No one anticipated that a vulnerability from five years ago would lead to this year's largest Bitcoin theft.
On July 30, an anomaly was detected: hundreds of bitcoins were rapidly aggregated from hundreds of addresses, after which the attack rapidly expanded as the attacker scanned thousands of Bitcoin addresses and stole nearly 2,000 bitcoins, worth hundreds of millions of dollars.
The cause of the issue was quickly identified: a bug in the mnemonic generation process of a hardware wallet called Coldcard, involving a weak random number issue—meaning the random numbers were predictable.
Because Coldcard has few users in China, it initially attracted little attention. However, it has already caused a major stir overseas, where Coldcard is highly well-known. After several days of escalation, panic sentiment has reached its peak. On July 31, the total volume of Bitcoin transfers below 1 BTC reached 39,600 BTC, the highest level since the FTX collapse in 2022.
This time, the vulnerability was likely discovered and exploited by an AI model, similar to the impact seen with Zcash, which dropped by 50% in a single day. This incident appears to be even more severe; while the data doesn’t reflect it, the primary impact is on confidence—an effect that cannot be quantified.
To understand the perspectives and impact analysis of the Coldcard incident from the front lines, BlockBeats reached out to Yu Xian, founder of SlowMist, who has been assisting some victims and has been closely monitoring the Coldcard incident throughout. In Yu Xian’s view, the impact of this theft is profound because it strikes at the core community of Bitcoin believers.
律动 BlockBeats: Has Coldcard engaged a security firm to assist in recovering the assets? Given that the stolen bitcoins are now worth over $100 million, is recovery likely?
Cosine: It's not yet clear which hacker group is responsible; we'll need to analyze their subsequent transfer methods to determine the origin. If it's ultimately confirmed to be a state-sponsored hacker organization (such as North Korean hackers), recovery will be extremely difficult.
Besides issuing some security advisories, the official team has not yet engaged a security team. Now, individual victims of stolen Coldcard devices have reached out to us for help recovering their assets.
律动 BlockBeats: Judging from the current details of the theft, the cause is essentially that the random number is no longer random. I recall that random number issues have occurred almost every year in the history of the crypto industry—why does this one appear to be so severe?
Cosine: Looking solely at the quantity and value, thousands of bitcoins are not historically the largest; in the past, incidents such as those involving Mt. Gox, BitFinex, or LBank pool resulted in the loss of hundreds of thousands or even millions of bitcoins, or a single bridge hack could easily surpass this amount.
The problem is that Coldcard has an excellent reputation—it’s open-source, transparent, and minimalist, favored by many Bitcoin OGs and believers over the long term. When something so seemingly perfect fails, it delivers a massive blow to its most dedicated users.
At the core of this issue is severely insufficient entropy during mnemonic generation, resulting in seed randomness far weaker than expected, allowing hackers to brute-force collisions and recover users' mnemonics. This is the most fundamental and critical security flaw in cryptocurrency asset protection.
I find it most absurd that, with the emergence of powerful AI models today, neither Coldcard nor Bitcoin believers have taken a step back to review the code using AI—yet hackers did. Because if the focus is solely on vulnerabilities related to mnemonic seed randomness, modern AI can easily identify and detect them.
So this issue became a big deal because it struck at the core group of believers.
律动 BlockBeats: So, extending from your earlier perspective, does this theft have a profoundly far-reaching impact on the crypto industry?
Cosine: When a long-standing, open-source geek hardware wallet encounters issues under the assumption that it is "perfect," it severely undermines the community's confidence in similar products. Users will begin to wonder: Could my current wallet also have problems? Are the mnemonic phrases I generate in the future secure?
律动 BlockBeats: Would you recommend that crypto projects now run AI tools themselves to scan their code for vulnerabilities? Or how does SlowMist currently handle this?
Cosine: I would recommend doing this.
The impact of AI on the entire security industry is far greater than the public currently realizes. Hackers face almost no restrictions and can deliberately build powerful models, while defenders are constrained by model access eligibility, computational power, censorship, and other limitations.
We do not audit the source code of public blockchains like Bitcoin and Ethereum due to limited resources, which we prioritize for key clients to help reduce their risk in the AI era. By using AI to review past projects, we have indeed identified numerous issues that were previously overlooked—its effectiveness has been excellent.
BlockBeats: This raises another, more pessimistic question: as models become stronger, will distrust in early cryptocurrency technologies increase—for example, did Zcash experience a similar impact?
Cosine: Absolutely. Security can never be 100%—attack and defense are constantly escalating in response to each other. Hackers have far greater motivation and capability to leverage AI than defenders, because successfully breaching a system allows them to directly monetize their efforts, offering an extremely high return on investment. Defenders, by contrast, are constrained by various processes and limited resources.
Under such imbalances, security incidents far exceeding previous scales are inevitable—potentially reaching billions of dollars in losses—and even Bitcoin’s own code may be found to have vulnerabilities in the future.
Overall, I’m not pessimistic about the industry’s ability to respond to these threats—attack and defense will always coexist, and cryptographic systems will only become more robust over time.
律动 BlockBeats: Some opinions are beginning to shift toward highlighting the advantages of centralized exchanges, arguing that they are more secure. What are your thoughts on this?
Cosine: Several top centralized exchanges have made solid investments in basic security and have some fallback capabilities even if issues arise, unless it's a super catastrophic event.
Most users find it difficult to independently handle complex tasks like mnemonic phrases and multisignature setups; previously, they mostly chose wallets based on word-of-mouth and recommendations from people around them. But this incident has made users realize that even widely trusted wallets may have vulnerabilities, so some feel it’s more reassuring to keep their assets on centralized exchanges with solid reputations—a reasonable perspective.
律动 BlockBeats: For ordinary users who don't understand technology or review wallet code, how should they protect themselves against incidents like Coldcard?
Cosine: First, we recommend that all users use a passphrase with their mnemonic phrase—a secondary password that adds an extra layer of security, which is vastly better than using no passphrase at all. Use a passphrase of at least 8 characters with some complexity, but make sure you never forget it. Most mainstream hardware wallets now support this feature.
Even if a similar incident occurs again, hackers will prioritize transferring funds from addresses without a passphrase, giving your main assets significant protection. For example, you could keep a small amount of funds in a regular address without a passphrase and store larger amounts in addresses protected by a passphrase. If the smaller amount is stolen, it signals that your seed phrase has been compromised—while the high cost of brute-forcing the passphrase buys you valuable time.
For ordinary users who are completely unfamiliar with the industry, simply use the services of centralized institutions and rely on them for support if issues arise.
Additionally, three general recommendations for all players:
· Review your assets: Take time to assess whether your memory of wallet creation is unclear or if your seed phrase may have been exposed. If there is any uncertainty, consider changing your storage method.
· Stay calm: Avoid falling for fake wallets or phishing scams due to haste.
· Isolation mindset: Place uncertain assets on a separate device (even one that can be disconnected from the internet); do not mix them together—this is much safer than assuming everything is fine.
By doing this, you can effectively prevent over 90% of common risks.

