Coldcard hardware wallet RNG vulnerability from 2021 code migration weakened seeds for nearly five years, affecting ~5,294 addresses and 1,815.75 BTC across four suspected attack waves.
Security & Exploits ·
A flaw in random number generation stemming from a 2021 code migration compromised seed creation across multiple Coldcard hardware wallet models and firmware versions over a span of nearly five years. The vulnerability caused the device firmware to rely on a predictable software-based random number generator rather than its hardware counterpart, shrinking the computational difficulty of brute-forcing seeds to approximately 40 bits for Mk2 and Mk3 units and around 72 bits for subsequent generations. Simply upgrading firmware or transferring a compromised seed to a different wallet does not resolve the issue; affected users must create fresh seeds using corrected firmware or an alternative secure environment, then move their holdings accordingly.
Galaxy Research documented four distinct waves of suspected exploitation targeting roughly 5,294 addresses holding approximately 1,815.75 BTC. These tallies derive from patterns visible on the blockchain but remain unverified—the numbers do not confirm individual victims or final confirmed damages. The vulnerability stems from flawed key generation in particular Coldcard firmware iterations and does not indicate a breach of Bitcoin's cryptographic foundation itself.
What remains unclear is how many users knowingly or unknowingly held seeds generated during the vulnerable window and whether the four identified attack waves represent the full extent of exploitation or if additional drains may have occurred undetected.