7OrStone

Market Prices

BTC Bitcoin
$64,935.5 +1.17%
ETH Ethereum
$1,919.31 +2.44%
SOL Solana
$74.38 +0.35%
BNB BNB Chain
$599 +0.96%
XRP XRP Ledger
$1.07 -0.53%
DOGE Dogecoin
$0.0703 +0.10%
ADA Cardano
$0.1902 -1.50%
AVAX Avalanche
$6.69 -0.36%
DOT Polkadot
$0.8487 +0.35%
LINK Chainlink
$8.2 +0.21%

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$64,935.5
1
Ethereum ETH
$1,919.31
1
Solana SOL
$74.38
1
BNB Chain BNB
$599
1
XRP Ledger XRP
$1.07
1
Dogecoin DOGE
$0.0703
1
Cardano ADA
$0.1902
1
Avalanche AVAX
$6.69
1
Polkadot DOT
$0.8487
1
Chainlink LINK
$8.2

🐋 Whale Tracker

🟢
0xb660...0ba1
30m ago
In
1,515,235 DOGE
🔴
0x2954...e473
30m ago
Out
470,550 USDC
🔴
0xfaa8...3ac1
1d ago
Out
4,242 ETH

Coldcard's $130M Entropy Failure: The Exploit Nobody Audited

NFT | StackSignal |
Fifteen attackers. 7,300 wallets. $130 million in Bitcoin — gone, or about to be. The exploit wasn't a zero-day in a DeFi bridge or a governance attack on a DAO. It was Coldcard — the hardware wallet preferred by the most paranoid Bitcoiners in self-custody — generating private keys with an entropy source weaker than a shuffled deck of cards. Galaxy Research identified 73 confirmed victims when its report went public, but its own analysts admit the actual number is likely in the thousands. The attackers aren't stopping. Every hour, more join the scan. The first thefts occurred hours before Coinkite published its warning — meaning somebody knew about this weakness before the vendor did. There is no firmware fix that will restore the compromised seeds. There is only migration. Coldcard has never been a consumer product. It's the professional-grade device for the meticulous Bitcoin holder — the one who refuses to trust exchanges, rejects "user-friendly" interfaces as attack surfaces, and stores seed phrases in fireproof safes. Coinkite built its reputation on uncompromising security. Air-gapped operation. Open-source firmware. No cameras, no Bluetooth, no complexity where complexity creates attack surface. For years, that positioning was accepted as fact. The exposed reality is structural. In affected firmware versions, the seed generation routine routes through MicroPython's software pseudorandom number generator — a PRNG never designed for cryptographic key generation — instead of the hardware's true random number generator. The numbers are damning: the Mk2 and Mk3 generate approximately 40 bits of entropy. The Mk4 generates approximately 72 bits. The industry standard for key generation is a minimum of 128 bits. This is not marginal underperformance. It's a failure of the central security premise that justified the product's existence. The attack vector is trivial once the weakness is known. Bitcoin's blockchain is a public ledger of every address and every unspent transaction output. Attackers need no special access, no vulnerability in Bitcoin itself, no interaction with the victim. They scan the ledger, identify addresses with weak private keys, and brute-force them. The cost is largely computational — and that cost is negligible against the prize. Coinkite shipped a hotfix across all affected models and release tracks. Co-founder Rodolfo Novak publicly apologized. The response was fast, transparent, and entirely insufficient. Because the firmware update prevents new seeds from being generated with low entropy. It does not and cannot repair seeds already generated by the vulnerable code path. Coinkite's own documentation is unambiguous: affected users must move their Bitcoin to a new wallet, created by secure software, on a device that never touched the compromised firmware. Based on my audit work — including an eight-week sprint through 0x protocol v2's exchange contracts in 2018, where the project's own auditors missed three reentrancy vectors — the first question I ask after any incident is always the same: what did the design assume, and where did that assumption break? Coldcard's design assumed the hardware RNG would always be available. The firmware's fallback to software PRNG is a classic silent failure: the code path executes correctly, the random values look random, and no error surfaces to the user. Every seed generated through that path carries the flaw invisibly. The device continues to function. Transactions sign normally. No cracked screen, no warning message. In code, silence is the loudest vulnerability. The difference between 40 bits and 128 bits is not a matter of degree. It's a difference in kind. Forty bits is roughly 1.1 trillion possible values. That sounds mathematically intimidating to a layperson — until you remember that the Bitcoin network itself computes hashes at exahash rates, and that modern GPU miners are optimized for exactly this kind of parallel brute-force work. An attacker scanning for weak Coldcard keys is not guessing. They are sifting through a file cabinet where thousands of drawers are already open. The Mk4's 72-bit entropy is better, but not meaningfully better. It expands the search space to roughly 4.7 septillion possibilities. Against distributed computing resources and enough time, that is still within reach — and the attacker holds the advantage that matters most: the entire public key set is available to search, while earlier generations of the same device fall at a far lower threshold. The blockchain remembers, but the auditors forget. How many affected wallets are still out there, untouched and unchecked? Galaxy's count of 7,300 addresses is a lower bound, not a census. The gap between 73 confirmed victim