Coldcard Bitcoin exploit explained: How a firmware bug turned entropy into a ticking time bomb

Via bitrawr.com

Coldcard Bitcoin exploit explained: How a firmware bug turned entropy into a ticking time bomb

A 2021 code change quietly swapped Coldcard's hardware random number generator for a weaker software alternative, and attackers finally noticed.

For five years, a subset of Coldcard hardware wallets were generating Bitcoin keys with the cryptographic equivalent of a flimsy padlock. The bug, introduced during a March 2021 firmware rewrite in version 4.0.1, replaced the device’s hardware random number generator with a software-based pseudorandom number generator. The result: seed phrases that looked secure but were dramatically easier to crack than anyone realized.

Attackers figured it out in late July 2026, executing coordinated sweeps that drained approximately 594 BTC, roughly $38 million, from around 500 wallets in under 30 minutes. Some estimates put the total losses across all affected users at over 1,300 BTC, north of $80 million.

What went wrong with entropy

Here’s the thing about Bitcoin security: it all comes down to randomness. When a hardware wallet generates your seed phrase, it needs to pull from a source of entropy, true unpredictability, that makes your private keys essentially impossible to guess. The industry standard target is 128 bits of entropy, which translates to a number so astronomically large that brute-forcing it would take longer than the age of the universe.

Advertisement

Coldcard’s firmware version 4.0.1 broke that promise. Instead of using the device’s dedicated hardware RNG, a physical chip designed to produce genuinely random numbers from electrical noise, the updated code defaulted to a software-based PRNG.

The effective seed entropy dropped to approximately 40 bits for Mk3 models. For Mk4, Mk5, and Q models, it was roughly 72 bits. Both figures fall well below the 128-bit target. To put 40 bits in perspective, that’s roughly one trillion possible combinations. Sounds like a lot until you realize that modern computing can chew through that search space in hours, not centuries.

The attack and its aftermath

The coordinated wallet sweeps began around July 30-31, 2026. Attackers didn’t need to hack into anyone’s device remotely. They didn’t need phishing emails or malware. They simply exploited the mathematical weakness baked into the seed generation process itself, grinding through the reduced keyspace to reconstruct private keys.

One sweep alone hit approximately 500 wallets, draining around 594 BTC in less than half an hour. The speed and precision suggested the attackers had pre-computed a large set of vulnerable seeds before executing the transfers simultaneously.

Coinkite, the company behind Coldcard, responded by releasing patched firmware to address the flaw. But fixing the firmware doesn’t fix seeds that were already generated with weak entropy. Users who created their wallets on affected firmware versions need to generate entirely new seed phrases using secure methods and migrate their funds. Coinkite specifically recommended using physical dice rolls to ensure high entropy during new seed generation. The company also warned users not to generate new seeds on unpatched devices.

The self-custody debate reignites

The fallout has reignited one of crypto’s oldest arguments: is self-custody actually safer than trusting an exchange? The immediate reaction from many affected users was to move their remaining Bitcoin to exchanges.

This wasn’t a sophisticated zero-day exploit or a nation-state attack. It was a regression bug in a firmware update. The fact that it persisted from March 2021 until mid-2026 raises serious questions about the audit and testing processes at Coinkite and, by extension, across the hardware wallet industry.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Coldcard Bitcoin exploit explained: How a firmware bug turned entropy into a ticking time bomb

Coldcard Bitcoin exploit explained: How a firmware bug turned entropy into a ticking time bomb

A 2021 code change quietly swapped Coldcard's hardware random number generator for a weaker software alternative, and attackers finally noticed.

Via bitrawr.com

For five years, a subset of Coldcard hardware wallets were generating Bitcoin keys with the cryptographic equivalent of a flimsy padlock. The bug, introduced during a March 2021 firmware rewrite in version 4.0.1, replaced the device’s hardware random number generator with a software-based pseudorandom number generator. The result: seed phrases that looked secure but were dramatically easier to crack than anyone realized.

Attackers figured it out in late July 2026, executing coordinated sweeps that drained approximately 594 BTC, roughly $38 million, from around 500 wallets in under 30 minutes. Some estimates put the total losses across all affected users at over 1,300 BTC, north of $80 million.

What went wrong with entropy

Here’s the thing about Bitcoin security: it all comes down to randomness. When a hardware wallet generates your seed phrase, it needs to pull from a source of entropy, true unpredictability, that makes your private keys essentially impossible to guess. The industry standard target is 128 bits of entropy, which translates to a number so astronomically large that brute-forcing it would take longer than the age of the universe.

Advertisement

Coldcard’s firmware version 4.0.1 broke that promise. Instead of using the device’s dedicated hardware RNG, a physical chip designed to produce genuinely random numbers from electrical noise, the updated code defaulted to a software-based PRNG.

The effective seed entropy dropped to approximately 40 bits for Mk3 models. For Mk4, Mk5, and Q models, it was roughly 72 bits. Both figures fall well below the 128-bit target. To put 40 bits in perspective, that’s roughly one trillion possible combinations. Sounds like a lot until you realize that modern computing can chew through that search space in hours, not centuries.

The attack and its aftermath

The coordinated wallet sweeps began around July 30-31, 2026. Attackers didn’t need to hack into anyone’s device remotely. They didn’t need phishing emails or malware. They simply exploited the mathematical weakness baked into the seed generation process itself, grinding through the reduced keyspace to reconstruct private keys.

One sweep alone hit approximately 500 wallets, draining around 594 BTC in less than half an hour. The speed and precision suggested the attackers had pre-computed a large set of vulnerable seeds before executing the transfers simultaneously.

Coinkite, the company behind Coldcard, responded by releasing patched firmware to address the flaw. But fixing the firmware doesn’t fix seeds that were already generated with weak entropy. Users who created their wallets on affected firmware versions need to generate entirely new seed phrases using secure methods and migrate their funds. Coinkite specifically recommended using physical dice rolls to ensure high entropy during new seed generation. The company also warned users not to generate new seeds on unpatched devices.

The self-custody debate reignites

The fallout has reignited one of crypto’s oldest arguments: is self-custody actually safer than trusting an exchange? The immediate reaction from many affected users was to move their remaining Bitcoin to exchanges.

This wasn’t a sophisticated zero-day exploit or a nation-state attack. It was a regression bug in a firmware update. The fact that it persisted from March 2021 until mid-2026 raises serious questions about the audit and testing processes at Coinkite and, by extension, across the hardware wallet industry.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.