
CVA Security Watch #4: The $800 Million Wake-Up Call That Made Crypto Stronger
CVA Security Watch #4
A quarterly briefing by the Cybersecurity Working Group at the Crypto Valley Association
The $800 Million Wake-Up Call That Made Crypto Stronger
Picture a lock built for a million possible combinations, except a manufacturing shortcut quietly limited it to a few thousand. Nobody noticed for four years. Then this summer, more than 7,000 digital wallets protected by a popular hardware device called Coldcard opened themselves to strangers, one after another, and the crypto world got a real-time lesson in what "random" actually means when real money is on the line.
This was the quarter that tested Bitcoin's reputation as the boring, reliable member of the crypto family. It was also the quarter artificial intelligence proved it could work as both lockpick and locksmith, sometimes on the same lock, in the same month.

The Number That Wasn't Random Enough
Coldcard, hardware wallet, July-August
Coldcard is a small physical device, about the size of a USB stick, that generates and stores the secret keys behind a Bitcoin wallet, keeping them offline and out of reach of hackers. Generating those keys well depends on true randomness, the same principle behind shuffling a deck so thoroughly that no one could predict the order.
In 2021, a firmware update quietly swapped part of that randomness for a shortcut built from the device's own clock and serial number. On two older models, that shortcut narrowed the odds so much that a patient researcher with a laptop could work backward from a public address to the private key behind it: arithmetic, not hacking. Once word got out, so did the researchers. Independent security sleuths traced $130 million moving out of more than 7,000 wallets.
Coinkite, the company behind Coldcard, owned the mistake publicly and shipped a fix within days. The fix can't rescue a key already generated the old way, so its advice was blunt: if your device predates the patch, move your funds to a fresh wallet today.
The Working Group's take is about design, not blame: spreading trust across multiple hardware devices beats pooling it into one system, however convenient.
The Shortcut That Went Too Far
Liquid Sidechain, September 6
Liquid is a companion network to Bitcoin, built to move funds faster by having a small group of trusted operators verify transactions before releasing real bitcoin. To speed things up, the system started remembering, or "caching," proofs it had already checked.
An update let two different proofs share the same cached answer. One legitimate proof unlocked the cache; a second, fabricated one, dressed up to look identical, rode the same green light straight through. The network approved roughly $320 million in Bitcoin that never should have moved.
A backup alarm meant to catch unusually large withdrawals fired twice, correctly, and was overridden before anyone paused to ask why.
The team shipped a fix within days and paused withdrawals until every dollar could be confirmed backed one-to-one again.
When the Front Door Looked Locked
Bitget, September 24
Bitget is a major cryptocurrency exchange, the kind of platform millions of people use the way they'd use an online bank. In late September, intruders got into a back-office system, not by stealing a password or a key, but by tricking the exchange's own approval process into thinking a transfer request was legitimate.
Within about three hours, they moved roughly $350 million, converting it quickly into a harder-to-freeze form.
Bitget's cold storage, funds kept fully offline, was never touched. And the exchange had already built a $464 million user protection fund for exactly this scenario: every affected customer was made whole.
The Warning Nobody Wanted to Reopen
Ostium, July 15
Ostium runs a trading platform that needs real-world prices, like the price of Bitcoin, to work, sourced from outside "oracle" services. An attacker found a way to feed the platform a fake, absurdly low Bitcoin price, open a bet against it, then close the bet moments later once the real price kicked back in.
Repeated enough times, the trick moved roughly $23.75 million.
Eight months earlier, an independent security firm reviewing Ostium's code had flagged, in writing, that this category of weak spot existed.
The lesson isn't about any one missed item. It's that a documented warning is worth revisiting as a protocol grows, not filed away.
The Machines Are Learning Fast, In Both Directions
Bitcoin Red Team & Core Lightning, August
Coldcard's discovery sparked something encouraging. A volunteer group calling itself the Bitcoin Red Team spent about $40,000 in AI computing power to scan 390 open-source Bitcoin projects in 27 hours, surfacing 85 serious issues for human reviewers to fix, work that once took months.
Around the same time, the team behind Core Lightning, popular Bitcoin payment software, got an early heads-up on a separate bug from AI-assisted researchers and quietly shipped a fix first.
The twist that keeps things honest: Coinkite says its own AI-assisted review of the Coldcard code, run before and after the incident, missed the entropy problem entirely, and so did several other advanced AI models tested afterward.
The lesson isn't that AI failed. It's that AI is a powerful new set of eyes on old code, not a replacement for humans asking the right question.
The Big Picture
None of this quarter's stories started with a smart contract bug, the kind of flaw a standard audit is built to catch. Each lived one layer deeper: in how randomness gets generated, how a system remembers its decisions, how an exchange authorizes a transfer.
That's not a reason to worry more about crypto. It's a sign of an industry growing up in public.
Four years passed before Coldcard's flaw surfaced; once it did, disclosure and a same-week fix, plus a global volunteer effort to find more bugs before attackers did, took days, not years. Bitget's users were made whole in the same news cycle.
The honest headline for Q3 2026 isn't that crypto has a security problem. It's that crypto is building the reflexes of a much older industry, faster than most expected, and mostly in the open.
Sources
Coldcard incident — https://rekt.news/coldcard-rekt
Coldcard advisory — https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
Coldcard technical backgrounder — https://blog.coinkite.com/entropy-technical-backgrounder/
Coldcard AI review — https://blog.coinkite.com/adding-to-public-record/
Liquid Sidechain incident — https://timesweb3.com/news/liquid-sidechain-loses-320m-btc-to-proof-cache-flaw/
Bitget official statement — https://x.com/GracyBitget/status/2103284083363398137
Bitget incident analysis — https://timesweb3.com/news/bitget-hacked-183m-350m-drained-from-hot-wallets/
Bitget AI commentary — https://x.com/P3b7_/status/2103242864461238653
Ostium incident — https://rekt.news/ostium-rekt
Bitcoin Red Team — https://bitcoinmagazine.com/business/bitcoin-red-team-finds-85-critical-flaws-across-390-open-source-repos-after-coldcard-exploit
Core Lightning — https://blog.blockstream.com/core-lightning-26-06-7/
