Coldcard RNG Flaw Linked to Suspected $88.6M Bitcoin Theft

A Coldcard RNG flaw may have exposed predictable wallet seeds linked to $88.6 million in suspected Bitcoin thefts across 4,585 addresses.

執筆者
Kezia Jungco
Kezia Jungco
Aug 3, 2026
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A random number generation flaw in Coldcard firmware may have left thousands of Bitcoin addresses with substantially weakened seeds. Researchers have linked the bug to suspected thefts totaling $88.6 million across 4,585 blockchain addresses, although the connection has not been computationally confirmed for every wallet.

The affected firmware generated seeds with reduced entropy, potentially allowing an attacker to reproduce candidate seeds offline, derive their Bitcoin addresses, and compare them with public blockchain data. Coldcard owners who created seeds on vulnerable releases should install the patched firmware, generate a new seed, and transfer their funds, as updating the device does not repair an existing seed. 

Weak randomness may have exposed wallet seeds

BleepingComputer reported that an integration error caused affected Coldcard firmware to route seed generation through MicroPython’s deterministic Yasmarang pseudorandom number generator instead of the device’s STM32 hardware random number generator.

The fallback generator relied on the device’s microcontroller identifier and system timing values rather than fresh cryptographic entropy. Researchers said the feasibility of reproducing a seed would depend on factors including the device identifier, boot timing, previous RNG calls, and the cost of testing candidate seeds.

According to The Hacker News, Galaxy Research initially identified a 41-minute sweep on July 30 involving 1,196 addresses and approximately 1,082.65 BTC, valued at $70.2 million at the time. Two additional suspected waves later raised the estimate to 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses.

Galaxy based its findings on transaction patterns and on-chain analysis. Researchers have not publicly reconstructed a victim’s seed and matched it to a drained address, and Galaxy has not computationally confirmed that every identified address was generated by vulnerable Coldcard firmware.

Advertisement

Which Coldcard devices are affected

Exposure depends on the firmware used when the seed was generated. Reported affected versions include Mk2 and Mk3 firmware from the 4.0.x and 4.1.x release lines, Mk4 and Mk5 standard firmware earlier than 5.6.0, and Q firmware earlier than 1.5.0Q.

Certain Edge releases before 6.6.0X for Mk4 and Mk5 devices or 6.6.0QX for Q devices are also vulnerable.

Coinkite released emergency firmware for the affected products on July 31. Restoring an old seed on patched firmware or importing it into another wallet carries the weakness forward, which is why Coinkite recommends generating a replacement seed.

Seeds supplemented with at least 50 fair, independent, and private dice rolls are not considered at risk from this flaw alone. Coinkite also said TAPSIGNER, OPENDIME, and SATSCARD products are unaffected because they use different codebases.

What affected wallet owners should do

Before migrating, owners should verify their existing backup and install the appropriate firmware update. They should securely record the replacement seed, confirm the receiving address on the device, send a small test transaction, and move the remaining balance only after the test is confirmed.

A BIP-39 passphrase may reduce the risk in some configurations, but Coinkite still advises users to replace the underlying seed rather than rely on the passphrase as a permanent defense. Multisignature configurations may offer protection only when the signing quorum does not consist entirely of affected devices.

The suspected thefts show why patching firmware cannot always reverse a cryptographic failure. For affected Coldcard owners, the immediate priority is to retire potentially weak seeds and move funds to a wallet generated with patched firmware.

Other News: Hardware wallet flaws are not the only way attackers target cryptocurrency. Read how the Silent Swap campaign used a fake Chrome extension to steal crypto from unsuspecting users.

Kezia Jungco

Kezia Jungco is a staff writer with five years of hands-on experience testing and analyzing generative AI platforms, chatbots, and NLP tools. She writes in-depth coverage for both enterprise and consumer audiences, focusing on artificial intelligence, data analytics, CRM solutions, cloud infrastructure, cybersecurity, and emerging tech trends. Her work appears in TechRepublic, eWEEK, Datamation, TechnologyAdvice, and Selling Signals.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。