BlockThreat - Week 31, 2026
$90.5M stolen across 8 incidents. Your keys, their bugs.
As I mentioned in the previous edition, attackers have firmly put wallet software, and now hardware wallets, in their crosshairs. On July 30, 2026, Coinkite, the maker of Coldcard, disclosed a vulnerability in its seed generation process following years of unexplained wallet drains.
The flaw had been present in Coldcard firmware since March 2021, when BIP-39 seed generation was routed through MicroPython’s weak Yasmarang software PRNG instead of the STM32 hardware TRNG. In practice, this reduced seed generation to roughly 40 bits of entropy derived from predictable device state, making offline brute-force recovery feasible.
Multiple waves of attackers have reportedly exploited the weakness to drain roughly $88.6M so far. With several PoC implementations now publicly available (see Hacks section below), we are likely to see vulnerable Bitcoin wallets continue getting emptied for months or even years. This is a complete disaster precisely because it affected some of the ecosystem’s most security-conscious users with dedicated hardware wallets, generated their keys offline, and seemingly did everything right.
This week’s news and research selection features a couple of 2026 H1 reports spotlighting attacker focus areas and the impact, or lack thereof, of audits on recent incidents. We will also look at the latest tactics used by newly reactivated DPRK threat actors, fresh security research for bug hunters and defenders, and new tooling for auditors.
May you find lots of crits and prosper!