AIO APEX

Coldcard hardware wallet RNG flaw enabled $88 million Bitcoin theft across 4,585 addresses

BleepingComputer
Share:
Coldcard hardware wallet RNG flaw enabled $88 million Bitcoin theft across 4,585 addresses

A critical flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin, with attackers draining 4,585 compromised addresses across two separate theft events. The vulnerability, which traces back to a March 2021 firmware integration error, effectively reduced the cryptographic randomness protecting private keys to a level that could be broken offline — without ever touching the hardware wallet itself.

What went wrong

The flaw lies in how Coldcard's Mk3 firmware handled seed generation. When a firmware update in March 2021 integrated a new module, seed derivation was accidentally routed through a deterministic software pseudorandom number generator (PRNG) rather than the intended STM32 hardware RNG. The result was catastrophic: effective entropy dropped from the required 128 bits to roughly 40 bits on affected devices.

With only ~40 bits of entropy, an attacker who knows the device's UID, timer state, and prior RNG call history can reconstruct seed candidates entirely offline. Those candidates are then checked by deriving the corresponding Bitcoin addresses and matching them against publicly visible blockchain data — no device access required, no interaction with the victim.

The theft

On July 30, 2026, an attacker moved with surgical speed: 1,196 Bitcoin addresses were drained in just 41 minutes, netting 1,082.65 BTC worth approximately $70.2 million. A subsequent analysis updated that total to 1,367.05 BTC across 4,585 addresses — approximately $88.6 million — suggesting the attacker continued working through the list of vulnerable wallets.

The vulnerability was publicly disclosed on July 31, 2026, one day after the initial theft. Coldcard's parent company issued an emergency firmware update and began notifying affected users. Anyone who generated a seed on an Mk3 device running firmware from March 2021 onwards is potentially affected.

What users should do

Coldcard has strongly urged all Mk3 wallet holders to immediately generate a new seed using a fully updated device, transfer funds to the new seed, and treat any existing Mk3 seeds generated during the affected period as compromised. Replacement devices and recovery guidance are being offered to affected customers.

Hardware wallets are considered among the safest ways to store cryptocurrency precisely because they isolate private key generation from internet-connected devices. This incident is a reminder that hardware isolation only protects against remote attacks — a flawed random number generator defeats that protection entirely, as the vulnerability exists in the math, not the network.

As reported by BleepingComputer, investigators are still assessing whether additional addresses remain at risk.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: