HispasecAugust 3, 2026🇪🇸Translated from Spanish

Coldcard Firmware Flaw Linked to Theft of 1,082 Bitcoin in 41 Minutes

A defect in the firmware of COLDCARD hardware wallets degraded randomness when generating seed phrases and has been linked to coordinated sweeps that drained more than 1,000 Bitcoin in under an hour.

On 30 July 2026 an automated attacker emptied 1,082.65 BTC from 1,196 addresses in only 41 minutes. The operation followed a predictable pattern of rapid, offline seed enumeration made possible by insufficient entropy in seeds created on affected COLDCARD devices from Coinkite.

The vulnerability originated in an integration error introduced in March 2021. Instead of using the hardware RNG of the STM32 microcontroller, certain firmware versions routed seed creation to a deterministic software PRNG seeded solely with the chip’s unique identifier and boot-time registers. No additional entropy was mixed after startup, reducing effective entropy to approximately 40 bits on Mk3 units and 72 bits on Mk4, Mk5 and Q models—far below the 128 bits expected from a standard 12-word BIP39 seed.

Seeds remain vulnerable based on the firmware version present at the moment of creation, not the version running today. Affected ranges include Mk2 and Mk3 devices on versions 4.0.0–4.1.9, Mk4 and Mk5 devices before 5.6.0, and Q devices before 1.5.0Q. Corrected builds were also released in the Edge branches for earlier Mk4/Mk5 and Q hardware.

Coinkite published an emergency firmware release on 31 July 2026 that improves entropy for new seeds. Updating the device does not strengthen an already-generated weak seed; funds must be moved to a freshly created seed after the update.

Users who added manual entropy with dice are considered unaffected only if they performed at least 50 fair, independent, and private rolls. A strong, unique BIP39 passphrase creates a separate wallet and adds a defensive layer but does not replace the need to replace the underlying seed. Multisig setups are safe only when the required quorum does not rely exclusively on keys generated by vulnerable firmware.

Owners of potentially affected addresses are advised to monitor on-chain activity and move funds at the first sign of consolidation or unauthorized sweeps. Once an attacker locates a valid seed, automated draining can occur within minutes.

Related articles

安全客Crypto & Financial Crime

1755 Bitcoin Worth $110 Million Stolen from 5000 Hardware Cold Wallets Due to Flawed Random Number Generator

A mainstream hardware cold wallet suffered a systemic defect in its random number generation algorithm, allowing attackers to compromise approximately 5000 wallets and steal 1755 BTC valued at around $110 million. The incident, confirmed on August 4, marks the largest hardware wallet security breach in crypto history because the flaw existed at the foundational level of private key generation rather than in network defenses. Victims had relied on the common assumption that offline cold storage provides ultimate protection, yet the non-random RNG reduced the effective keyspace dramatically, enabling feasible brute-force attacks. Historical precedents show similar RNG weaknesses have repeatedly undermined wallet security across platforms including Android implementations and various hardware chips. The event underscores that cold storage security depends entirely on correct implementation of cryptographic primitives at every layer, from hardware entropy sources to firmware. Experts recommend avoiding blind trust in any single device, verifying third-party audits, and diversifying storage across multiple solutions including open-source options.

HabrCrypto & Financial Crime

COLDCARD Wallets Suffer Mass Crypto Theft After RNG Flaw Allows Seed Reconstruction

A critical implementation error in COLDCARD hardware wallets enabled attackers to reconstruct wallet seeds and steal cryptocurrency from thousands of users. The flaw stemmed from an incorrect switch to the libsecp256k1 library, which inadvertently used the rng_get() function from libNgU for seed generation instead of proper hardware entropy. Depending on the model, seeds for Mk2 and Mk3 devices could be derived solely from UID, timer state, and generator history, while Mk4, Mk5, and Q models added limited extra entropy. On July 30, the attacker drained over 1,367 BTC worth approximately $88 million from 4,585 addresses in just 41 minutes. Coinkite released updated firmware, but affected users must also regenerate new seeds and consider additional protections such as passphrases. Other Coinkite products including TAPSIGNER, OPENDIME, and SATSCARD remain unaffected. The incident highlights how even well-tested cryptographic libraries can fail when integrated incorrectly.