Coldcard RNG Bug Tied to ~1,816 BTC in Suspected Losses; Some Users Told to Rebuild Wallets

AI Market Summary
Coldcard disclosed an RNG-related seed generation flaw affecting specific legacy firmware ranges, with researchers estimating ~1,816 BTC stolen across suspected attack waves. Mandatory wallet migrations for impacted users and heightened focus on hardware-wallet operational risk can pressure near-term Bitcoin flows via precautionary exchange deposits and reshuffling of custody. While the fix strengthens future seed creation via required user entropy, prior weak seeds remain vulnerable until funds are moved.
Impact level
● Medium
Affected assets
BTC/USDT+7.98%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Coldcard has issued two security updates and says some customers need to generate a fresh wallet and move any Bitcoin tied to affected recovery phrases, after a flaw in seed generation raised the risk of funds being drained. Firmware updates and review Coldcard released firmware 5.6.1 for Mk4/Mk5 devices and 1.5.1Q for Coldcard Q, following a three-week review that began after a July 31 emergency hotfix. The review revisited the earlier seed-generation failure and also examined signing, device connectivity, firmware installation, and random-number checks. Coldcard said it recognizes customers who suffered losses and has tightened seed creation to require private user-provided entropy. Who is affected Only seeds created on certain older firmware versions are at risk; not every Coldcard seed is impacted. - Mk2/Mk3: seeds created on firmware 4.0.1 through 4.1.9 - Mk4/Mk5: seeds created before standard 5.6.0 (or Edge 6.6.0X) - Coldcard Q: seeds created before standard 1.5.0Q (or Edge 6.6.0QX) Coldcard added that Mk1 devices and other Coinkite products (TAPSIGNER, OPENDIME, SATSCARD) use different software and are not covered by this disclosure. What changed in seed creation New seeds must now incorporate at least one source of user-supplied randomness, mixed with the device’s STM32 true random-number generator and two secure elements (SE1 and SE2). Accepted sources of user entropy include: - at least 65 key presses with unpredictable timing, or - 50 private rolls of a fair six-sided die, or - 128 physical coin flips. Coldcard warned user inputs must remain private, since anyone who records them could help reconstruct the seed. The changes apply only to seeds created after installing the updated firmware; they cannot add randomness to seeds generated in the past. What affected users should do Coldcard’s recommended steps: 1) Update firmware and verify the update's digital signature before installing. 2) Create and verify a completely new seed using the updated entropy process. 3) Move funds from the old wallet to addresses controlled by the new seed. Verify the receiving address on-device, send a small test transfer, then migrate the remaining balance. 4) Keep the old backup offline until the move is confirmed, but stop using it to receive funds. Notes and exceptions Coldcard said wallets where owners added at least 50 fair, independent, private dice rolls before the final seed words were generated already contributed about 128 bits of entropy and are not subject to forced migration. If a user cannot prove they did this, Coldcard recommends migrating. The company also said a BIP39 passphrase can add friction for attackers but does not fix a weak underlying seed; it advises replacing the recovery phrase even if a passphrase was used. Technical origin and estimated impact The issue traces back to a March 2021 firmware change that could cause devices to fall back to a deterministic MicroPython routine for seed generation instead of using the STM32 hardware TRNG. Block’s review estimated effective entropy of roughly 40 bits for older Mk2/Mk3 devices and about 72 bits for vulnerable Mk4/Mk5/Q devices, below the intended 128 bits, making some seeds potentially searchable offline. Researchers have linked four suspected attack waves to the flaw, estimating about 1,816 BTC taken from more than 5,200 addresses, though loss estimates may change as investigations continue. Blockchain analytics firm Galaxy Research said it shared suspected attacker addresses with exchanges and U.S. law enforcement. As of early August, it estimated roughly 90% of Bitcoin moved during confirmed attack waves remained in identified destination wallets. Other firmware changes Additional updates include staged verification of partially signed Bitcoin transactions (PSBTs) immediately before signing, a change to default SIGHASH handling that alters which parts of a transaction a signature covers, and broader hardening of USB boundaries and firmware-update checks. Coldcard also cited improved isolation in Delta Mode, fixes to backup behavior, and extra checks around RNG initialization and fault conditions. Why it matters The episode highlights how critical strong randomness is to wallet security. When seed entropy is weak, attackers can derive likely seeds, compute addresses, and drain funds without physical access, PINs, or network attacks. Some users have moved funds to exchanges or other custodians, shifting risk to third parties and coinciding with elevated exchange inflows. Bottom line If your Coldcard seed was created on one of the vulnerable firmware versions, update your device, generate a new seed using the updated entropy workflow, and migrate your Bitcoin using Coldcard's verification steps. Verify firmware signatures before installing updates, and keep migration backups until you have confirmed the move was successful.