- An attacker swept 1,082.65 BTC (~$70.2 million) from 1,196 Bitcoin addresses in 41 minutes by exploiting a predictable random number generator flaw in Coldcard hardware wallets.
- Galaxy Research traced the exploit to a March 2021 firmware integration error where seed generation relied on a software pseudorandom number generator instead of the hardware RNG.
- Coinkite deployed emergency firmware updates, but existing seeds remain compromised; users must generate entirely new seeds on patched devices and transfer their funds.
- The vulnerability affects specific firmware versions across Coldcard Mk2, Mk3, Mk4, Mk5, and Q models, with effective entropy estimates as low as 40 bits on older devices.
An attacker drained 1,082.65 Bitcoin (~$70.2 million) from 1,196 Coldcard wallet addresses in 41 minutes on July 30. Galaxy Research mapped the coordinated sweep and tied it to a critical firmware flaw in the Bitcoin-only hardware wallet made by Canadian firm Coinkite.
A March 2021 firmware integration error routed seed generation to a deterministic software PRNG instead of the STM32 hardware RNG. Block traced the fault to a build configuration error that forced MicroPython’s deterministic Yasmarang fallback instead of the hardware RNG wrapper.
Coinkite shipped emergency firmware on July 31, but installing it does not repair an existing seed. The company tells owners to generate a new seed on patched firmware and move their coins.
Restoring the old seed to updated firmware or another wallet carries the weakness forward. No public report has reconstructed a victim’s seed and matched it to a drained address.
Coinkite estimates the effective entropy at roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q, against the 128-bit standard for a 12-word BIP-39 seed. Exposure depends on the firmware version running when the seed was created, not the version currently installed.
The company says a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone. Multisig helps only when the quorum is not built entirely from affected devices; TAPSIGNER, OPENDIME and SATSCARD are unaffected.
No one has publicly named the attacker. Galaxy Research warned that the sweep transaction pattern identifies the operator but “looks the same as if a coin owner chose to move coins.” The disclosure follows Coinspect‘s Ill Bloom research in early July, a separate weak-PRNG flaw tied to more than $5 million in thefts.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
