Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: seed-theft (1 article)Clear

Coldcard wallet firmware flaw let attackers guess seeds and steal 70 million dollars

A firmware flaw in Coldcard Bitcoin hardware wallets let attackers reconstruct wallet seeds offline and sweep roughly 70 million dollars from 1,196 addresses in 41 minutes on July 30. A March 2021 build error routed seed generation to a weak software random number generator instead of the device's hardware one, because the check confirmed a configuration macro existed rather than that it was enabled. That collapsed the randomness behind seeds to as little as 40 bits on older models, letting an attacker who can constrain the device identifier and timer state reproduce candidate seeds and match them to funded addresses. Coinkite shipped emergency firmware, but updating does not repair an already-generated seed.

Check
If you use a Coldcard wallet, check whether your seed was generated on affected firmware, and if so, generate a new wallet on patched firmware and move funds to fresh addresses.
Affected
Coldcard hardware wallet users whose seeds were generated on affected firmware from March 2021 onward; the weak randomness lets attackers reconstruct seeds offline and drain funds.
Fix
Generate a new seed on patched firmware and move funds to new addresses, treat any wallet made on affected firmware as compromised, and verify hardware RNGs are enabled, not just present.