COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

Aug 3, 2026

A critical firmware vulnerability in COLDCARD Bitcoin hardware wallets has been linked to one of the largest cryptocurrency wallet compromises in recent months, with researchers estimating that attackers stole approximately 1,367 BTC (worth around $88.6 million) from 4,585 affected wallet addresses.

The flaw stems from an error in the wallet's random number generator (RNG) implementation, allowing attackers to predict wallet seed phrases generated on vulnerable firmware versions and ultimately steal funds.

Incident Overview

Details

Target

COLDCARD Bitcoin Hardware Wallets

Issue

Weak Random Number Generator (RNG) implementation

Impact

Approximately $88.6 million (1,367 BTC) stolen

Affected Wallets

4,585 wallet addresses

Root Cause

Firmware integration error causing deterministic seed generation

Vendor

Coinkite

Status

Security updates released; users advised to migrate to new wallet seeds

What Happened?

Researchers from Galaxy Research, Block's Bitcoin Engineering & Security teams, and Chainalysis believe attackers exploited a flaw in COLDCARD wallet firmware that caused certain devices to generate wallet seed phrases using a predictable software-based random number generator instead of the intended hardware random number generator.

According to Galaxy Research, the attackers launched multiple coordinated theft waves beginning on July 30, draining over 1,196 wallets within just 41 minutes during the first attack. Additional theft waves discovered on August 1 increased the estimated losses to 1,367 BTC across 4,585 wallets.

How the Vulnerability Worked

Hardware wallets rely on high-quality randomness when generating recovery seed phrases.

However, researchers found that an integration mistake in COLDCARD firmware caused the software to fall back to MicroPython's deterministic Yasmarang pseudo-random generator rather than using the STM32 hardware RNG.

Instead of relying on cryptographically secure entropy, the fallback generator used predictable values such as:

  • Device identifiers

  • System timing information

  • Microcontroller state

These values could potentially be reconstructed offline, allowing attackers to generate candidate seed phrases, derive associated Bitcoin addresses, compare them against public blockchain data, and identify wallets whose private keys could then be recreated.

Attackers Appeared Well Prepared

Researchers observed several characteristics indicating a highly automated and carefully planned attack:

  • Identical transaction fee of 30 sat/vB for every theft

  • No change outputs in stolen transactions

  • High-value wallets targeted first

  • Roughly $30 million stolen within the first ten minutes

  • Thousands of wallets swept automatically

Chainalysis believes the attackers had likely identified vulnerable wallets before beginning the coordinated theft campaign.

Which Devices Are Affected?

According to Coinkite, affected wallets include seeds generated on:

  • Mk2 and Mk3 firmware versions 4.0.1–4.1.9

  • Mk4 and Mk5 devices running firmware earlier than 5.6.0

  • Q devices before 1.5.0Q

  • Edge firmware versions earlier than 6.6.0X and 6.6.0QX

Importantly, updating firmware alone does not secure wallets whose seed phrases were already generated using vulnerable firmware. Existing seeds remain at risk until users create entirely new wallets.

Recommended Actions for COLDCARD Users

Users who may have created wallets using affected firmware should:

  1. Verify existing wallet backups.

  2. Install the latest patched firmware.

  3. Generate a completely new wallet seed.

  4. Securely record the new recovery phrase.

  5. Verify the new wallet address on the device.

  6. Send a small test transaction.

  7. Transfer all remaining Bitcoin to the newly generated wallet.

Coinkite also noted that wallets created using at least 50 independent private dice rolls to supplement randomness are not believed to be affected by this vulnerability alone.

Security Implications

Although hardware wallets are considered one of the safest methods for storing cryptocurrency, this incident demonstrates that hardware security ultimately depends on correctly implemented firmware.

Even a small implementation error in random number generation can undermine the entire security model by producing predictable cryptographic keys. Unlike software vulnerabilities that can often be fixed through updates, compromised seed phrases remain permanently weak and require users to migrate funds to newly generated wallets.

The incident also highlights the importance of independent security research, rapid vendor disclosure, and prompt user action whenever vulnerabilities affecting cryptographic key generation are discovered.

Key Takeaways

  • A firmware RNG flaw in COLDCARD wallets has been linked to approximately $88.6 million in stolen Bitcoin.

  • The vulnerability caused predictable wallet seed generation instead of cryptographically secure randomness.

  • Researchers estimate 4,585 wallets were compromised across multiple coordinated theft waves.

  • Firmware updates fix future seed generation but do not repair existing compromised seeds.

  • Users should immediately generate new wallet seeds after installing patched firmware and migrate all funds to newly secured wallets.

As cryptocurrency adoption continues to grow, secure implementation of cryptographic functions remains critical. Organizations and individual investors alike should regularly monitor vendor advisories, keep wallet firmware updated, and promptly rotate cryptographic secrets whenever vulnerabilities affecting key generation are disclosed.

Latest News

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

Aug 3, 2026

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Jul 24, 2026

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

Jul 23, 2026

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Jul 20, 2026

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Jul 16, 2026

Microsoft July 2026 Patch Tuesday Fixes 570 Vulnerabilities Including 3 Zero-Day Exploits

Microsoft July 2026 Patch Tuesday Fixes 570 Vulnerabilities Including 3 Zero-Day Exploits

Microsoft July 2026 Patch Tuesday Fixes 570 Vulnerabilities Including 3 Zero-Day Exploits

Microsoft July 2026 Patch Tuesday Fixes 570 Vulnerabilities Including 3 Zero-Day Exploits

Microsoft July 2026 Patch Tuesday Fixes 570 Vulnerabilities Including 3 Zero-Day Exploits

Jul 16, 2026

Get updates in your inbox directly

You are now subscribed.

Get updates in your inbox directly

You are now subscribed.

Get updates in your

inbox directly

You are now subscribed.

Get updates in your inbox directly

You are now subscribed.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.