PRNG

Coldcard
2026-08-18 16:02:53

Coldcard hack probe points to possible FBI lead on first wave attacker

Law enforcement may already have a concrete lead on the operator behind the first and largest wave of the July 2026 Coldcard wallet drains, according to reporting by Bitcoin Magazine. The report centers on 1,082.65 BTC taken in the initial wave, a tranche that remains untouched in the attacker’s address and is still being watched on-chain. Alex Thorn of Galaxy Research said publicly that the identity of the Wave 1 attacker may be known to authorities, while Block engineering lead Clay Garrett said Block’s investigation traced the sweep pattern to a paid account at a major blockchain services provider whose internal logs matched the theft workflow with unusual precision. The article also reconstructs the vulnerability that made the theft possible: a bug introduced in March 2021 during Coldcard’s migration to libngu that redirected randomness generation away from the STM32 hardware RNG and into MicroPython’s Yasmarang PRNG fallback. According to the report, that reduced effective entropy to roughly 40 bits on older models and around 72 bits on newer ones. As of early August, confirmed and estimated losses across multiple waves had exceeded 1,800 BTC from more than 5,000 addresses, with roughly $118 million confirmed stolen. The piece reviews claims of a possible insider “retirement attack,” but says public evidence remains insufficient to support that conclusion.

100
Coldcard hack probe points to possible FBI lead on first wave attacker
Bitcoin
2026-08-06 18:43:13

Coldcard flaw revives open-vs-closed source debate as AI shrinks the cost of reading code

Bitcoin Magazine published a guest essay by Fedi content producer Colin Crossman arguing that the Coldcard entropy flaw has exposed the limits of security through obscurity. The piece says users who followed standard precautions still lost Bitcoin after seed generation was routed to MicroPython’s Yasmarang PRNG instead of a hardware entropy source, reducing effective entropy to about 40 bits on some models. According to the article, attackers first swept 500 addresses, and Galaxy Research later counted 4,585 addresses and nearly $90 million, with the attack still ongoing at the time of writing. Crossman argues that Coinkite’s shift from a free-software license to source-available terms did not materially improve protection because machines can read distributed code regardless of licensing. He links that point to the rise of AI-assisted code analysis, noting that while an earlier AI audit found nothing, researchers later showed frontier models identifying the same flaw within minutes from a single prompt. The essay extends the argument beyond open-source licensing, saying closed binaries retain only a thin and eroding security margin. The article also references Heartbleed, the xz backdoor, and the Milk Sad vulnerability, and says openness is not a guarantee of safety. Its case is narrower: reproducible builds, smaller trusted cores, published interfaces, and key distribution across independent implementations offer stronger defenses than relying on code being hard for humans to read.

590
Coldcard flaw revives open-vs-closed source debate as AI shrinks the cost of reading code
Coldcard
2026-08-04 19:11:36

Coldcard flaw left Bitcoin wallet keys guessable as thefts topped 1,596 BTC

Coldcard, the air-gapped hardware wallet made by Canada-based Coinkite, is facing one of the more serious key-generation failures seen in Bitcoin self-custody. According to Galaxy Research, more than 1,596 BTC has been stolen across three confirmed waves from roughly 7,300 addresses, with a suspected fourth wave pushing the total to about 2,055 BTC, or roughly $130 million at current prices. One sweep moved $70 million in 41 minutes, and Coinkite said at least 15 separate attackers have joined in. In a technical backgrounder published on August 1, Coinkite said the issue traces back to a migration in 2021, when Coldcard’s seed generation path was unintentionally routed away from its hardware random number generator and into MicroPython’s Yasmarang software fallback. On affected Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9, the resulting entropy was estimated at about 40 bits; newer devices reached roughly 72 bits after mixing in some secure-element entropy, still below the 128-bit target. The fix is available in updated firmware, but existing wallet seeds remain compromised and must be replaced. Users who created seeds on affected devices without dice rolls or a strong BIP-39 passphrase are being told to generate a new seed and move funds.

590
Coldcard flaw left Bitcoin wallet keys guessable as thefts topped 1,596 BTC
Coldcard
2026-08-03 11:21:11

Coldcard flaw linked to 1,755 BTC theft as wallet trust comes under pressure

Coldcard’s hardware wallet security crisis has shaken confidence in Bitcoin self-custody after a flaw tied to its March 2021 v4.0.1 firmware update was linked to the theft of 1,755.95 BTC, worth more than $110 million at market prices. The issue stemmed from the use of a pseudo-random number generator instead of a true hardware random number generator during private-key creation, leaving affected wallets exposed to brute-force reconstruction for years. According to Galaxy Research, attackers emptied 1,196 victim addresses in just 41 minutes during the first two waves and moved more than $70 million before Coldcard issued its warning, with the main transfers completed about 30 hours earlier. In a later wave, the attacker used Replace-By-Fee transactions at a pace of as many as 13.8 transfers per block to push transactions through quickly. The fallout spread across the Bitcoin network. CryptoQuant said daily active addresses jumped from 645,000 on July 30 to nearly 1 million on July 31, while transfers below 1 BTC reached the highest level since November 2022, close to the spike seen after FTX filed for bankruptcy. The case also highlighted AI’s dual role in crypto security: attackers were described as using AI at scale, while community developers used Claude Code, Zhipu GLM 5.2 and Kimi K3 to identify and verify the flaw, with one scan reportedly taking just eight minutes.

540
Coldcard flaw linked to 1,755 BTC theft as wallet trust comes under pressure
Coldcard
2026-08-03 08:45:00

Coldcard flaw sparks fresh doubts over Bitcoin self-custody as $110 million in BTC is drained

A long-hidden flaw in Coldcard firmware has triggered one of the most jarring security shocks for Bitcoin self-custody users in recent years. According to PANews, 1,755.95 BTC, worth more than $110 million at market prices, was quietly drained from thousands of addresses on July 30, with most of the funds moved roughly 30 hours before an official warning was issued. The issue traces back to Coldcard’s v4.0.1 firmware released in March 2021, when the wallet reportedly used a pseudo-random number generator instead of a true hardware random source during private key generation. Galaxy Research said the first two waves of attacks emptied 1,196 victim addresses in just 41 minutes and moved more than $70 million before users were broadly alerted. CryptoQuant data showed a sharp jump in on-chain activity after the incident, with Bitcoin active addresses rising from 645,000 on July 30 to nearly 1 million on July 31, while sub-1 BTC transfers climbed to their highest level since November 2022. The episode has pushed market participants to reassess concentration risk in single-wallet setups and renewed discussion around multisig, MPC, social recovery wallets, exchange custody, and spot Bitcoin ETFs as alternatives or complements to pure hardware-wallet storage.

570
Coldcard flaw sparks fresh doubts over Bitcoin self-custody as $110 million in BTC is drained
Coldcard
2026-08-01 16:41:01

Coldcard features may remain exposed to Yasmarang PRNG flaw even if seed phrase is safe

Bitcoin News said in a post on X that several Coldcard functions may still be vulnerable because of a flaw in the Yasmarang pseudo-random number generator, even when the seed phrase itself remains secure. The post said mnemonic phrases generated by rolling dice enough times, or seed phrases imported from an existing source, are still safe on their own. The issue instead affects other secrets created through the device’s flawed randomness. Functions named in the post include paper wallets, device cloning, USB sessions, Secret Teleport, multisig keys, the password generator, and HSM mode. The warning suggests that protecting a mnemonic phrase through manual dice rolls does not fully shield every feature on the hardware wallet if those features depend on the affected random number generator.

610
Coldcard features may remain exposed to Yasmarang PRNG flaw even if seed phrase is safe