Coldcard Wallet Bug Drained 2,055 BTC via Weak RNG That Audits Failed to Catch
Since July 30, approximately 2,055 BTC worth around $130 million has been stolen from Coldcard hardware wallets across multiple attack waves, with no phishing or malware involved. Attackers exploited a flaw introduced during a 2021 cryptography migration that silently redirected seed generation from the device's hardware random number generator to a weaker software fallback called Yasmarang. The root cause was a single flawed build directive — #ifndef — which checked whether a setting was defined rather than whether it was enabled, allowing a zero value to pass as valid. This reduced the key search space from 128 bits to roughly 40 bits on older models, making private keys brute-forceable offline and enabling one attacker to sweep $70 million in just 41 minutes. Security experts note that existing hardware wallet audits confirmed the correct generator existed in the codebase but never verified which code path actually executed on real devices — a systemic gap with no current industry standard to address it.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in