Newsroom
12 August, 2026 / News / AI / Tags: casa, neuman, firmware, coldcard, seeds

Following a major hardware wallet vulnerability that drained roughly 2,100 BTC, on-chain data shows 233,000 BTC left long-term holder addresses as users secured their funds
A firmware flaw in Coldcard hardware wallets has led to the theft of approximately 2,100 bitcoin, valued near $130 million, across multiple attack waves that began on July 30. The vulnerability originated in a March 2021 update affecting firmware versions 4.0.1 through 4.1.9, which routed seed generation through a weakened software random number generator rather than the device’s dedicated hardware chip. This reduced cryptographic strength substantially, leaving private keys far more predictable than intended.
Canadian manufacturer Coinkite has advised all users who generated seeds on the affected firmware to treat those wallets as compromised and migrate funds to new seeds without delay. Updating the firmware does not repair existing seeds created under the flawed process.
While attackers continued draining vulnerable addresses one by one, long-term holder wallets—those dormant for at least 155 days—saw roughly 233,000 bitcoin exit in the days surrounding the incident. At prevailing prices, that volume equated to about $15 billion. An additional 22,000 bitcoin moved toward exchanges during the same period.
Data tracked by on-chain analysts placed confirmed losses from the entropy flaw between roughly 1,700 and more than 2,000 bitcoin across several thousand addresses. Galaxy Research documented multiple distinct attack waves, with the higher end of estimates approaching the $130 million mark.
Casa CEO Nick Neuman pointed to these figures as evidence that distributed self-custody enabled a rapid, network-wide reaction. He noted that the volume shifted to safer arrangements ranged between roughly 10 and 100 times the amount stolen.
Conversations with Casa customers indicated that the 233,000 bitcoin movement included several distinct patterns. Some Coldcard users transferred holdings into multisignature setups, which require multiple independent keys to authorize transactions and thereby limit the impact of any single compromised device. Other flows involved holders of non-Coldcard single-signature wallets, including those using Ledger or Trezor devices, who upgraded to multisig after reassessing the risks of single-key arrangements. In additional cases, existing multisig users removed Coldcard devices from their key sets.
Neuman contrasted the outcome with a hypothetical breach of a centralized custodian. In that scenario, he argued, the proportions would likely reverse: only a limited amount might escape while the majority would be lost in one event. Because funds were held individually, attackers had to target wallets separately, earning incremental amounts while the broader set of holders retained the ability to act independently.
Analytics firm Glassnode recorded a decline in long-term holder supply from nearly 15 million bitcoin to approximately 14.7 million, representing the largest weekly drop since December 2024. The shift occurred while bitcoin traded roughly 50 percent below its October 2025 all-time high near $126,000.
The episode has renewed industry discussion around single-signature hardware wallets, key-generation practices, and the comparative strengths of multisignature arrangements. Casa, which offers multi-signature vault solutions for higher-value holders and institutions, reported increased interest in upgrading from single-key setups.
Coinkite continues to urge immediate migration for any seeds generated on the vulnerable firmware range. The incident demonstrated that while specific device flaws can produce localized losses, the ability of holders to move funds independently constrained the overall systemic impact and allowed a far larger volume of bitcoin to reach safer configurations.









