MPC-lab

Market Prices

Coin Price 24h
BTC Bitcoin
$79,239.8 -2.17%
ETH Ethereum
$2,467.2 -2.49%
SOL Solana
$97.52 -4.63%
BNB BNB Chain
$698.2 -2.85%
XRP XRP Ledger
$1.45 -5.70%
DOGE Dogecoin
$0.0869 -6.35%
ADA Cardano
$0.2130 -6.86%
AVAX Avalanche
$7.42 -3.70%
DOT Polkadot
$0.8581 -6.81%
LINK Chainlink
$11.42 -4.12%

Fear & Greed

65

Greed

Market Sentiment

Event Calendar

{{ๅนดไปฝ}}
12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All โ†’
1
Bitcoin
BTC
$79,239.8
1
Ethereum
ETH
$2,467.2
1
Solana
SOL
$97.52
1
BNB Chain
BNB
$698.2
1
XRP Ledger
XRP
$1.45
1
Dogecoin
DOGE
$0.0869
1
Cardano
ADA
$0.2130
1
Avalanche
AVAX
$7.42
1
Polkadot
DOT
$0.8581
1
Chainlink
LINK
$11.42

๐Ÿ‹ Whale Tracker

๐Ÿ”ต
0xab63...ee79
6h ago
Stake
4,587,476 USDC
๐Ÿ”ด
0xa4b9...8ddd
2m ago
Out
957.95 BTC
๐ŸŸข
0x027b...3a76
12h ago
In
2,208.57 BTC

๐Ÿ’ก Smart Money

0x3139...a4e9
Institutional Custody
+$3.6M
67%
0x0cce...f341
Institutional Custody
+$2.2M
75%
0xd9ee...111e
Institutional Custody
+$0.6M
65%

