No one could have imagined that a vulnerability from five years ago would lead to the biggest Bitcoin theft of the year.
On July 30th, unusual activity was detected. First, several hundred Bitcoins were consolidated from over a hundred addresses in a short period, then the scope of the attack rapidly expanded. The attacker scanned thousands of Bitcoin addresses and stole nearly 2000 BTC, worth over a hundred million dollars.
The cause was quickly identified: a bug in the mnemonic phrase generation process of a hardware wallet named Coldcard—a weak randomness issue, meaning the random numbers weren't truly random and could be guessed.
Initially, there wasn't much attention because Coldcard doesn't have many users in China. But overseas, the situation exploded, as Coldcard is highly renowned there. After several days of escalation, panic has reached its peak. On July 31st, the total volume of single transactions below 1 BTC reached 39,600 BTC, hitting the highest level since the FTX collapse in 2022.
This attack was also most likely discovered and exploited by an AI model, similar to the Zcash incident that halved its value in a day. This one seems even more severe. The numbers don't fully show it; the bigger impact is on confidence, which is unquantifiable.
To understand the perspectives and impact analysis of the Coldcard incident from the front lines, The Block contacted Yu Xian, founder of SlowMist, who is assisting some victims and tracking the Coldcard case closely. In Yu Xian's view, the impact of this theft is profound because it strikes at Bitcoin's most core group of believers.
The Block: Has Coldcard sought assistance from security firms to recover the assets? The stolen Bitcoin is now worth over a hundred million; is recovery likely?
Yu Xian: It's still uncertain which hacking group is responsible. We'd need to analyze their subsequent fund movement patterns to determine. If it's ultimately confirmed to be a state-sponsored hacker group (like North Korean hackers), recovery would be difficult.
Apart from issuing some security advisories, we haven't seen the official team engage a security firm yet. Now, a few individual Coldcard theft victims have come to us for help recovering their assets.
The Block: Looking at the cause of this theft, simply put, the random numbers weren't random. I recall randomness issues appear almost yearly in the crypto industry's history. Why does this one seem exceptionally severe?
Yu Xian: In terms of quantity and amount alone, over a thousand BTC isn't the largest in history. Past incidents like Mt. Gox, BitFinex, LuBian mining pool were robbed of hundreds of thousands of BTC, or any major bridge hack could exceed this amount.
The problem lies in Coldcard's excellent reputation. They are open-source, transparent, minimalistic, and geeky, long used by many Bitcoin OGs and believers. For such a seemingly perfect product to fail is a massive blow to its most steadfast users.
Simultaneously, the core issue is severely insufficient entropy during mnemonic phrase generation, resulting in seed randomness far weaker than expected. Hackers could brute-force compute and collide to find users' mnemonic phrases. This is the most fundamental and fatal problem for crypto asset security.
I think the most absurd part is that with the emergence of powerful AI models, neither Coldcard nor the Bitcoin believers thought to revisit the code using AI. Instead, the hackers did. Because identifying vulnerabilities related to mnemonic phrase randomness is relatively easy for current AI.
So this incident is causing such an uproar because it impacts the most core group of believers.
The Block: So, extending from your perspective, the impact of this theft on the crypto industry is quite profound?
Yu Xian: A long-established, open-source, geeky hardware wallet failing under circumstances everyone considered "perfect" severely shakes the entire community's confidence in similar products. Users will start doubting: Could the wallet I'm using have issues? Will the mnemonic phrases I generate in the future be secure?
The Block: Would you recommend crypto projects now use AI to scan their code for vulnerabilities? Or how does SlowMist currently approach this?
Yu Xian: I would recommend it.
AI's impact on the entire security industry is far greater than the public currently realizes. Hackers face almost no restrictions; they can build powerful models directionally, while defenders are constrained by model access, computing power, compliance, and various other limitations.
We don't audit the source code of public chains like Bitcoin or Ethereum due to limited resources. We prioritize important clients, ensuring they have a lower probability of risks in the AI era. Using AI to review past projects, we have indeed found many previously unnoticed issues with very good results.
The Block: This leads to another somewhat pessimistic question: as models grow stronger, will distrust towards early crypto technology intensify? For example, Zcash had a similar impact before.
Yu Xian: Definitely. Security can never be 100%. Attack and defense constantly evolve in confrontation. Hackers have far greater motivation and capability to leverage AI because breaching systems directly translates to profit, offering extremely high cost-effectiveness. Defenders are constrained by various processes and resources.
Under this asymmetry, security incidents far exceeding past scales are bound to occur, potentially even reaching tens of billions of dollars. Even Bitcoin's own code might be found to have issues in the future.
However, overall, I'm not pessimistic about the industry's ability to handle these threats. The cat-and-mouse game will always exist, and crypto ecosystems will certainly become more robust.
The Block: Some viewpoints are shifting towards highlighting the advantages of centralized exchanges, arguing they are more secure. What's your take?
Yu Xian: Several top-tier centralized exchanges indeed have solid investments in fundamental security. Even if problems occur, they have some capacity to cover losses, barring super-catastrophic events.
Most users actually struggle to handle hardcore operations like managing mnemonic phrases or multi-signature setups independently. Previously, they often relied on reputation and recommendations to choose wallets. But this incident shows that even widely acclaimed wallets can have hidden flaws. Therefore, it's understandable that some users think keeping assets on reputable centralized exchanges is more worry-free.
The Block: For ordinary users who don't understand technology or review wallet code, how should they guard against incidents like Coldcard?
Yu Xian: First, I recommend all users use a mnemonic phrase passphrase. Think of it as adding a password layer to your mnemonic phrase; it's vastly better than not having one. Add a passphrase that's at least 8 characters long and somewhat complex, with the crucial caveat: never forget it. Most mainstream hardware wallets support this.
Even if similar incidents recur, hackers would prioritize transferring funds without a passphrase. Your main assets gain significant buffer time. For example, keep a minimal amount in a standard address without a passphrase and your substantial funds in an address with a passphrase. If the small amount is moved, it signals mnemonic phrase exposure. The cost for hackers to brute-force the passphrase is high, buying you time.
For ordinary users completely unfamiliar with the industry, using services from centralized institutions well and relying on their safety nets when issues arise is fine.
Additionally, three universal suggestions for all players:
· Audit Your Assets: Take time to review your wallet creation memories. Is anything fuzzy? Could your mnemonic phrase have been leaked? If there's any uncertainty, consider changing your custody method.
· Stay Calm: Don't let urgency lead you into fake wallets or phishing traps.
· Isolate Your Thinking: Place uncertain assets on separate devices (even air-gapped), don't mix them. This is safer than assuming everything's fine.
Following these steps can effectively block over 90% of common risks.








