Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

0
Low
Vulnerability
Published: 08/02/2026 (08/02/2026, 21:14:29 UTC)
Source: Bleeping Computer

Description

A vulnerability in the COLDCARD hardware wallet firmware caused the device to use a deterministic software random number generator instead of its hardware RNG, leading to weak wallet seed generation. This flaw allowed attackers to predict wallet seeds, steal an estimated $88.6 million in Bitcoin from thousands of affected wallets, and automate thefts with identical transaction fee patterns. The issue affected multiple firmware versions across Mk2, Mk3, Mk4, Mk5, and Q devices. Fixed firmware versions have been released, but users must generate new seeds and migrate funds as the flaw compromises existing seeds.

Affected software

Affected versions
>=4.0.1 <=4.1.9<5.6.0=1.5.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/02/2026, 21:18:15 UTC

Technical Analysis

The COLDCARD hardware wallet firmware contained an RNG integration error causing it to fallback to MicroPython's deterministic Yasmarang RNG instead of the STM32 hardware RNG. This fallback RNG used non-cryptographically secure sources such as the microcontroller identifier and system timing, enabling attackers to reconstruct wallet seeds offline. Attackers matched generated addresses with blockchain addresses to confirm seeds and steal Bitcoin. The flaw affected seeds generated on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, Mk4 and Mk5 devices before standard version 5.6.0 or Edge version 6.6.0X, and Q devices before standard version 1.5.0Q or Edge version 6.6.0QX. Fixed firmware versions are 4.2.0 or later for Mk2/Mk3, 5.6.0 or later for Mk4/Mk5, 1.5.0Q or later for Q devices, and 6.6.0X/6.6.0QX for Edge releases. Firmware updates do not fix previously generated seeds; users must generate new seeds and migrate funds. Coinkite destroyed affected unsent devices and notified customers with remediation instructions.

Potential Impact

Attackers exploited the RNG flaw to steal approximately 1,367 BTC (~$88.6 million) from 4,585 addresses by reconstructing wallet seeds and generating private keys. The theft was automated, prioritized high-value wallets, and left no change outputs in transactions. The stolen Bitcoin remained in attacker-controlled addresses at the time of reporting. The vulnerability compromises the fundamental security of affected wallet seeds, rendering funds accessible to attackers who can predict the RNG output.

Mitigation Recommendations

Fixed firmware versions are available and should be installed: 4.2.0 or later for Mk2/Mk3, 5.6.0 or later for Mk4/Mk5, 1.5.0Q or later for Q devices, and 6.6.0X/6.6.0QX for Edge releases. Users must verify existing backups, update firmware, generate new seeds, verify new wallet addresses, test with small transactions, and then migrate remaining funds. Old backups should be retained until migration is confirmed complete. Seeds supplemented with at least 50 fair, independent, and private dice rolls are not considered at risk from this flaw alone. Strong unique BIP-39 passphrases increase security but do not repair compromised seeds. Coinkite's TAPSIGNER, OPENDIME, and SATSCARD products are unaffected. Users should follow official migration instructions and treat existing seeds as compromised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/","fetched":true,"fetchedAt":"2026-08-02T21:18:02.140Z","wordCount":1036}

Threat ID: 6a6fb40abf32cb7a346a7a4e

Added to database: 08/02/2026, 21:18:02 UTC

Last enriched: 08/02/2026, 21:18:15 UTC

Last updated: 08/02/2026, 21:18:24 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses