HabrAugust 4, 2026🇷🇺Translated from Russian

COLDCARD Wallets Suffer Mass Crypto Theft After RNG Flaw Allows Seed Reconstruction

A major incident last week involved the mass theft of cryptocurrency from users of COLDCARD hardware wallets produced by Coinkite. Although cold wallets are designed to keep private keys offline and resistant to remote attacks, a flaw in the random number generation process allowed attackers to reconstruct wallet seeds for a large number of devices.

The root cause traces back to 2021 when Coinkite decided to replace its custom elliptic-curve cryptographic stack with the widely used libsecp256k1 library. During integration, developers mistakenly routed seed generation through the libNgU library’s rng_get() function. For COLDCARD Mk2 and Mk3 devices running firmware v4, the resulting seed depended only on the device UID, timer state, and prior generator calls, making reconstruction straightforward. Newer models added limited extra entropy that only marginally increased attacker effort.

Attackers were able to replicate the flawed generator on their own infrastructure and validate candidate seeds against public Bitcoin blockchain data. On July 30, the first large-scale operation drained more than 70 million dollars in roughly 41 minutes, targeting the richest wallets. By August 1, total losses reached 1,367 BTC across 4,585 addresses, equating to approximately 88 million dollars.

Coinkite published details of the vulnerability the same day and later released patched firmware. Users must both update their devices and generate fresh seeds; simply applying the firmware update is insufficient. Wallets that combine the generated seed with a passphrase or independently created entropy remain at lower risk. Products such as TAPSIGNER, OPENDIME, and SATSCARD are not affected.

The case demonstrates how a subtle coding error in a cryptographic component can undermine years of hardware security design, remaining undetected despite standard testing and code review processes.

Related articles

安全客Crypto & Financial Crime

1755 Bitcoin Worth $110 Million Stolen from 5000 Hardware Cold Wallets Due to Flawed Random Number Generator

A mainstream hardware cold wallet suffered a systemic defect in its random number generation algorithm, allowing attackers to compromise approximately 5000 wallets and steal 1755 BTC valued at around $110 million. The incident, confirmed on August 4, marks the largest hardware wallet security breach in crypto history because the flaw existed at the foundational level of private key generation rather than in network defenses. Victims had relied on the common assumption that offline cold storage provides ultimate protection, yet the non-random RNG reduced the effective keyspace dramatically, enabling feasible brute-force attacks. Historical precedents show similar RNG weaknesses have repeatedly undermined wallet security across platforms including Android implementations and various hardware chips. The event underscores that cold storage security depends entirely on correct implementation of cryptographic primitives at every layer, from hardware entropy sources to firmware. Experts recommend avoiding blind trust in any single device, verifying third-party audits, and diversifying storage across multiple solutions including open-source options.

HispasecCrypto & Financial Crime

Coldcard Firmware Flaw Linked to Theft of 1,082 Bitcoin in 41 Minutes

A critical defect in COLDCARD firmware degraded entropy during BIP39 seed generation, enabling offline enumeration of weak seeds and resulting in the theft of 1,082.65 BTC from 1,196 addresses in just 41 minutes on July 30, 2026. The root cause traces to a March 2021 integration error that replaced the STM32 hardware RNG with a deterministic software PRNG initialized only by chip ID and timing registers, yielding roughly 40 bits of effective entropy on Mk3 devices and 72 bits on Mk4, Mk5, and Q models. Coinkite issued emergency firmware updates, yet any seed created on vulnerable versions remains exposed regardless of later updates. Additional sweeps matching the same pattern have raised total observed losses to 1,367.05 BTC across 4,585 addresses. Users must generate fresh seeds on patched firmware and migrate funds immediately; dice-based entropy addition or BIP39 passphrases provide only partial mitigation.