reviews find no clear evidence that the entropy failure was intentional. Engineer Alekos Filini’s technical report on the bug explicitly tracks the technical facts, stating that “My goal is to purely present facts and NOT make any conclusions.” Wizardsardine detailed on their Technical autopsymultiple failed safeguards and describes the failure as sitting “across a submodule boundary, which is precisely where reviewers stop looking.”
If the drains had been a classic insider retirement attack, or a long con as some might call it, the conversation today would be quite different. The last time we saw a major long con hack in the Bitcoin industry was probably QuadrigaCX, a centralized Canadian exchange whose founder, Gerald Cotten, was reported “dead in India” in 2018 amid mysterious circumstances, not long after the missing funds were discovered. The founders are accused by the Ontario Securities Commission of having misappropriated the exchange users’ deposits totaling almost 170 million CAD, over many years, before disappearing.
Instead, Coinkite’s leadership remains publicly active, responding to the incident, shipping patched firmware, assisting user migrations, and engaging on the technical details. Coinkite’s founders and operators are fairly well known and are still operating the company as of the time of writing; they have not disappeared at the same time as the funds went missing.
Meanwhile, the wave 1 funds, totaling over 1000 BTC, are still collected in three addresses, watched by hundreds of engineers and likely law enforcement such as the FBI. Were Coinkite trying to do a 5D chess-style retirement attack, they would have been far more careful in their theft of the coins. They would not have pooled them all to a handful of addresses that are easy to track, and its founders would probably be ‘mysteriously dead in India.’
While there are no conclusions and investigations will likely be ongoing for years, so far, evidence points to a cultural failure in the Bitcoin maximalist and self-custody community, a failure to broadly educate the users and influencers about good or bad etiquette in open-source culture, and frankly, arrogance on the part of Coinkite OG’s who, in hindsight, were overconfident about their own capabilities.
Hackers started taking bitcoin stored using Coinkite’s popular Coldcard hardware wallet on July 31.
Canadian company Coinkite said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator, allowing hackers to essentially guess investor seedphrases.
The number has slowly risen as the criminals have targeted more recent devices while Coinkite and other Bitcoiners have urged Coldcard users to immediately move their funds.
Galaxy Research last week said that it estimates at least 15 separate attackers were exploiting the bug independently.
Previous research from Galaxy found that the typical stolen coin had sat untouched for 3.5 years, and a striking 88% of pilfered funds were at least a year old.
The firm is still confirming how much is stolen, and has said that total losses could exceed $130 million.
Since the attack, cautious investors have been moving their coins to other storage solutions — including exchanges.
Coinkite said in a statement this week that the bug in its software “silently went unnoticed” and “its potential impact grew with every release” of its products.
Days after the first hack, the company urged investors to update their software or move their funds off the popular hardware wallet.
Hardware wallet manufacturer Trezor has announced a data breach exposing customer data.
Writing on X Thursday, the company said that 13,689 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order 90 days prior to August 8 were affected.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
“Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts,” the Prague, Czech Republic-based company said. “We are deeply sorry to the community and those affected.”
Trezor said that 11,742 customers had their names, emails, phone numbers, and shipping addresses leaked. Another 1,947 customers had just their names, cities and emails exposed.
SatoshiLabs, the parent company of Trezor, said in an email to Bitcoin Magazine that its third-party fulfillment partner, ShipMonk, had experienced “unauthorized access to their systems containing customer data.”
“Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor,” the company said.
SatoshiLabs said it was continuing to investigate the incident.
Trezor is one of the most popular Bitcoin hardware wallet solutions, and also has support for storing other cryptocurrencies.
Bitcoiners’ personal data has been targeted by cybercriminals in the past: back in 2020, an unauthorized party accessed popular hardware manufacturer Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers.
And at the start of this year, customers reported receiving emails from Global-e, Ledger’s payment partner, that a data breach at its cloud systems leaked sensitive customer data.
The Bitcoin community is still reeling after hackers targeted Canadian company Coinkite’s popular Coldcard product.
Hackers started draining $111 million in Bitcoin from the popular Coldcard hardware wallets at the end of last month.The amount stolen could be much higher as investigations continue, with some estimating the real figure to be over $130 million.
The theft continued, with Bitcoiners — and Coinkite — asking users to move their funds as hackers continued to drain digital coins from the later devices.
Supporters of BTCPay Server have committed to funding a bounty of up to three Bitcoins for the recovery of funds stolen through a recently disclosed vulnerability in the open-source bitcoin payment processor, the project said in a statement.
The bounty is set at 10 percent of whatever is recovered, capped at three coins in the event of a full recovery.
The project even extended the offer to the attacker directly alongside anyone else holding actionable information, directing them to a dedicated security address and offering Signal or other encrypted channels on request.
Hackers last week managed to extract Lightning Network admin macaroon credentials from affected BTCPay Server instances. The project published technical details and remediation guidance in a separate security advisory.
“To the users who lost funds: we are sorry,” the project said in a statement. “We will examine our mistakes, but regret alone will not help affected users or secure the project. There is no time to waste. We have to learn, improve, and act quickly.”
The BTCPay Server Foundation said it would donate 0.21 Bitcoins to Sparrow Wallet developer Craig Raw and a further 0.21 Bitcoins to the Bitcoin Red Team fund in recognition of their responsible disclosure of the vulnerability.
