A firmware bug in Coldcard hardware wallets, introduced in March 2021, routed seed generation to a weak software pseudorandom number generator instead of the device's hardware RNG, resulting in significantly reduced entropy and predictable wallet seeds. On July 30, an attacker exploited this vulnerability to drain 1,082.65 BTC (~$70.2 million) from 1,196 addresses in just 41 minutes. Coinkite released emergency firmware on July 31, but existing seeds remain compromised, and affected users must generate a new seed on patched firmware and transfer their funds.