Concept illustration of a hacked hardware wallet. ASTIG.PH, 2026.

Is the COLDCARD hack an inside job? The math says probably not, but the shadow is bigger than you think

Somebody knew. That is the question burning through the Bitcoin community after the COLDCARD hack drained up to USD 100 million: somebody knew about this bug, and the question is who knew first.


Advertisements

Somebody knew. That is the question burning through the Bitcoin community after the COLDCARD hack drained up to USD 100 million: somebody knew about this bug, and the question is who knew first.

The bug shipped in March 2021. The attack came on July 30, 2026, 1,900 days later. In between, the flaw sat in plain sight, in open source code, on GitHub, waiting.

So is this an inside job? Did someone at Coinkite, or someone with the source code, exploit a bug they knew about for years? We did the math, weighed the evidence, and here is the honest probability analysis.

COLDCARD insider job probability analysis infographic

What actually happened, in numbers

Galaxy Research tracked the first wave: 1,082.65 Bitcoin, about USD 70 million, drained from 1,196 wallet addresses in 41 minutes, moved to four attacker controlled addresses.

Two more waves followed on August 1, pushing the total to roughly 1,367 Bitcoin, and CBC reports the figure has grown past USD 100 million.

Every one of those wallets generated its seed on COLDCARD firmware with a specific defect, and the attacker found the wallets, not the other way around.

The bug: a flag set to zero for 1,900 days

Here is the technical core. Block’s engineering analysis found that the production board configuration defines MICROPY_HW_ENABLE_RNG as zero, and a library bug checked whether the macro was defined rather than whether it was enabled.

The result: seed generation silently fell back to a non-cryptographic software generator for 1,900 days, initialized from the device UID and timer registers.

On Mk2 and Mk3, that meant wallet generation was deterministic for anyone who knew the UID, timer state, and call history. On Mk4, Q, and Mk5, only 32 bits of secure entropy survived, capping the seed space at 2 to the 32.

This is not a random memory corruption or a lucky guess. This is a specific, identifiable integration error that required reading the code to find.

The math: how hard was this to crack?

The Mk4 and Mk5 exposure caps at 2 to the 32, which is 4,294,967,296 possible seed states. That number looks huge, but it is tiny by cryptography standards.

A modern GPU rig can check millions of candidate seeds per second. At even 100 million checks per second, the entire 2 to the 32 space is exhausted in under a minute.

For the Mk2 and Mk3, it was even easier in theory: with the UID and timer state known, the generator was fully deterministic, meaning the seeds were not just weak, they were predictable.

The 41 minute drain of 1,196 wallets is the giveaway. That is about 29 wallets per minute, one every two seconds, which is only possible if the addresses were precomputed in advance. The attacker did the math before the attack, then swept the results.

The 1,900 day question

Here is the uncomfortable part. The bug was live in open source firmware from March 2021. Anyone with the code could have found it at any point in those five years.

So why did the attack happen exactly when it did? Three theories explain the timing, and they lead to very different conclusions.

Theory one: the attacker found it recently, like Block’s researchers did, and moved fast. Theory two: the attacker knew for years and waited for enough vulnerable funds to accumulate. Theory three: someone with the code finally turned.

The strongest evidence against an inside job

Let me be fair to Coinkite first, because the inside job theory has real problems.

The source code is public. The flaw is visible in Coldcard’s GitHub repository, and Block’s team found it by reading the code, not by receiving a tip from an employee.

The attacker’s capability also matches an external actor: they brute forced or predicted seeds, precomputed the address sweep, and executed an automated drain. Nothing about that requires Coinkite access.

And the economics favor waiting: the longer the bug stayed secret, the more wallets got funded on vulnerable firmware. An attacker who found it early would rationally wait, which explains the five year gap without any insider involvement.

The evidence that keeps the door open

But the inside job theory will not fully die, and here is why.

The bug is subtle. It is an interaction between the board config, a third party library, and MicroPython’s fallback, and finding it requires deep familiarity with the codebase. The people most likely to spot it are the people who wrote it.

Block’s own report credits “anonymous security researchers” who worked alongside them. Anonymous is doing a lot of work in that sentence, and it raises a question: were those researchers the finders, or were they involved earlier?

There is also the matter of who benefits. Coinkite sells hardware wallets, and the company moved quickly to publish advisories and fixed firmware. A swift response is exactly what a responsible vendor does, but it is also exactly what a vendor caught red handed would do.

The probability assessment

Putting all of this together, here is our honest estimate of how this happened, based on the evidence available today.

External researcher or attacker finding the bug independently: 55 percent. This is the most likely path, because the code is open, the flaw is findable, and the attacker’s methods match an external actor.

Insider or former insider involvement: 20 percent. The subtlety of the bug and the five year patience keep this in play, but there is no direct evidence of it, and the open source alternative is strong.

Researcher community leak or acquisition: 15 percent. A researcher could have found it, sold it, or had it stolen before the attack, a known pattern in the exploit market.

Supply chain or other vector: 10 percent. This covers compromised tooling, a leaked private key in the build pipeline, or scenarios we cannot see yet.

Why 55 percent is the right number

The simplest explanation is usually right, and the simplest explanation here is an external actor who read public code. The open source nature of the firmware makes insider access unnecessary.

But the honest answer is that 20 percent is not nothing. A one in five chance that someone inside, or formerly inside, knew about a wallet draining bug for years is a number the community should sit with.

The anonymous researchers, the 1,900 day patience, and the perfect timing all nudge that number up, even if none of them prove it.

What would settle it

Two pieces of evidence would end the speculation. The first is the attacker’s UID knowledge: if the drained wallets all had their device UIDs known or guessed, it points to a specific capability. If the attacker only brute forced the 2 to the 32 space, it points to a pure external crack.

The second is the origin of the anonymous researchers. If they come forward with a discovery timeline predating the attack, the insider case weakens. If their involvement traces back further, it strengthens.

Until either surfaces, the probability stays where it is: probably external, possibly inside, and definitely worth watching.

The bottom line

The COLDCARD hack is most likely not an inside job, but it is closer than Coinkite would like. Open source code, a subtle five year old bug, and a patient attacker explain 55 percent of the probability without any insider at all.

The remaining 45 percent is the uncomfortable part: insider involvement, researcher leaks, or something we cannot see. That is a large enough shadow to keep asking questions.

In security, the question is never whether you trust the people who built the thing. It is whether the thing would still be safe if you did not have to. For 1,900 days, the COLDCARD was not.


What's Your Reaction?

Wakeke Wakeke
0
Wakeke
BULOK! BULOK!
0
BULOK!
Aww :( Aww :(
0
Aww :(
ASTIG! ASTIG!
0
ASTIG!
AMP#*@! AMP#*@!
0
AMP#*@!
Nyeam! Nyeam!
0
Nyeam!
Candy Chan

Candy is a certified shop-a-holic. A communications graduate of De LaSalle University, she enjoys shopping for clothes and discovering new places to eat. She is also a certified movie and television addict, though her first love has always been music.