COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A massive Bitcoin heist has shaken the cryptocurrency community, with an estimated $88.6 million in digital assets stolen from thousands of COLDCARD wallets. Researchers believe a vulnerability in the hardware wallet’s firmware, specifically its random number generator (RNG), was exploited to facilitate the thefts.

Galaxy Research, a digital asset research firm, identified an initial wave of transactions that they suspect was linked to the vulnerability. In just 41 minutes on July 30, approximately $70.2 million in Bitcoin was drained from 1,196 addresses. The attackers used an automated tool, leaving no change output and paying a hardcoded fee rate of 30 satoshis per virtual byte – significantly higher than the median fee for that week.

The attack’s sophistication suggests the attacker had identified and studied the affected wallets beforehand, prioritizing high-value targets. In fact, $30 million was stolen in just the first ten minutes, with one victim losing $1.8 million. This level of planning and precision raises concerns about the attackers’ capabilities and potential motivations.

Researchers have since identified a second and third wave of transactions, bringing the estimated total to 1,367 Bitcoin worth approximately $88.6 million. The stolen funds remained in attacker-controlled addresses at the time of the report.

Block’s Bitcoin Engineering and Security teams worked with other researchers to analyze the COLDCARD firmware and identify the underlying vulnerability. They found that an integration error caused the RNG code to use a deterministic software generator instead of the device’s hardware RNG. This fallback generator relied on non-cryptographically secure sources of randomness, allowing attackers to generate possible wallet seeds offline.

The fallout from this attack has left many COLDCARD users scrambling to update their firmware and secure their wallets. Affected seeds include those generated on specific firmware versions of Mk2 and Mk3 devices, as well as some Mk4, Mk5, and Q devices. New firmware is available that fixes the flaw, but updating will not repair a seed that was previously generated.

To mitigate this risk, affected users should verify their existing backup, install the fixed firmware, generate and securely record a new seed, verify the new wallet address on the device, send a small test transaction, and then move the remaining funds. It’s also recommended to retain the old backup until the migration is complete and confirmed.

While having a strong, unique BIP-39 passphrase makes it harder for attackers to exploit the vulnerability, it does not repair the underlying seed. Coinkite advises that seeds supplemented with at least 50 fair, independent, and private dice rolls are not considered at risk from this flaw alone.

The COLDCARD incident serves as a stark reminder of the importance of robust security measures in protecting digital assets. As the cryptocurrency market continues to grow, so too do the threats facing users. By staying informed and taking proactive steps to secure their wallets, individuals can minimize their exposure to such attacks.


Source: Bleeping Computer — 2026-08-02