


Perceptive Security
SOC/SIEM Consultancy

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Published:
1 August 2026 at 19:17:22
Alert date:
1 August 2026 at 20:00:29
Source:
thehackernews.com
Emerging Technologies, Zero-Day Vulnerabilities, Data Breach & Exfiltration
An attacker drained 1,196 Bitcoin addresses in just 41 minutes on July 30, stealing 1,082.65 BTC valued at approximately $70.2 million. Galaxy Research investigated and traced the theft to a firmware vulnerability in Coldcard, a Bitcoin-only hardware wallet produced by Canadian company Coinkite. The root cause was a March 2021 firmware integration error that mistakenly routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of a secure hardware entropy source. This flaw made wallet seeds predictable and susceptible to brute-force or precomputed attacks. The scale and speed of the theft suggest a sophisticated, premeditated operation leveraging knowledge of the PRNG weakness. This incident highlights critical risks in hardware wallet firmware development and the catastrophic consequences of weak randomness in cryptographic key generation.
Technical details
A March 2021 firmware integration error in Coldcard hardware wallets routed seed generation to a deterministic software pseudorandom number generator (PRNG) — MicroPython's Yasmarang fallback — instead of the STM32 hardware random number generator (RNG). The root cause was in Coldcard's production config: the macro MICROPY_HW_ENABLE_RNG was set to zero because Coinkite supplies its own hardware-RNG wrapper, but the libngu library checked whether the macro existed rather than whether it was enabled. As a result, the MicroPython PRNG fallback was used, initialized only from the chip's unique ID (UID) and timer registers, with no fresh entropy collected after initialization. An attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. Candidate seeds can be checked by deriving their addresses and comparing them with public blockchain data. Effective entropy is estimated at roughly 40 bits on Mk3 and about 72 bits on Mk4/Mk5/Q, far below the 128 bits expected for a 12-word BIP-39 seed. On July 30, an attacker drained 1,196 Bitcoin addresses in 41 minutes, stealing 1,082.65 BTC (~$70.2 million). Galaxy Research identified the sweep by a unique on-chain signature pattern: 30 sat/vB fee rate with no change output, not seen in any other Bitcoin transactions in the prior 30 days. A related but separate weak-PRNG vulnerability dubbed 'Ill Bloom' (researched by Coinspect) affected older software wallets across Bitcoin, Ethereum, Tron, Rootstock, and Polygon, draining over $5 million since May.
Mitigation steps:
1. Determine whether your Coldcard seed was generated using a vulnerable firmware version (Mk2/Mk3: 4.0.0–4.1.9; Mk4/Mk5: before 5.6.0; Q: before 1.5.0Q; Edge builds: before 6.6.0X or 6.6.0QX). Exposure is based on the firmware version active at seed creation, not the current version. 2. Install the emergency firmware released by Coinkite on July 31 for all affected models and release tracks. Note: updating firmware does NOT repair an existing vulnerable seed. 3. Generate a new seed on patched firmware and move all coins to addresses derived from the new seed immediately. Do NOT restore the old seed to updated firmware or another wallet, as this carries the weakness forward. 4. If you used at least 50 fair, independent, private dice rolls to generate your seed, Coinkite states it is not at risk from this bug alone; however, if the number or privacy of rolls is uncertain, migrate the seed. 5. Adding a strong, unique BIP-39 passphrase creates a separate wallet inaccessible from the seed words alone, but Coinkite still recommends replacing the seed. 6. For multisig setups, ensure the signing quorum is not built entirely from affected Coldcard devices. 7. TAPSIGNER, OPENDIME, and SATSCARD use different codebases and are unaffected — no action needed for those. 8. Monitor on-chain activity for the distinctive sweep pattern: transactions with 30 sat/vB fee and no change output targeting multiple addresses in rapid succession.
Affected products:
Coldcard Mk2 - firmware versions 4.0.0 through 4.1.9 (vulnerable at seed creation time)
Coldcard Mk3 - firmware versions 4.0.0 through 4.1.9 (Coinkite lists 4.0.1–4.1.9; fixed in 4.2.0)
Coldcard Mk4 - firmware versions before 5.6.0
Coldcard Mk5 - firmware versions before 5.6.0
Coldcard Q - firmware versions before 1.5.0Q
Coldcard Mk4/Mk5 Edge builds - before 6.6.0X
Coldcard Q Edge builds - before 6.6.0QX
libngu library (used in Coldcard firmware
incorrect MICROPY_HW_ENABLE_RNG macro check)
MicroPython Yasmarang PRNG fallback (used unintentionally due to macro misconfiguration)
Related links:
https://x.com/glxyresearch/status/2083181683067506899
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
https://blog.coinkite.com/entropy-technical-backgrounder/
https://x.com/glxyresearch/status/2083255552633635183
https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html
Related CVE's:
Related threat actors:
IOC's:
On-chain pattern: sweep of 1,196 Bitcoin addresses in 41 minutes on July 30, Transaction signature: 30 sat/vB fee rate with no change output, 1,082.65 BTC drained in a single coordinated sweep, Addresses derived from low-entropy BIP-39 seeds generated by Coldcard firmware versions in affected range
This article was created with the assistance of AI technology by Perceptive.
