There Will Be No Warning, Only Losses
Open source is not a security model. A silent work-factor collapse drained $70M in 25 minutes after hiding for five years — and AI and quantum are about to make that the default failure mode.
On July 30, 2026, roughly 594 BTC — about $70 million — drained out of some 500 hardware wallets in 25 minutes. No malware. No phishing. No stolen seed phrases. The owners did everything right. They bought a well-regarded, open-source hardware wallet and kept their keys offline.
The cause was a build error introduced five years earlier. A firmware change in March 2021 quietly routed key generation away from the device's hardware random number generator and into a predictable software fallback seeded from non-secret chip data. Seeds that were supposed to carry 128 bits of entropy carried as few as 40. The keys looked perfect. They passed every checksum, generated valid addresses, and signed valid transactions — right up to the second they were emptied.
This is the failure mode nobody prices in. And it is the exact shape of what quantum computing is about to do to every key in existence.
A Silent Collapse of Work Factor
A key's strength is not a visible property. A strong key and a fatally weak one are bit-for-bit indistinguishable. You cannot look at a seed, an address, or a signature and tell whether the randomness behind it was real. The only difference is the work factor — how much computation an attacker needs — and that number is invisible from the outside.
When that number silently collapses, three things follow, and all three are brutal:
- It is undetectable. Nothing about the key changes appearance. There is no error, no alert, no degraded state to monitor.
- It is retroactive. Fixing the firmware does nothing for the keys already generated. The damage is already minted.
- It is unpatchable at the point that matters. You cannot rotate a key you have already published, and you cannot un-expose a public key already on a chain.
And the collapse is not gradual. Going from 128 bits to 40 bits is not "somewhat weaker." It is a factor of roughly 1027. There is no comfortable middle ground where you are "a little exposed" — you are either arithmetically unreachable or you are already gone.
| Effective entropy | Real-world cost to break one key |
|---|---|
| 128-bit (intended) | Longer than the age of the universe, on any hardware |
| 72-bit | Out of reach today — but "today" is a moving line |
| 40-bit (Coldcard Mk3) | Roughly two GPU-weeks — a few hundred dollars |
| 32-bit (Milk Sad, CVE-2023-39910) | Hours on one machine |
"Many Eyes" Is a Belief, Not a Measurement
The Coldcard firmware was fully open source the entire time. Anyone could read it. The bug still hid for five years, and by public accounts it was ultimately surfaced with the help of AI review of the same code the vendor had already published.
This is the uncomfortable pattern across every major cryptographic failure of the last two decades. Openness has shown no correlation with how fast the defect is caught:
- Debian OpenSSL (2006–2008): a maintainer asked the public mailing list whether it was safe to remove some code, was told yes, and collapsed the entire key space to 32,767 possibilities. Public review didn't miss the bug — public review approved it.
- Dual_EC_DRBG: a weakness that lived for years inside a published national standard.
- Infineon ROCA (2017): five years of weak keys generated inside a library that had passed Common Criteria EAL5+/6+ certification. Formal certification didn't find it either.
- Milk Sad (2023) and Coldcard (2026): years of exposure in fully public code.
Open source grants the ability to look. It produces no evidence that anyone did. Absence of a reported bug is not a measurement of safety — it is just silence. And silence is exactly what a silent failure produces.
What changed in 2026 is that the reviewing is now automated. Every public repository with a key-generation path is under tireless, parallel, machine scrutiny — and the oldest, longest-lived code is the richest hunting ground. The defenders got that capability. So did everyone else.
The Attackers Read First
Here is the part people refuse to internalize: in this ecosystem, exploitation does not follow disclosure. It leads it.
When researchers documented the Milk Sad vulnerability — a wallet tool that seeded 256-bit keys from just 32 bits of clock — they found that the affected wallet range had held over 53,500 BTC, and that roughly $1.32 billion had already moved out on a single day in December 2020. By the time the researchers catalogued it in 2023, the range was, in their own words, "swept clean… before we discovered it." The harvesters got there first.
