Coldcard RNG flaw tied to four suspected attack waves as scrutiny grows over Bitcoin self-custody risks
A years-old randomness flaw in Coldcard hardware wallet firmware has come under intense scrutiny after several waves of suspicious Bitcoin sweeps were linked by researchers to seeds created under affected software versions. Investigations by Block and Coinkite traced the issue to a 2021 code migration that routed seed generation through a software pseudorandom number generator instead of the intended hardware RNG on some firmware paths, reducing the effective search space of wallet seeds below the design target. Galaxy Research said three suspected attack waves it identified covered 4,585 addresses and 1,367.05 BTC, and on Aug. 3 its researchers flagged a fourth wave that was later updated to about 448.7 BTC across 709 potential victim addresses. Those figures come from on-chain pattern analysis and are not a wallet-by-wallet confirmation of Coldcard victims or final losses. The incident has also reopened debate over custody models. Researchers and market observers pointed to higher address activity, movements from older UTXOs, and inflows to centralized venues after the disclosure, while cautioning that on-chain data alone cannot prove those moves were caused by the Coldcard bug. Coinkite has said users with affected seeds need to generate a new seed in patched firmware or another trusted environment and move funds, because updating firmware alone does not restore the missing entropy in an already created mnemonic.