reports and "potentially thousands" is where long-term holders live. People who generated seeds in 2019 and haven't opened the device since. People who bought Coldcard because a trusted figure on YouTube recommended it. People who stored their recovery phrase in a bank vault precisely to avoid touching their keys. The actual exposure is unknowable right now — and the unknown is the part that should keep the market uncomfortable. I watched this pattern unfold during DeFi Summer 2020, when Yearn's vaults showed anomalous gas patterns suggesting oracle manipulation. The lesson from that incident remains unchanged: markets don't collapse when the vulnerable protocol gets exploited. Markets collapse when users realize the trust layer they believed in was never load-bearing. Here, the trust layer is not a smart contract. It is a physical device held in the user's hands, advertised as the last defense against the chaos of the internet. Coinkite's response deserves credit on disclosure: the hotfix was pushed within hours, the public announcement came immediately, and the recommendations were explicit about severity. This is more transparent than most teams I have audited. But transparency does not move funds. The hotfix is a bandage on a severed artery. The economics of the stolen funds complicate the picture. Ninety percent of the stolen Bitcoin has not moved. That is a deliberate signal. Attackers are not panicking, not dumping, not converting to stablecoin on a public exchange. They are holding — waiting for better market depth, preparing laundering routes through mixers or chain-hopping services, or simply patient enough to sit on the funds until the heat dies down. The ten percent that has moved is a breadcrumb trail for investigators. The ninety percent is a floating structural overhang — not meaningful against Bitcoin's daily volume in the short term, but a known pressure point that can be weaponized at any moment. Liquidity is a mirror, not a vault. It reflects the expectations of whoever holds it. Right now, the attackers holding ninety percent of the stolen funds are demonstrating the same patience as a long-term Bitcoin investor waiting for a better exit price. The attacker count itself is a diagnostic. Fifteen attackers when Galaxy published. That number is already higher. Each scan is a race: multiple adversaries hunting the same weak-key space, all aware that the opportunity window shrinks with every wallet migrated and every address swept. This is not a finite pool of sophisticated criminals. It is an open-source exploit opportunity, published in broad daylight. Now the uncomfortable part: the bulls got some things right. Coinkite's disclosure and response speed exceeded the industry norm. I have seen vulnerabilities suppressed for months, patches shipped silently, and affected users never notified. Novak's public statement took responsibility. The hotfix covered all affected models within a short window. For an industry that usually learns of critical failures from security researchers — not vendors — this is the rare case of a manufacturer publicly admitting fault before being forced to. The second detail the market is getting wrong: this failure does not invalidate self-custody, nor does it condemn hardware wallets as a category. Ledger and Trezor ship secure elements with dedicated true random number generators; their known implementation paths do not fall back to software PRNG for key generation. The failure is specific to Coldcard's firmware architecture, not to the entire hardware wallet design philosophy. It attacks the premise that "any device is better than a hot wallet" — but it does not prove that all devices are equivalent. And here is where most analysts miss the deeper point. Users who distributed their trust — multi-signature schemes, seeds split across different hardware providers, regular verification of addresses — are functioning exactly as designed. The users harmed are those who placed absolute faith in a single vendor, a single device, a single point of failure. That is a behavioral failure amplified by technical failure. Logic is binary; trust is a spectrum. The people who treated their Coldcard as gospel, rather than as one component in a layered security model, were the real attack surface. If you or anyone you know generated a Coldcard seed on the Mk2, Mk3, or Mk4, the instruction is not to update the firmware. It is to move the Bitcoin. Now. The hotfix prevents new weak seeds. It does not protect old ones. Coinkite has said it plainly. Galaxy has said it plainly. The attackers are reading the same reports, and they can calculate exactly how many wallets have not yet migrated. The industry question following this incident: how do we mandate entropy-source verification for every hardware wallet that claims to offer self-custody? Not marketing claims, not "audited by a trusted partner" — actual, reproducible evidence that the random number generation path can never silently fall back to a software PRNG. The uncomfortable reality is that you didn't lose funds yet. That is not proof of safety. It is proof that the scanner hasn't reached your address. The blockchain remembers what the firmware generated. The question is whether the auditors will learn to check.

Coldcard's $130M Entropy Failure: The Exploit Nobody Audited

Fear & Greed

27

Fear

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xc36e...e3e3
Arbitrage Bot
+$4.2M
85%
0x24a4...4038
Arbitrage Bot
-$1.6M
63%
0xb718...808e
Early Investor
+$1.0M
67%