In the early hours of 30 July an automated operation swept 500 single-sig addresses across four consecutive blocks. Evidence points to weak private keys generated at birth. No multisig wallet and no taproot address was among the victims.
At 01:36 UTC on Thursday 30 July, block 960188 of the Bitcoin blockchain contained the first 63 transactions of what, fifteen minutes later, would prove to be one of the most surgical thefts ever observed on-chain. Across four consecutive blocks – 960188 to 960191 – 500 transactions swept 500 distinct addresses: 1,324 UTXOs totalling 594.5 BTC, approximately 38 million dollars at current prices. By 01:51 UTC it was already over: in the same block confirming the final sweeps, the attacker had consolidated 562 BTC into a new address, where they remain at the time of writing.
Atlas21’s analysis of mempool.space data reveals the profile of a meticulously planned operation. Each sweep transaction corresponds to one victim address: 419 addresses held a single UTXO, but one had accumulated 200 and another 105 – a pattern typical of someone receiving recurring purchases or automated withdrawals from an exchange always to the same address. The median loss per victim was 0.41 BTC (roughly 26,500 dollars); 110 victims lost more than 1 BTC and the hardest hit lost 29.9, nearly 2 million dollars. One figure stands out: no victim lost less than 0.15 BTC. This suggests the attacker may have filtered targets by minimum balance. The entire operation cost approximately 0.044 BTC in fees.
The first public alarm came from a victim. At 13:19 UTC a user posted on Reddit a thread titled “Full panic – one of my wallets was drained”. Their account was reconstructed in the comments: a Coldcard bought in 2021, a 24-word mnemonic seed phrase generated on the device, savings transferred onto it and then years of silence. In January 2025 they bought a second Coldcard and re-entered the 2021 mnemonic, “to make sure the words were right”. The seed, they explained, had never touched a computer – only the device, a watch-only wallet on Sparrow, and automated withdrawals from an exchange always to the same address. That night the address was swept along with the other 499.
Four hours later, the alarm
At 17:35 UTC Kevin Loaec, co-founder of Wizardsardine (the company behind the Liana wallet), publicly asked his followers with a Coldcard to check their balances: “Hoping this is a nothing-burger but doing my job here.” An hour and a half later the tone shifted: “This is not a drill.” Confirmation came from well-known names in the ecosystem: grubles, a community veteran, confirmed one case; Jameson Lopp reported partial thefts – wallets from which only some UTXOs had been taken, not the entire balance. Loaec noted that among the victims were “multiple real and known bitcoiners”: the theory of a single careless user no longer held.
The word Coldcard was by then at the centre of the conversation. NVK, founder and CEO of Coinkite, the company that makes the device, responded at 18:10: “No need to panic – someone loaded a compromised seed onto a Coldcard and/or their seed leaked. This is part of a broader attack involving 500 private keys from different wallets.” At this point no evidence exists of a flaw in Coldcard’s random number generator.
The weak entropy hypothesis
The first systematic on-chain analysis came from Rob Hamilton, CEO of AnchorWatch: 1,324 UTXOs swept, he noted, dated from 2021 to 2026, all from single-sig addresses, not one taproot. His conclusion: “At first glance, it appears there was faulty entropy in wallet generation somewhere along the path.” This is also the hypothesis that holds up best against our own data. If private keys were generated with a weak random number generator – in a software library, a secure element, a specific production batch of devices, or a specific firmware version – an attacker can recompute them one by one without needing to compromise the victims’ devices directly.
It has happened before: in 2023 the Milk Sad case exposed wallets created with Libbitcoin Explorer, which used the timestamp as its sole source of entropy, and the Randstorm disclosure revealed that millions of browser wallets generated between 2011 and 2015 with BitcoinJS were potentially recomputable. Just three weeks ago, on 10 July, security firm Coinspect disclosed Ill Bloom: five wallet implementations with weak seed generation, 5.1 million dollars already stolen and a coordinated sweep of 431 wallets within hours on 27 May. The structural resemblance to the 30 July operation is clear, even though Coinspect excludes hardware wallets from the Ill Bloom scope and no researcher has so far linked the two events.
Loaec pushed the theory further: a weak RNG “in a library or in the secure element itself” and an attacker who understands the vulnerability but does not know Bitcoin deeply – to the point of using a script “written with AI” that derives only BIP84 paths (native segwit) to a limited depth. That would explain the partial thefts reported by Lopp. The on-chain data collected by Atlas21 confirms the picture almost entirely, with one nuance: 490 of the 500 swept addresses are indeed native segwit, but there are also 5 legacy addresses and 5 nested segwit. The structure of the attack itself – one transaction per address rather than one per wallet – is consistent with someone who possesses individual recomputed private keys rather than fully reconstructed seeds. The data also allow one hypothesis to be ruled out, at least for some victims: nonce reuse in signatures, the vector that has drained wallets after outgoing transactions in the past, cannot apply to dormant wallets that have never signed anything.
Until the exact cause is known, the countermeasures circulating in recent hours should be taken for what they are: risk reduction, with a margin of uncertainty. Loaec warns that even passphrases and dice-rolled seed generation are not certain guarantees while the vector remains unknown, and recommends multisig, preferably multi-vendor: whatever happened, not a single multisig is among the 1,324 stolen UTXOs. Lopp is asking anyone who discovers shortfalls to report them in order to widen the sample. Anyone holding funds on single-sig wallets generated under even questionable conditions – particularly between 2021 and today – has a concrete reason to migrate to a new setup with a seed generated elsewhere.
562 BTC remain unmoved on the consolidation address, with another 32 on the intermediate address. The attacker has not yet moved a single satoshi toward an exchange or mixer: the next movement of those funds will be the first real trace of who holds those keys.





