Coldcard Bitcoin Theft Ongoing: Is Your Wallet Affected?

2 hours ago 8

A firmware error has disabled secure random number generation across multiple Coldcard hardware wallet generations, fueling an ongoing theft that has already drained 594.48 Bitcoin (BTC), worth about $38.3 million.

Coldcard maker Coinkite and Block’s Bitcoin engineering team traced the bug to a broken random number generator (RNG) check. As a result, attackers can rebuild a wallet’s private keys using predictable device details instead of true randomness.

Coldcard Bitcoin Theft: How It Happened

Coldcard’s firmware turns off the chip’s built-in randomness generator. Instead, a backup system builds wallet keys from the device’s serial number and its internal clock. Both follow patterns an attacker can guess, turning a supposedly random seed into a solvable puzzle.

Devices running certain firmware released since 2021 get almost no real randomness at all. Newer models add a partial fix. It still narrows the possible outcomes to roughly four billion combinations, a number modern computers can work through. Historically, Block traced the flaw to that 2021 update, and a follow-up fix a year later still fell short.

Therefore, the same weakness touches paper wallets, seed backups, and other features that share the same random source. Block’s report confirmed the wider reach. The setup resembles the Ill Bloom exploit, which drained wallets through weak seed phrases earlier this year.

What Users Should Do Now

Attackers do not need physical access to steal funds. A visible address or exported public key gives them a target to test guesses against. Once a guess matches, the attacker holds the private key and can move the coins immediately.

Coinkite recommends that every affected user generate a brand new seed on updated hardware and move funds right away. Firmware updates cannot undo the damage, because the weak seed still exists on the device.

COLDCARD Mk3 Security Advisory

If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.

Mk4, Q and Mk5 are not affected based on our early analysis.

Read the advisory and migrate carefully:https://t.co/3vgPHOjMS7

— COLDCARD (@COLDCARDwallet) July 30, 2026

Meanwhile, users who added an extra passphrase to their seed face substantially lower risk from this flaw. It is an approach ZachXBT recently endorsed for mobile wallets, too.

Weak key generation has drained crypto holders before. Similarly, a master key exposure hit South Korea’s tax agency earlier this year. A private key breach crashed Humanity Protocol’s token 88% in June.

Vendors keep expanding offline hardware wallets into retail stores. Yet this incident shows firmware bugs can undercut that promise from inside the device.

Coinkite and Block say they are still assessing how far the flaw’s reach extends across older firmware. Until that review closes, Coldcard owners should assume any seed generated before today’s fix might already be compromised.

The post Coldcard Bitcoin Theft Ongoing: Is Your Wallet Affected? appeared first on BeInCrypto.

Read Entire Article