Particle.news
Download on the App Store

Coldcard Firmware Flaw Exposes Seed Generation, Over $100M in Bitcoin Stolen

A deterministic software random‑number generator introduced in March 2021 collapsed entropy and forced urgent seed replacement.

Overview

  • Investigators tracked coordinated sweeps that began on July 30, 2026, with an initial drain of roughly 594 BTC and later waves that expanded the thefts into the thousands of addresses.
  • The root cause was a March 2021 firmware change that caused seed creation to use a deterministic MicroPython/Yasmarang fallback instead of the STM32 hardware RNG, reducing entropy to about 40–72 bits and making offline key reconstruction feasible.
  • Galaxy Research’s on‑chain forensics has confirmed roughly 1,596 BTC stolen across three waves and warned totals could reach about 2,055 BTC if a suspected fourth wave is validated, with roughly 90% of stolen coins still unmoved.
  • Coinkite released emergency patched firmware on August 1, 2026, and warned that updates only protect seeds generated after the fix, urging all affected users to make new seeds and migrate funds immediately.
  • The incident is prompting mass migrations that are distorting on‑chain market signals, intensifying scrutiny of self‑custody practices, and renewing calls for multisig, independent entropy sources or dice, and strong BIP‑39 passphrases.