MICROPY_HW_ENABLE_RNG = 0The consequence: Seed entropy collapsed. A secure hardware-generated seed offers a 128-bit key space — meaning 2¹²⁸ possible values, which is astronomically large and impractical to brute-force. The software fallback reduced that to as little as 40 bits, or roughly 4 billion possible values . For a sufficiently determined attacker armed with the right information, that key space was small enough to enumerate remotely.
Attackers could reconstruct wallet seed phrases by combining device serial numbers, clock readings, and other publicly observable data with the constrained key space . They then generated candidate seeds on their own machines, derived addresses, and checked those addresses against the Bitcoin blockchain to find wallets with balances. The entire attack required no physical access to any victim's device
.
The exploit unfolded in multiple waves, with the most aggressive action happening in the first hours.
As of August 4, Galaxy Research had high confidence that 1,596 BTC had been stolen, with unconfirmed losses adding another $30 million . The total damage settled around $130 million
.
The hack triggered an immediate migration. Bitcoin logged 2.27 million new wallets and 751,000 active wallets in the first week of August — the strongest on-chain activity in months — as holders raced to move funds off Coldcard devices .
Crucially, updating firmware could not fix an affected seed. The only remedy was generating a new seed on patched firmware and carefully migrating funds . This meant every wallet whose seed was created on vulnerable firmware versions (4.0.1 through 5.0.3, affecting Mk2 and Mk3 models) was permanently at risk until the user manually moved coins
.
In the first week of August 2026, U.S. spot Bitcoin ETFs posted $853.5 million in net inflows — their best weekly performance since April 2026 . The inflows were broad-based but concentrated at the top:
The ETF surge followed an eight-week stretch of outflows that had drained $8.26 billion through the start of July . The reversal was sharp and sudden — and its coincidence with the Coldcard hack fueled immediate speculation.
The timing was striking. The Coldcard attack became public on July 30-31. The ETF inflow run began on Monday, August 3. But that same week, on Friday August 7, the U.S. Bureau of Labor Statistics released a shockingly weak July jobs report. Both events could have driven ETF buying, and analysts remain divided on which was the primary cause.
Most analysts surveyed across major outlets concluded the ETF surge was likely driven by both forces acting in the same direction . The hack provided a micro-level "flight to custody" rationale — a concrete reason for self-custody holders to reconsider their security setup. The weak jobs report provided a macro-level "risk-on" catalyst — the kind of broad monetary policy shift that drives institutional capital into all risky assets, Bitcoin included.
As one Bloomberg analyst put it, the causal link between the hack and the ETF inflows is "unclear," but the coincidence has "fueled debate" . An MSN Money analysis concluded the hack provided a "convenient narrative" for a shift that may have been macro-driven, but noted that the custody debate was now "front and center" for the first time since the early days of Bitcoin ETFs
.
What is clear: the $853.5 million inflow week was the strongest since April, and two major events — a once-in-a-generation hardware wallet failure and a shock jobs report — converged in the same window. Both the custody question and the macro outlook are now more uncertain than they were before that week. That uncertainty, rather than a clean answer, is the real takeaway.