Silent Coldcard Seed Generation Bug Leads to $86M Bitcoin Theft Across Years

A hidden firmware configuration error in Coldcard wallets weakened seed generation for almost five years, eventually resulting in the theft of 1,367 BTC across 4,585 wallet addresses.

According to blockchain tracking published by Galaxy Research on Aug. 2, 2026, a pseudo-random number generator (PRNG) vulnerability that existed in Coldcard hardware wallet firmware since March 2021 caused losses of approximately 1,367 BTC, valued at around $86 million.

The exploit represents the largest confirmed Bitcoin hardware wallet attack by stolen funds. Unlike many crypto breaches, the incident did not involve phishing, stolen devices, or user mistakes. Instead, attackers exploited a weakness built into the wallet-generation process itself.

The event highlights a key principle of self-custody security: the protection of funds depends on the quality of randomness used to create wallet seeds. A single software configuration mistake can weaken that protection for years without creating obvious signs of compromise.

The attack unfolded as Bitcoin traded down about 1.4% at nearly $62,250 following a volatile week that pushed the cryptocurrency lower from above $65,000. Bitcoin’s daily trading volume stood near $16.9 billion, compared with more than $20 billion the previous day.

How a Firmware Error Weakened Coldcard Wallets

The vulnerability was traced by Block’s engineering team to Coldcard’s libngu library. Coinkite had configured a board setting to zero in order to disable MicroPython’s random number generator and force the device to rely on its hardware true random number generator (TRNG).

However, the libngu safeguard only checked whether the macro was present rather than verifying its actual value. This allowed the zero setting to pass validation.

Because of this, MicroPython removed the STM32 hardware RNG call during compilation and switched to Yasmarang, a software-based PRNG that provided only about 40 bits of effective entropy instead of the 128 bits expected for a BIP-39 seed phrase.

Newer Coldcard models, including Mk4, Mk5, and Q, improved entropy levels to an estimated 72 bits, but still remained below the ideal security standard. The gap between 40-bit and 128-bit entropy significantly reduced the protection of affected wallets.

On July 30, 2026, Coinkite issued a security warning just hours before attackers began draining funds. The first major wave removed roughly 594 BTC from around 500 addresses, followed by additional attacks that increased total losses to 1,367.05 BTC across 4,585 addresses by Aug. 2.

Most of the stolen Bitcoin has not yet been transferred, suggesting the attacker may be holding the funds rather than immediately moving or selling them.

Weak Randomness Remains a Recurring Crypto Threat

The Coldcard breach follows a long history of cryptocurrency security failures caused by flawed randomness systems.

In 2013, Android’s SecureRandom vulnerability caused repeated ECDSA nonces, exposing private keys linked to several Bitcoin wallets. In 2022, the Profanity vanity address generator weakness contributed to the Wintermute attack, where attackers exploited only 32 bits of entropy and stole roughly $160 million.

The Milk Sad vulnerability discovered in 2023 revealed that Libbitcoin Explorer’s bx seed tool used a Mersenne Twister generator seeded with system time. This reduced the expected 256-bit entropy to around 32 bits and exposed more than 120,000 wallets.

Despite involving different technologies, each case shared the same underlying issue: a randomness mechanism that appeared secure but failed to provide the required level of protection.

Ari Redbord, global head of policy at TRM Labs, said the Coldcard incident demonstrates that self-custody does not remove security risks but instead transfers responsibility to different parts of the system. TRM Labs’ first-half 2026 data showed that infrastructure and key compromises accounted for 15% of incidents but represented 76% of total losses across 207 recorded hacks.

Galaxy Research said it has identified about 600 suspected attacker-controlled addresses and shared information with federal investigators, compliance providers, and cybersecurity firms.

The research firm added that its Coldcard attribution is based on on-chain analysis and behavioral patterns rather than direct reconstruction of seed phrases for each individual wallet.