COLDCARD Firmware RNG Flaw Linked to Suspected $88.6M Bitcoin Theft
A vulnerability in COLDCARD hardware wallet firmware has been linked to the suspected theft of approximately 1,367 BTC, worth around $88.6 million, observed between July 30 and August 1, 2026. A conditional branching error in affected firmware versions caused wallet seed generation to rely on a predictable or severely limited random number generator instead of the hardware RNG. This allowed potential attackers to enumerate seed candidates offline and verify them against public Bitcoin blockchain addresses, then derive private keys and sweep funds without ever physically accessing the devices. Affected models include COLDCARD Mk2, Mk3 running firmware 4.0.0–4.1.9, and Mk4, Mk5, and Q devices below their respective patched versions. While cryptographic confirmation of exploitation has not been officially established, the theft transactions displayed automated characteristics including fixed fees, no change outputs, and rapid high-value targeting.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in