Summary
On the evening of 29 July, one holder watched 18.25245043 BTC leave every wallet he owned in seven minutes. “Perhaps the hardest part about this is that I did everything right,” he wrote afterwards.
Sara K. takes that at face value and works out where the failure actually happened.
Not at the device. A hardware wallet's most consequential job takes about a second: at setup it asks a chip for random numbers and derives the recovery phrase from them.
In Coldcard firmware from March 2021, a build-flag check tested whether a setting existed rather than whether it was enabled, leaving the generator producing a small, reconstructable set of seeds.
So nobody was hacked. The attacker rebuilt the flawed generator, enumerated the seeds it could produce, derived the matching addresses and waited.
Coinkite published an advisory and shipped a fix within days, with its co-founder stating publicly that the company takes responsibility.
The article is careful about what this does not prove. Bitcoin's cryptography was never touched. Air-gapping held — the device leaked nothing because the attacker needed nothing from it.
And it is not a case against hardware wallets: owners who supplied their own dice rolls were outside the blast radius entirely.
What it is, the piece argues, is the fifth appearance of one failure in different clothes, going back to a 2013 flaw in Android's random number generator.
None were failures of locks; all were failures in the factory that made the keys, with the code open and readable the whole time.
simpleswap.io's Head of Infrastructure Stefan Lauer supplies the line the article turns on: randomness is the least glamorous part of any crypto product and the only one that cannot be fixed later.
The closing argument follows from it — self-custody was the first step, not the last, because a key can be yours and still be badly made.
“Randomness is the least glamorous line in any crypto product, and it is the only one that cannot be fixed later.”
Key Takeaways
- A 2021 Coldcard firmware flaw left the seed generator producing a small, reconstructable set of keys.
- One holder lost 18.25 BTC in seven minutes despite following every recommended practice.
- Bitcoin's cryptography was untouched and air-gapping held; the failure was upstream of both.
- Owners who added their own dice rolls at setup were unaffected.
- The same class of failure has appeared at least five times, starting with Android's RNG in 2013.
- Stefan Lauer of SimpleSwap: randomness is the one part of a crypto product that cannot be fixed later.







