Coldcard losses near $114 million raise trust questions beyond one firmware flaw
Coldcard losses are now near $114 million. Galaxy tied the sweep to a firmware flaw in Coldcard, and Coinkite responded by telling affected users to generate a new seed on patched firmware and move their funds. For a custody product, that kind of incident can do damage far beyond the direct losses.
The metric that matters now: Cost of Discovery
Dragonfly estimates the Coldcard flaw cost just roughly USD 2 to find. That is the point Haseeb Qureshi is making with his "Cost of Discovery" metric: product safety may increasingly depend on how cheaply AI can reproduce a vulnerability. The reported Claude Code run took eight minutes, and a separate offline GLM test took about 20 minutes. Whether those exact timings generalize is unclear, but the broader direction seems clear-discovery can be fast and inexpensive.
Quick Backtesting Tool
Why the Coldcard RNG flaw turns secrets into a search problem
Investigators linked the drain to a fallback PRNG that provided only 40-bit entropy on Mk3. Later models improved that to about 72-bit entropy on Mk4, Mk5, and Q. That is still far below the 128 bits expected from a standard 12-word BIP-39 seed. Block's analysis says an attacker who can constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline, then check candidate seeds by deriving addresses and comparing them with public blockchain data.
The roughly USD 2 discovery setup matters because it lowers the barrier to finding flaws like this in the first place. A manual review can miss a bad RNG configuration. AI does not need to understand crypto ideology; it only needs to identify the weakness, reproduce it cheaply, and make exploitation easier. That shifts the question from "how good is our reviewer?" to "how expensive is it for an adversary to enumerate your keys?"

The bull case: weak RNG becomes harder to ship
If bad randomness can be found for the cost of a short API call, companies that care about long-term trust have a stronger incentive to treat entropy sources as a first-class control. Once fixes can be validated in plain sight through onchain address checks, weak RNG should become harder to ignore.
The bear case: one flaw does not rewrite every wallet
Bears can fairly argue that this does not make every hardware wallet a search problem. Coinkite shipped emergency firmware for every affected model and release track, and No public report has reconstructed a victim's seed and matched it to a drained address. That leaves room to question how easy exploitation is at scale.
What investors and operators should watch
This also puts traditional review workflows on notice. If discovery cost falls sharply, the period in which traditional code review alone is treated as sufficient becomes shorter. For smaller teams, the pressure may be even greater, since Qureshi argues small firms will struggle in security-sensitive markets without repeatable AI-assisted testing.
Watch three things: - whether vendors start publishing entropy design and validation details - whether security scanning becomes part of every release cycle - whether investigators find more evidence that offline seed enumeration is practical even after the patch
What gets repriced now: migration risk, not just reputation
What gets repriced is not the patch itself, but the cash flows tied to trust. Once a firmware update cannot repair a seed that already exists and users are urged to move their bitcoinBTC--, wallet vendors face migration risk as well as a credibility hit. That matters because affected holders were told to act immediately, and migration volume will be one of the first visible signs of whether trust is holding.
What to monitor next
- adoption of the fixed firmware
- whether migration continues beyond the initial alert
- whether losses keep expanding after a fourth wave of attacks
For now, the cleanest signal is user behavior, not messaging. If users migrate quickly, the market will see an operational crisis. If they do not, the longer-term trust hit may be larger.













