A long-running Coldcard firmware RNG regression reportedly reduced seed entropy, enabling rapid key recovery and coordinated thefts (hundreds of BTC in minutes). The incident undermines confidence in hardware self-custody, forces affected users to rotate seeds and migrate funds, and may trigger short-term flows toward custodians/exchanges. It also raises industry-wide audit and supply-chain assurance concerns that can weigh on broader crypto risk sentiment.
Impact level
● High
Affected assets
BTC/USDT+0.94%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A flaw in certain Coldcard hardware wallets left users with far weaker Bitcoin key generation than intended, enabling attackers to drain funds at speed. The issue traces back to a firmware rewrite released in March 2021 as version 4.0.1, when the device's hardware random number generator (RNG) was replaced in practice by a software-based pseudorandom number generator (PRNG). Seed phrases appeared normal, but the underlying randomness was significantly reduced.
Attackers identified the weakness in late July 2026 and carried out coordinated sweeps that emptied about 594 BTC (around $38 million) from roughly 500 wallets in under 30 minutes. Some estimates put total losses across all impacted users above 1,300 BTC, exceeding $80 million.
Why entropy matters
Bitcoin wallet security hinges on entropy—true unpredictability when generating a seed phrase. Industry practice targets 128 bits of entropy, making brute-force recovery infeasible on any realistic timeline.
Coldcard's v4.0.1 undermined that standard by defaulting to a software PRNG rather than the device's dedicated hardware RNG designed to produce genuine randomness from physical noise. Effective seed entropy fell to about 40 bits on Mk3 models and roughly 72 bits on Mk4, Mk5, and Q models, well below the 128-bit benchmark. At 40 bits, the search space is about one trillion combinations, a scale modern computing can traverse in hours rather than centuries.
How the theft unfolded
The sweeps began around July 3031, 2026. The attackers did not need remote access to devices, phishing, or malware. They exploited the reduced keyspace and reconstructed private keys by grinding through the weakened entropy. One operation alone hit about 500 wallets and extracted roughly 594 BTC in less than half an hour. The timing and uniformity suggest a large pool of vulnerable seeds may have been precomputed, with transfers executed in parallel.
Coinkite, the maker of Coldcard, released patched firmware to address the flaw. The fix does not retroactively strengthen seed phrases created under the affected firmware. Users who generated wallets on impacted versions are advised to create entirely new seed phrases using secure methods and migrate funds. Coinkite specifically recommended using physical dice rolls to ensure high entropy and warned against generating new seeds on unpatched devices.
Self-custody back in the spotlight
The incident has revived debate over whether self-custody is meaningfully safer than keeping assets on exchanges. Many affected users reportedly moved remaining Bitcoin to exchanges following the attack. Observers note the root cause was not an advanced zero-day or state-backed operation but a regression introduced via a firmware update. The fact that the weakness persisted from March 2021 to mid-2026 has raised questions about audit and testing rigor at Coinkite and across the hardware wallet sector more broadly.