BREAKINGFED holds rates steady — Powell signals no cuts before Q3 2025
Skip to main content
SPX5,432.18+0.71%
NDX18,721.34+0.77%
DJI39,845.62-0.14%
BTC91,240.50+2.60%
ETH3,412.80+1.34%
GLD2,321.40+0.53%
CL79.42-1.52%
DXY104.23+0.33%
EUR/USD1.08-0.30%
AAPL187.42+1.74%
NVDA621.80+7.10%
TSLA245.30-3.31%
SPX5,432.18+0.71%
NDX18,721.34+0.77%
DJI39,845.62-0.14%
BTC91,240.50+2.60%
ETH3,412.80+1.34%
GLD2,321.40+0.53%
CL79.42-1.52%
DXY104.23+0.33%
EUR/USD1.08-0.30%
AAPL187.42+1.74%
NVDA621.80+7.10%
TSLA245.30-3.31%
Crypto

The Coldcard Catastrophe and North Korea's Crypto War: Two Crises, One Broken Summer

Alex Rivera
Alex Rivera

Senior Markets Editor

August 8, 20269 min read
Share
The Coldcard Catastrophe and North Korea's Crypto War: Two Crises, One Broken Summer

The Coldcard Catastrophe and North Korea's Crypto War: Two Crises, One Broken Summer

A Perfect Storm in Crypto Security

July 2026 will be remembered as the month when two of the darkest forces in cryptocurrency collided in the public consciousness — even if they never actually touched. On one front, a five-year-old firmware bug in Coldcard hardware wallets began systematically draining millions in Bitcoin from long-term holders who thought they were the most security-conscious users in the ecosystem. On another, North Korea's Lazarus Group continued its relentless, state-sponsored campaign of crypto theft that has already made 2026 the most devastating year for digital asset crime on record.

Together, these events have shaken the foundations of self-custody and exposed how even the most paranoid security models can collapse under the weight of a single coding error — or a nation-state's patience.


The Coldcard Hack: When "Unhackable" Hardware Betrayed Its Users

The 41-Minute Heist

At approximately 01:10 UTC on July 30, 2026, an attacker began draining Bitcoin addresses associated with Coldcard hardware wallets. By 01:51 UTC — just 41 minutes later — 1,196 addresses had been emptied of 1,082.65 BTC, worth roughly $70.2 million at the time.

The speed was surgical. The attacker used an identical hardcoded fee rate of 30 satoshis per virtual byte across every transaction — a 30-75x overpay compared to network norms — and left no change outputs, suggesting an automated script sweeping keys it already held rather than panicked owners moving funds.

But this was only the beginning. Over the following days, researchers identified additional waves of theft. Galaxy Research eventually tracked approximately 1,367.05 BTC stolen from 4,585 addresses, with total losses estimated between $88.6 million and $130 million depending on the source.

The attacker appeared to have studied its targets beforehand. Chainalysis noted that approximately $30 million was extracted in the first ten minutes alone, with one victim losing $1.8 million in a single wallet — indicating the attacker prioritized high-value targets rather than discovering them at random.

A Bug Five Years in the Making

The root cause was not a network exploit, a phishing campaign, or a supply chain attack. It was a build configuration error introduced on March 1, 2021, when Coinkite — Coldcard's Canadian manufacturer — integrated a proprietary library called libNgU into its firmware.

Coldcard devices contain a hardware-based true random number generator (TRNG) built into the STM32 microcontroller. This chip is supposed to provide cryptographically secure entropy for generating wallet seeds — the master secret from which all private keys and addresses are derived. But a faulty preprocessor check in the libngu library only verified whether a configuration macro existed, not whether it was enabled.

Because Coinkite's production configuration defined MICROPY_HW_ENABLE_RNG as zero (intending to use its own wrapper), the check passed — and the firmware silently fell back to MicroPython's deterministic software PRNG called Yasmarang. This software generator was seeded only from the device's unique ID and the hardware timer value at power-on. It collected no fresh entropy after initialization.

