On July 30, 2026, Coinkite published a security advisory that confirmed the worst kind of bug a wallet can have: for five years, Coldcard devices had been generating seed phrases with far less randomness than advertised. In a single 25-minute window, one entity swept 594 BTC from roughly 500 addresses . By August 2, on-chain analysts had traced over 1,300 BTC — roughly $89 million — drained across more than 4,500 addresses .