Coldcard RNG Flaw Let Attackers Reconstruct Seed Phrases Remotely, Draining $130M in Bitcoin

Coldcard RNG Flaw Let Attackers Reconstruct Seed Phrases Remotely, Draining $130M in Bitcoin

A predictable RNG fallback and 32-bit reseed flaw in Coldcard firmware let attackers brute-force victims' seed phrases without touching the device or its network. Galaxy Research puts losses at roughly $130 million as of August 4, 2026, with at least a dozen independent attackers involved across multiple waves. Coinkite urges firmware updates and seed migration. The air gap was irrelevant; the entropy source was the attack surface.

Published

Read at another depth