The consequences were catastrophic. On Coldcard Mk2 and Mk3 devices, effective entropy collapsed to approximately 40 bits — meaning only about a trillion possible seed combinations. At a rate of one million guesses per second, an attacker could brute-force the entire space in roughly thirteen days. Mk4, Mk5, and Q models fared slightly better at roughly 72 bits of entropy, but this was still far below the 128-bit minimum considered secure for BIP-39 seeds.

Critically, because the vulnerability weakened the seed itself, attackers could reconstruct private keys entirely offline — without ever touching the physical device, without phishing the user, and without any network access. They simply had to guess the seed parameters, derive the corresponding Bitcoin addresses, and check them against the public blockchain.

The Aftermath

Coinkite shipped emergency firmware updates on July 31, 2026, but the company was blunt: patching the device does not retroactively fix a seed that was already generated with weak entropy. Users must create entirely new seeds on patched firmware and move their funds. Restoring an old, compromised seed to updated firmware or a different wallet carries the weakness forward indefinitely.

The company also admitted it only maintains customer records for 120 days, making it impossible to notify most affected users who purchased devices over the past five years. Coinkite has since halted shipments of affected devices and destroyed remaining inventory with vulnerable firmware.

The psychological damage may exceed the financial. Glassnode reported that long-term holders — addresses with coins unmoved for at least 155 days — transferred roughly 210,000 BTC in the week following the disclosure, the largest such migration since December 2024. Unlike previous large LTH movements that occurred near market tops, Bitcoin was trading near $64,000 — about 50% below its October 2025 all-time high — suggesting this was not profit-taking but a mass evacuation of assets from compromised storage.


The Lazarus Group: North Korea's $6.7 Billion Crypto Army

While the Coldcard exploit unfolded, North Korea's Lazarus Group — operating under the Reconnaissance General Bureau and tracked by the FBI as "TraderTraitor" — was already deep into what analysts call the most aggressive state-sponsored cryptocurrency theft campaign in history.

The Scale of the Threat

DPRK-linked actors stole $2.02 billion in 2025, a 51% year-on-year increase, pushing their all-time cumulative haul to approximately $6.75 billion. Through April 2026, North Korean hackers accounted for 76% of all crypto hack value globally.

The February 2025 Bybit theft of $1.5 billion in Ethereum remains the largest single cryptocurrency theft in history. The attack was not a smart contract exploit but a supply chain compromise: Lazarus operators compromised a developer laptop at SafeWallet, the multisig infrastructure provider Bybit used, and manipulated the cold wallet signing process to redirect approximately 500,000 ETH to attacker-controlled addresses.

In April 2026, the same group drained $292 million from Kelp DAO and over $500 million from DeFi platforms Drift and KelpDAO combined in under two weeks.

Evolving Tactics

Lazarus has evolved far beyond simple exchange hacks. Their "Operation DreamJob" uses fake recruiter pitches and malware-laced pre-employment tests to compromise technical staff at crypto companies. In 2026, they launched the "Mach-O Man" campaign targeting macOS users — disguising malware as fake online meeting invitations and tricking crypto and fintech executives into pasting malicious terminal commands on their own devices.

The group has also industrialized fake IT worker schemes, with North Korean operatives posing as remote software developers using stolen identities and proxy interviews to gain insider access to technology and cryptocurrency firms.

Analysts forecast that by late 2026, Lazarus will deploy AI-native tactics at scale — using large language models to conduct automated rapport-building with thousands of LinkedIn targets simultaneously, and leveraging real-time AI translation to eliminate the linguistic "tells" that previously helped identify North Korean operators.


The Attribution Gap: Why Lazarus Has Not Been Linked to Coldcard

Here is where the two stories diverge — and where responsible reporting matters.

Despite the user's apparent assumption, no credible source has attributed the Coldcard hack to the Lazarus Group or any North Korean actor.

