Coldcard RNG Flaw Let Attackers Reconstruct Seed Phrases, Draining $130M in Bitcoin

Coldcard RNG Flaw Let Attackers Reconstruct Seed Phrases, Draining $130M in Bitcoin

A predictable random number generator in Coldcard hardware wallets let attackers brute-force victims' seed phrases without touching the device. Galaxy Research puts losses near $130 million as of August 4, 2026, with a dozen-plus attackers across multiple waves. Coinkite urges firmware updates and seed migration. The air gap didn't matter; the entropy source was the attack surface.

Published

Read at another depth