Coldcard Seed RNG Bug Puts $116M of Bitcoin at Risk

AI Market Summary
Disclosure of a Coldcard seed-generation randomness flaw implies ~1,816 BTC (~$116m) may be vulnerable, with attackers reportedly sweeping funds by reconstructing low-entropy seeds without device access. While not a Bitcoin protocol issue, the incident pressures self-custody confidence, raises operational risk awareness around hardware wallets and backups, and can trigger near-term caution among holders as affected users migrate wallets despite a firmware fix only protecting future seeds.
Impact level
● Medium
Affected assets
BTC/USDT-0.22%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A newly disclosed flaw in how certain Coldcard hardware wallets generated recovery seeds has left about 1,816 BTC—roughly $116 million—potentially exposed, CoinDesk reported. The case is renewing scrutiny of seed randomness, backup practices and the broader security tradeoffs of self-custody. Coldcard is a Bitcoin-only hardware wallet made by Canada-based Coinkite. In a security advisory, the company said some units relied on an incorrect randomness source when creating mnemonic phrases, producing far less entropy than intended. Coinkite said affected firmware versions include 4.0.1 through 4.1.9 on Coldcard Mk2 and Mk3 devices. The firm estimates those units produced seeds with about 40 bits of effective entropy. Some Mk4, Mk5 and Q devices may have about 72 bits, versus a typical target of 128 bits. TRM Labs estimates an attacker has already moved about 1,816 BTC from more than 5,200 addresses tied to the issue. The report said the related funds made four suspicious transfers after July 30, and the totals could still change as analysis continues. According to TRM Labs, an attacker may not need physical access to the wallet or any firmware modification. If the weakened seed can be reconstructed, the corresponding private keys can be derived and transactions signed on other systems. Coinkite has released a firmware update for the affected models. The fix only protects seeds generated going forward; wallets created with vulnerable mnemonics still need to be migrated. The incident is also reigniting debate over self-custody. TEXITcoin founder Bobby Gray argued the event does not reflect a weakness in Bitcoin itself, but rather users' reliance on devices to automatically generate randomness. He said users who added their own dice-based entropy were not impacted in the same way. Gray also cautioned against treating the episode as evidence that exchange custody is inherently safer. For U.S. investors seeking only Bitcoin price exposure, spot Bitcoin ETFs avoid mnemonics and firmware upkeep. The risk profile shifts instead to institutional custody and the ETF's securities structure.