Coldcard RNG Flaw Linked to Suspected $88.6M Bitcoin Theft

A Coldcard RNG flaw may have exposed predictable wallet seeds linked to $88.6 million in suspected Bitcoin thefts across 4,585 addresses.

Written By
KJ
Kezia Jungco
Aug 3, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A random number generation flaw in Coldcard firmware may have left thousands of Bitcoin addresses with substantially weakened seeds. Researchers have linked the bug to suspected thefts totaling $88.6 million across 4,585 blockchain addresses, although the connection has not been computationally confirmed for every wallet.

The affected firmware generated seeds with reduced entropy, potentially allowing an attacker to reproduce candidate seeds offline, derive their Bitcoin addresses, and compare them with public blockchain data. Coldcard owners who created seeds on vulnerable releases should install the patched firmware, generate a new seed, and transfer their funds, as updating the device does not repair an existing seed. 

Weak randomness may have exposed wallet seeds

BleepingComputer reported that an integration error caused affected Coldcard firmware to route seed generation through MicroPython’s deterministic Yasmarang pseudorandom number generator instead of the device’s STM32 hardware random number generator.

The fallback generator relied on the device’s microcontroller identifier and system timing values rather than fresh cryptographic entropy. Researchers said the feasibility of reproducing a seed would depend on factors including the device identifier, boot timing, previous RNG calls, and the cost of testing candidate seeds.

According to The Hacker News, Galaxy Research initially identified a 41-minute sweep on July 30 involving 1,196 addresses and approximately 1,082.65 BTC, valued at $70.2 million at the time. Two additional suspected waves later raised the estimate to 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses.

Galaxy based its findings on transaction patterns and on-chain analysis. Researchers have not publicly reconstructed a victim’s seed and matched it to a drained address, and Galaxy has not computationally confirmed that every identified address was generated by vulnerable Coldcard firmware.

Advertisement

Which Coldcard devices are affected

Exposure depends on the firmware used when the seed was generated. Reported affected versions include Mk2 and Mk3 firmware from the 4.0.x and 4.1.x release lines, Mk4 and Mk5 standard firmware earlier than 5.6.0, and Q firmware earlier than 1.5.0Q.

Certain Edge releases before 6.6.0X for Mk4 and Mk5 devices or 6.6.0QX for Q devices are also vulnerable.

Coinkite released emergency firmware for the affected products on July 31. Restoring an old seed on patched firmware or importing it into another wallet carries the weakness forward, which is why Coinkite recommends generating a replacement seed.

Seeds supplemented with at least 50 fair, independent, and private dice rolls are not considered at risk from this flaw alone. Coinkite also said TAPSIGNER, OPENDIME, and SATSCARD products are unaffected because they use different codebases.

What affected wallet owners should do

Before migrating, owners should verify their existing backup and install the appropriate firmware update. They should securely record the replacement seed, confirm the receiving address on the device, send a small test transaction, and move the remaining balance only after the test is confirmed.

A BIP-39 passphrase may reduce the risk in some configurations, but Coinkite still advises users to replace the underlying seed rather than rely on the passphrase as a permanent defense. Multisignature configurations may offer protection only when the signing quorum does not consist entirely of affected devices.

The suspected thefts show why patching firmware cannot always reverse a cryptographic failure. For affected Coldcard owners, the immediate priority is to retire potentially weak seeds and move funds to a wallet generated with patched firmware.

Other News: Hardware wallet flaws are not the only way attackers target cryptocurrency. Read how the Silent Swap campaign used a fake Chrome extension to steal crypto from unsuspecting users.

KJ

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.