TRNG

Coldcard
2026-08-04 14:52:47

Coldcard says claims of permanent bricking from current firmware are inaccurate

Coldcard said in a post on X that claims saying its current firmware can permanently brick Coldcard devices are inaccurate. The company said that if a device encounters a TRNG fault, users only need to power-cycle it by fully removing all power and then restarting the device. According to Coldcard, the fault state is volatile and is not written to the device’s flash memory. It added that the system handles the condition in a “fail safe” manner, meaning the issue does not permanently damage the device. Coldcard also told users to keep following its earlier security guidance to address related risks, while noting that a fix is still being worked on. The statement was cited in an Odaily newsflash.

580
Coldcard says claims of permanent bricking from current firmware are inaccurate
Coldcard
2026-08-03 11:21:11

Coldcard flaw linked to 1,755 BTC theft as wallet trust comes under pressure

Coldcard’s hardware wallet security crisis has shaken confidence in Bitcoin self-custody after a flaw tied to its March 2021 v4.0.1 firmware update was linked to the theft of 1,755.95 BTC, worth more than $110 million at market prices. The issue stemmed from the use of a pseudo-random number generator instead of a true hardware random number generator during private-key creation, leaving affected wallets exposed to brute-force reconstruction for years. According to Galaxy Research, attackers emptied 1,196 victim addresses in just 41 minutes during the first two waves and moved more than $70 million before Coldcard issued its warning, with the main transfers completed about 30 hours earlier. In a later wave, the attacker used Replace-By-Fee transactions at a pace of as many as 13.8 transfers per block to push transactions through quickly. The fallout spread across the Bitcoin network. CryptoQuant said daily active addresses jumped from 645,000 on July 30 to nearly 1 million on July 31, while transfers below 1 BTC reached the highest level since November 2022, close to the spike seen after FTX filed for bankruptcy. The case also highlighted AI’s dual role in crypto security: attackers were described as using AI at scale, while community developers used Claude Code, Zhipu GLM 5.2 and Kimi K3 to identify and verify the flaw, with one scan reportedly taking just eight minutes.

520
Coldcard flaw linked to 1,755 BTC theft as wallet trust comes under pressure
Coldcard
2026-08-03 08:45:00

Coldcard flaw sparks fresh doubts over Bitcoin self-custody as $110 million in BTC is drained

A long-hidden flaw in Coldcard firmware has triggered one of the most jarring security shocks for Bitcoin self-custody users in recent years. According to PANews, 1,755.95 BTC, worth more than $110 million at market prices, was quietly drained from thousands of addresses on July 30, with most of the funds moved roughly 30 hours before an official warning was issued. The issue traces back to Coldcard’s v4.0.1 firmware released in March 2021, when the wallet reportedly used a pseudo-random number generator instead of a true hardware random source during private key generation. Galaxy Research said the first two waves of attacks emptied 1,196 victim addresses in just 41 minutes and moved more than $70 million before users were broadly alerted. CryptoQuant data showed a sharp jump in on-chain activity after the incident, with Bitcoin active addresses rising from 645,000 on July 30 to nearly 1 million on July 31, while sub-1 BTC transfers climbed to their highest level since November 2022. The episode has pushed market participants to reassess concentration risk in single-wallet setups and renewed discussion around multisig, MPC, social recovery wallets, exchange custody, and spot Bitcoin ETFs as alternatives or complements to pure hardware-wallet storage.

550
Coldcard flaw sparks fresh doubts over Bitcoin self-custody as $110 million in BTC is drained
Bitcoin Core
2026-07-30 23:02:52

Bitcoin Core developer says reported COLDCARD flaw was reproduced on freshly initialized MK3

Bitcoin News said in a post on X that Bitcoin Core developer instagibbs was able to reproduce a reported COLDCARD vulnerability on a newly initialized COLDCARD MK3 device using only the number of button presses during setup. He wrote, "sorry, now is the time to panic," and said he believes the issue affects MK2 and MK3 devices, while adding that he cannot yet confirm whether MK4 is vulnerable as well. Developer Antoine Poinsot said the key distinction is that the MK4 uses a hardware random number generator to provide entropy for the seed and actually relies on the microcontroller's true random number generator, or TRNG, while the MK3 does not. The proof of concept and mnemonic verification are still under review, according to the post cited by ChainCatcher.

790
Bitcoin Core developer says reported COLDCARD flaw was reproduced on freshly initialized MK3