COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A catastrophic flaw in a popular hardware wallet’s random number generator (RNG) has been linked to a staggering $88.6 million Bitcoin heist, leaving thousands of users vulnerable to theft. Digital asset research firm Galaxy Research identified an initial wave of transactions that it believes was likely exploited using the vulnerability, draining approximately 1,083 BTC from 1,196 addresses in just 41 minutes.

The flaw, which was discovered by Block’s Bitcoin Engineering and Security teams in collaboration with other researchers, lies in COLDCARD hardware wallet firmware. Specifically, an integration error in the RNG code causes the device to use a deterministic software generator instead of its own cryptographically secure hardware RNG. This allowed attackers to generate possible wallet seeds offline, determine their corresponding Bitcoin addresses, and compare them with those visible on the blockchain. A match would confirm the correct seed, enabling the attacker to generate the private keys needed to steal the funds.

Galaxy Research identified a second and third wave of transactions, raising the estimated total to 1,367 Bitcoin stolen from 4,585 addresses. The attackers prioritized high-value wallets, stealing approximately $30 million during the first ten minutes and taking $1.8 million from one victim. This suggested that the attacker had identified and studied the affected wallets before beginning the thefts.

The vulnerability affects COLDCARD devices with specific firmware versions: Mk2 and Mk3 (4.0.1 through 4.1.9), Mk4 and Mk5 (before standard version 5.6.0 or Edge version 6.6.0X), and Q devices (before standard version 1.5.0Q or Edge version 6.6.0QX). Fortunately, new firmware that fixes the flaw is available for download. However, it’s essential to note that updating the firmware does not repair a seed that was previously generated.

To mitigate this risk, affected users should verify their existing backup, install the fixed firmware, generate and securely record a new seed, verify the new wallet address on the device, send a small test transaction, and then move the remaining funds. The old backup should be retained until the migration is complete and confirmed. Additionally, seeds supplemented with at least 50 fair, independent, and private dice rolls are not considered at risk from this flaw alone. A strong, unique BIP-39 passphrase also makes it harder to exploit, but users should still migrate as it does not repair the underlying seed.

In a surprising move, Coinkite has destroyed all COLDCARD devices that were awaiting shipment with the affected firmware and contacted customers whose devices had already shipped with the security advisory. Their TAPSIGNER, OPENDIME, and SATSCARD products are not affected because they use different codebases. This incident serves as a stark reminder of the importance of robust security measures in protecting digital assets. As always, users should remain vigilant and take proactive steps to safeguard their wallets against potential vulnerabilities.


Source: Bleeping Computer — 2026-08-02