TRM Labs, one of the leading blockchain intelligence firms tracking the incident, explicitly stated: "Transaction patterns suggest multiple attackers may be involved, so TRM isn't attributing the theft to a specific actor yet." Fortune reported that "investigators have not yet linked this incident to any specific actor," noting that while recent large crypto thefts have often been attributed to state-backed groups, the Coldcard case remains unattributed. The Hacker News similarly noted: "No one has named the attacker."

The on-chain evidence actually argues against typical Lazarus tradecraft. TRM observed that the laundering pattern so far — limited consolidation, one deposit into Wasabi Wallet, and minimal movement through mixers or exchanges — looks "more exploratory than the fast, aggressive laundering typical of groups like North Korea's TraderTraitor."

Additionally, the transaction construction differs across the four identified waves of theft, suggesting multiple independent attackers may have discovered and exploited the same vulnerability — a scenario more consistent with a public or semi-public exploit than a coordinated state operation.

Why the Confusion Is Understandable

The conflation is natural. Both events dominated crypto security headlines in the same week. Both involved massive Bitcoin theft. Both exposed the fragility of systems users assumed were secure. And Lazarus has indeed targeted wallet infrastructure before — the Bybit attack compromised SafeWallet's signing interface, and analysts predict wallet SDKs and CI/CD pipelines will be priority targets in 2026.

But the Coldcard exploit was fundamentally different from Lazarus's typical operations. It required no social engineering, no malware deployment, no compromised vendor laptop, and no insider access. It was a pure cryptographic brute-force attack against a deterministic random number generator — a technical vulnerability that any skilled attacker with sufficient compute resources could exploit once the firmware flaw was understood.


What This Means for Bitcoin Self-Custody

The Coldcard incident and Lazarus's ongoing campaign represent two distinct failure modes that together challenge every assumption hardware wallet users have made.

The Coldcard lesson is that open-source firmware, air-gapped operation, and secure element chips are not sufficient if a single build configuration error can silently disable the entropy source that underpins the entire security model. As Ledger CTO Charles Guillemet observed, "Every private key you own derives from one number: the seed. If that number is predictable, everything derived from it is too."

The Lazarus lesson is that nation-state adversaries are no longer theoretical. They are the dominant force in crypto theft, accounting for three-quarters of all stolen value, and they have evolved from smash-and-grab exchange hacks to multi-month supply chain penetrations, fake employee infiltration, and AI-enhanced social engineering.

For Coldcard users, the immediate action is clear: if your seed was generated on firmware version 4.0.1 through 4.1.9 (Mk2/Mk3), or any version before 5.6.0 (Mk4/Mk5) or 1.5.0Q (Q), you must generate a new seed on patched firmware and move your funds. Do not restore your old seed. A strong BIP-39 passphrase provides some protection by creating a separate wallet, but Coinkite still recommends full seed replacement.

For the broader ecosystem, the dual crises of July 2026 should kill the myth that any single security layer is enough. True resilience requires verifiable entropy (consider dice rolls for seed generation), multi-signature setups across different hardware vendors, continuous firmware audit, and the understanding that your adversary may be a patient nation-state with a $6.7 billion budget and a mandate to fund nuclear weapons programs through your private keys.

The Coldcard hack may not have been Lazarus. But in a year when North Korean hackers are stealing billions and a five-year-old RNG bug can evaporate $100 million in 41 minutes, the distinction barely matters. The threat model has changed. The only question is whether users have changed with it.

Alex Rivera
Alex Rivera

Senior Markets Editor

Alex covers global equity markets, commodities, and macro strategy. Former derivatives trader at Morgan Stanley with 12 years of markets experience.

Deep Research: Lazarus Group Investigations

Our forensics team has compiled extensive intelligence on the Lazarus Group as part of our ongoing blockchain security research. For more context on these operations, consult the external research nodes.

Open External Intel Node

Found this useful? Share it.

Share