Separately, the project said it has been contacted by security teams at exchanges, blockchain analytics firms and law enforcement agencies offering assistance in tracking the stolen coins.
Affected users who have not yet come forward are being asked to share on-chain addresses and transaction details, and to file reports with local authorities and any exchange or service where the funds surface.
Individual reports, the project said, help preserve records and establish a chain of evidence that improves the odds of funds being frozen.
The project added that improving AI models are making it faster and cheaper to comb large codebases for weaknesses, shifting the balance toward attackers, and that Bitcoin projects are feeling it first because they are unusually valuable targets.
New analysis of Bitcoin theft reports reveals that stolen funds overwhelmingly came from long-dormant wallets, with victims reporting a median loss of over one coin.
Data posted on X from Galaxy Research’s Alex Thorn looked at 250 victim reports and found the typical stolen coin had sat untouched for 3.5 years, and a striking 88% of pilfered funds were at least a year old.
By address, losses ranged from a median of 0.014 Bitcoin to a mean of 0.212 Bitcoin, while individual victims reported a median loss of 1.022 Bitcoin and an average of 4.04 Bitcoin — with one unlucky holder losing as much as 58.97 coins.
Hackers started by taking over $35 million in Bitcoin from wallets last week Thursday. Coinkite, which makes Coldcard, said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator, allowing hackers to essentially guess investor seedphrases.
The theft continued throughout the weekend while Coinkite and other Bitcoiners urged Coldcard users to immediately move their funds.
Galaxy Research said Friday that a total of $111 million has been confirmed stolen but the number could be much higher as it continues its research.
“We have many more coins we are vetting for confirmation — we think total losses likely exceed $130 million,” the firm wrote on X.
Since the attack, cautious investors have been moving their coins to other storage solutions — including exchanges.
Coinkite said in a statement this week that the bug in its software “silently went unnoticed” and “its potential impact grew with every release” of its products.
Days after the first hack, the company urged investors to update their software or move their funds off the popular hardware wallet.
The whales are on the move. An O.G. Bitcoin address holding 500 coins — worth $31.8 million at today’s prices — shifted its stash on Tuesday after not budging for 12 years.
Blockchain data shows that the legacy Bitcoin address moved all the funds in one go, paying just 191 sats, or $0.12, in transaction fees.
First flagged by Lookonchain on X, the address piqued Bitcoiners’ interest due to the recent wallet drainage happening with Coldcards, with some speculating that the HODLer moved the funds to a safer place.
Hackers last week started taking over $35 million in Bitcoin from wallets after discovering a vulnerability in the Coldcard wallet product software.
Now, the amount drained could stand at $130 million, according to Galaxy Research, which said Monday that it was investigating a fourth wave of attacks.
Bitcoin that sits still for so many years is often attributed to lost coins — amateur investors often forget the private keys to their digital wallet.
But whales — an investor or investors holding over 1,000 Bitcoins — occasionally move funds after many years, leading to big market moves as other investors often expect a big sale.
Sometimes whales are just moving their Bitcoin to a hardware wallet or consolidating their coins.
Following the Coldcard security issue, Bitcoiners have been urging investors to get their coins to a new security setup. Coinkite, the company behind Coldcard, said on Sunday that all of its models were now vulnerable following more thefts.
Engineers have warned that all Bitcoin addresses related to Coldcard could be at risk eventually.
Hackers continue to drain Coldcard Bitcoin wallets, with the total amount stolen now estimated to be standing at over $114 million.
A fourth wave of attacks likely started on Sunday evening, according to Galaxy Research’s Alex Thorn. Posting at around 7:50pm in New York, he revealed then that 388.9 Bitcoins worth over $29 million had been moved in new transactions that were highly likely to be part of the theft.
Hackers started by taking over $35 million in Bitcoin from wallets on Thursday. Coinkite, which makes Coldcard, said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator, allowing hackers to essentially guess investor seedphrases.
The theft continued throughout the weekend while Coinkite and other Bitcoiners urged Coldcard users to immediately move their funds.
Posting on X on Monday, Trezor’s Josef Tětek wrote that the biggest transaction in the ongoing theft so far was 51 Bitcoins.
The biggest drained address (so far) is 51 BTC. Damn. Imagine owning 50+ btc in cold storage and losing it all. Must be absolutely crushing. pic.twitter.com/qu6CiQOjeV
Coinkite has since admitted all of its models were vulnerable following more thefts. Engineers have warned that all Bitcoin addresses related to Coldcard could be at risk eventually.
The company said Sunday that it was asking “hard questions about our company.”
“The last three days have been some of the hardest in this company’s history, and for a lot of the people reading this, they’ve been something much worse,” Coinkite said.
“Money that took years to save, gone. Trust that took years to build, broken. That impact is real, and for some, the damage is permanent.”
The company added that it had destroyed its remaining Coldcard inventory manufactured with the vulnerable firmware, and shipments of the product have been halted.
Coinkite makes a number of Bitcoin products, including the popular cold storage hardware wallets.
Engineers at payments company Block investigated the hack and reported that the hackers used a top blockchain services provider for help in moving the funds, and that they’ve contacted the provider and federal authorities with their findings.
The Attack and Local Impact Over the weekend of July 26 and July 27, 2026, a coordinated cyberattack struck deep into local infrastructure, hitting operational technology across more than 30...