๐Ÿงฎ Tools

All โ†’
News

Coldcard's $130M Entropy Failure: The True Cost of Trusting Hardware

PlanBtoshi
Breaking: 15 attackers are now actively draining vulnerable Coldcard wallets. Over $130 million in Bitcoin has been swept from at least 7,300 addresses. Galaxy Research confirms the attacker count is growing daily. The first thefts occurred hours before Coinkite publicly admitted the flaw. This is not a drill. This is an entropy catastrophe. The affected devices: Coldcard Mk2, Mk3, and Mk4. The root cause: firmware routing seed generation to MicroPython's software PRNG instead of a true random number generator. Entropy levels range from 40 to 72 bits. The security floor is 128 bits. This isn't a rounding error. This is a brute-force invitation. I've been tracking this since the first on-chain sweep. I audited the Parity multi-sig vulnerability in 2017, and I can tell you: this is worse. In 2017, a critical bug was exploitable after deployment. Here, the product shipped with a built-in probabilistic theft vector. The market hasn't priced this properly. Bitcoin price impact is muted so far. The real damage is to the self-custody narrative. Coldcard, manufactured by Coinkite, has long been the security purist's choice. It's the hardware wallet for the Bitcoin-only maximalist who distrusts everything. No screens, no Bluetooth, no wireless. Just a USB device with a secure element and a microSD slot. Its entire value proposition is trust in the entropy source. That trust just collapsed. Galaxy Research first disclosed the vulnerability. They found that a subset of Coldcard wallets had private keys derived from insufficient entropy. The culprit: a fallback mechanism in the firmware. When the hardware's dedicated entropy source failed, the system degraded to MicroPython's software PRNG. Instead of 256-bit security, some wallets got 40 bits. For context, 40 bits is roughly one trillion possibilities. A modern GPU cluster can exhaust that space in hours. The blockchain is public. Attackers scan for public keys tied to weak private keys. Coinkite's co-founder, Rodolfo Novak, issued a public apology. A hot fix was pushed to all affected models. But here's the catch: updating firmware does not fix seeds generated by the vulnerable firmware. The damage is irreversible. Every user who generated a seed on an affected device must migrate their Bitcoin to a new wallet created on hardware with a verified true random number generator. That's not a simple task. It's a panic migration. Galaxy has received 73 victim reports. But the actual number could be in the thousands. Many long-term holders haven't checked their wallets recently. They've been storing coins for years, not looking at movements. The attackers are counting on that. The attacker count is increasing every day. This is a race between thieves and victims. Galaxy identified more than 7,300 wallets at risk. The total balance exceeded $130 million when the research was compiled. Attackers have already drained a significant portion. But 90% of the stolen funds remain unmoved. That's not laziness. That's strategic positioning. The attackers are holding their loot, watching the market. They are not selling into a crash. They are waiting for liquidity to build, or for attention to fade. This is exactly what sophisticated adversaries do. From my 2020 Yearn.finance work, I learned that yield is a function of trust, not just math. The same applies to self-custody. The trust in Coldcard's entropy source is the underlying asset here. When that trust is gone, the value of every wallet created on that device is potentially zero. The hot fix is a band-aid on a bleeding artery. The firmware excuse is irrelevant. The hardware had one job: generate randomness. It failed. The entropy values are damning. Mk2 and Mk3 devices: approximately 40 bits of entropy. Mk4: approximately 72 bits. Both are catastrophically low. The industry standard requires at least 128 bits for cryptographic key generation. A 72-bit key is not brute-forceable with a single computer, but it is with a botnet or a large-scale GPU cluster. The attacker count of 15 and rising suggests that the barrier to entry is low. The tools are simple. Scan the blockchain, identify public keys, run a brute-force search. There's a deeper implication often overlooked. The use of MicroPython's PRNG as a fallback means the hardware's dedicated TRNG was either not available at runtime or was bypassed by an error-handling path. This is a design flaw, not a one-off bug. The firmware architecture likely has a failure mode where the system degrades to insecure software randomness instead of halting the process. In security-critical systems, the correct response to a TRNG failure is to abort key generation, not silently fall back. Coinkite needs to release a full technical post-mortem. Until they do, no one should trust their current firmware. Also, the affected wallet count is likely undercounted. Galaxy's 7,300 figure is based on publicly detected addresses with vulnerable characteristics. But there could be hundreds of thousands of wallets generated on Coldcards that haven't made any transactions yet. Those are not visible in the same scan. They exist in a hidden state, dormant and vulnerable. Every single user who has ever used a Mk2, Mk3, or Mk4 Coldcard must assume their seed is compromised until proven otherwise. The only safe action is to migrate funds to a new address generated by a completely different device. The market impact of the stolen funds is nuanced. If the hackers decide to move their 90% holding, they could cause a sell-side shock. But $130 million is relatively small compared to Bitcoin's daily trading volume of billions. However, the psychological impact is not small. This is the second major self-custody crisis in recent memory. The BAYC crash wasn't about art; it was about liquidity. This Coldcard event isn't about convenience; it's about entropy. Now the contrarian angle. This event is an unintended endorsement of centralized custody. The self-custody crowd will scream 'not your keys, not your coins.' But for the average Bitcoin holder, losing funds via a hardware wallet bug is no better than losing them on an exchange hack. In fact, it's worse: no insurance, no recovery process, no one to sue. The unintended consequence of this event will be a migration of weak-handed holders back to regulated custodians. That increases counterparty risk. Exchange inflows will tick up. I've seen this pattern after Mt. Gox, after Bitfinex, after every major self-custody failure. The immediate reflex is to run to the perceived safety of a trusted third party. That's a mistake. Another blind spot: the 90% unmoved funds. The attackers are not amateur thieves. They are patient, methodical, and clearly capable of advanced crypto-forensics. They are likely using mixers, cross-chain bridges, or OTC desks to launder the assets slowly. When they eventually move the funds, they will do so in a way that maximizes extraction value. This is not a one-time theft; this is a new whale wallet that will overhang the market for months. The market has not priced this in. Bitcoin may trade flat, but stolen coin inventory is a volatile variable. And here's the key point: Coinkite's response is not enough. Apologizing and pushing a hot fix is the bare minimum. The real test is whether they will release a full root-cause analysis, a public code audit, and a compensation plan for victims. If they don't, the entire hardware wallet industry will face a crisis of confidence. The winners will be manufacturers who can demonstrate verifiable TRNG integration and independent audits. The losers will be those who rely on trust. 17 reveals the true cost of trust. Speed without precision is just noise; the market doesn't wait. Right now, every Coldcard user must act with urgency. Do not update the firmware and assume you are safe. You are not. Move your funds to a new wallet generated on hardware with a verified entropy source. And for the rest of the market: treat this as a systemic warning. The next vulnerability will not be in a smart contract; it will be in the hardware you hold in your hands. Ask the question: what does your wallet do when its randomness source fails? If the answer is 'it keeps going,' then your coins are not safe. The industry needs an entropy audit standard. Every hardware wallet should have a public, auditable entropy verification process. Until then, the true cost of trust will keep escalating. The question is: are you willing to pay it?