This is not rare. Automated sweeper bots watch the chain continuously for keys derived from weak or known randomness; documented tests show funds sent to such addresses being taken within seconds. In 2014, a two-hour window of a reused-nonce bug at one wallet service was enough for a single person to sweep nearly 900 BTC. And when a signing implementation reuses a random nonce even once, the private key falls out of two public signatures by simple algebra — measurable studies find this fingerprint on roughly 0.35–0.48% of all Bitcoin signatures, with thousands of keys laid bare. No brute force required; the chain is a permanent public record of the mistake.
So the loss is the notification. There is no intermediate "your key is now weak" alert, because the primitive doesn't emit one. In every case, detection equalled loss. The first time most victims learn their work factor collapsed is when the balance reads zero.
Quantum Is This, Scheduled
Everything above is the entropy version of the story. The quantum version is the same failure mode with a calendar attached.
A cryptographically relevant quantum computer collapses the work factor of every key whose public key has ever been exposed — and it does so silently, retroactively, and unpatchably, exactly like a bad RNG. In 2026, published estimates put the resources to break Bitcoin's elliptic-curve signatures at fewer than 1,200 logical qubits, a roughly 10× reduction over prior work. Bitcoin's own developers have responded: a new quantum-resistant address type merged in February 2026, and a companion proposal contemplates migrating — and potentially freezing — the 6.5 to 6.9 million BTC, about a third of all supply, that sit in quantum-exposed addresses.
Read that last point for what it is. Faced with a work-factor collapse they cannot reverse and owners they cannot reach, the only remedy on the table is to freeze the property in place. That is what "no measurement, therefore no response capability" costs at scale. (For the other half of the quantum threat — the encrypted data being harvested today to be read later — see our companion piece, The Quantum Threat Isn't Your Keys, It's Your Data.)
"Safe Until Now" Is Not a Strategy
A key's strength is fixed the instant it is generated and never improves. The world's ability to attack it only moves one direction: AI keeps lowering the cost of finding the defect, and quantum keeps lowering the cost of breaking the primitive. Both curves are monotonic.
So every key ever generated is sitting on a decay curve, and the owner cannot see where they are on it. "It has been fine so far" describes a position in a queue, not a property of the key. The coins and credentials still sitting untouched are either not yet selected, or protected only by a work factor that is actively eroding. Neither is safety. Both are "the harvester hasn't reached your row yet."
Waiting optimizes for the single outcome the system is built to produce: silent, total, unannounced loss. It is the one strategy guaranteed to fail.
The Only Answer: Move the Keys and Rebuild
If security decays, the alarm never fires, and the attacker only strengthens, then keys must be treated as perishable. You rotate proactively, on your own schedule, before the decay curve crosses a threshold you can't see and won't be told about — because the alternative is to move on the attacker's schedule, which means not moving at all.
But naive rotation just resets the clock. Every migration that reveals a public key hands the next harvester its target. Moving keys only works if the destination binds ownership to something other than the guessability of a secret. That is the whole point of measured provenance:
- Record how the key was made, at the moment it is made. When a generation path silently degrades, it shows up as a changed measurement that day — not as a forensic autopsy five years and $70 million later.
- Bind ownership to origin, not to possession of the secret. Then ownership survives key compromise — which is exactly why no after-the-fact "rescue service" can ever work for the lost wallets of the past: they were minted with no identity to claim against.
- Make the next migration provable. Identity carried in the message, not in the key, means you can move again — and again — without re-exposing yourself each time.
The dormant billions of the last decade can never be rescued precisely because they were generated without provenance. That is not a tragedy to be reversed; it is the argument, written in losses, for never again creating value whose only defense is that nobody has guessed it yet.
Measurements, not trust. A key that can only assert it is strong is a key you are trusting. A key that carries a verifiable record of how it was born, and an ownership that does not depend on the secret staying secret, is a key you can measure. The lock was never supposed to be the only proof of who owns the house.
Steven Sprague — Rootz
August 2026
Build Value That Doesn't Depend on a Secret Staying Secret
Measured provenance for keys, data, and AI output. Ownership bound to origin — not to guessability.
Measurements, not trust.