Particle.news
Download on the App Store

Coldcard RNG Flaw Prompts Urgent Migrations After 594 BTC Sweep

A build error caused devices to use a predictable software fallback that made some seeds guessable and prompted Coinkite to publish migration steps and emergency firmware fixes.

Overview

  • A coordinated on-chain sweep moved about 594.48 BTC from roughly 500 single-signature wallets in a short window on Friday, with 562 BTC later consolidated into a single address.
  • Block’s engineers traced the likely cause to a March 2021 build/configuration change that skipped the device hardware random-number generator and fell back to a predictable MicroPython RNG seeded by nonsecret chip data.
  • Coinkite issued an advisory covering Mk3 seeds created on firmware 4.0.1–5.0.3, gave migration options including new seeds on patched devices or strong BIP-39 passphrases and dice-based entropy, and released hotfixes for newer models that do not alter existing seeds.
  • Both Coinkite and outside researchers say the analyses are preliminary: Block disclosed its findings to Coinkite, investigators are conducting a formal root-cause review, and no public, definitive proof yet links the Mk3 seed flaw to the 594 BTC theft.
  • The incident highlights that offline custody depends on correct seed generation, raises maintenance risks for legacy devices, and means exposed users must move funds carefully to avoid further losses while adopting passphrases, multisig, or user-supplied entropy.