Coldcard seed-generation PRNG actively exploited security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Coldcard hardware wallet firmware carried a seed-generation flaw that used a deterministic software PRNG instead of the STM32 hardware RNG, enabling offline reconstruction of candidate seeds for affected wallets. The flaw was linked to a July 30 Bitcoin sweep that drained 1,196 addresses and about 1,082.65 BTC. Coinkite shipped emergency firmware on July 31, but existing seeds created on vulnerable builds still need to be replaced.
Related Happenings
COLDCARD wallet random number generation security flaw
Vulnerability
H score42
First: 05.08.2026 20:49
Last: 05.08.2026 20:49
Sources 1
About this happening:
A random number generation flaw in multiple COLDCARD models and firmware versions has been tied to theft of about 1,367 Bitcoin from 4,585 addresses, putting affec...
COLDCARD wallet random number generation security flaw
VulnerabilityAbout this happening: A random number generation flaw in multiple COLDCARD models and firmware versions has been tied to theft of about 1,367 Bitcoin from 4,585 addresses, putting affec...
Wallet software weak recovery-phrase generation actively exploited security flaw
Vulnerability
H score31
First: 10.07.2026 12:00
Last: 10.07.2026 12:00
Sources 1
About this happening:
Coinspect disclosed Ill Bloom, a weak-randomness recovery-phrase flaw in crypto wallet software that is actively exploited and can let attackers derive wallet addresse...
Wallet software weak recovery-phrase generation actively exploited security flaw
VulnerabilityAbout this happening: Coinspect disclosed Ill Bloom, a weak-randomness recovery-phrase flaw in crypto wallet software that is actively exploited and can let attackers derive wallet addresse...
FatFs seven vulnerabilities (CVE-2026-6682)
Vulnerability
H score28
First: 03.07.2026 23:19
Last: 03.07.2026 23:19
Sources 1
About this happening:
runZero disclosed seven vulnerabilities in FatFs, including CVE-2026-6682, exposing embedded devices to memory corruption, code execution, crashes, data leakag...
FatFs seven vulnerabilities (CVE-2026-6682)
VulnerabilityAbout this happening: runZero disclosed seven vulnerabilities in FatFs, including CVE-2026-6682, exposing embedded devices to memory corruption, code execution, crashes, data leakag...
Timeline
-
03.08.2026 11:40 1 articles · 4d ago
Coldcard exploit expands with second and third attack waves
Campaign Scope UpdateGalaxy Research identified a second and third Coldcard attack wave on August 1 that pushed the total stolen to 1,367 Bitcoin ($88.6m) from 4,385 victim addresses, and said on August 2 that the Coldcard exploit is ongoing while about 600 suspected hacker addresses tied to Coldcard-generated weak entropy funds were reported to investigators.
Show sources
- Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked — www.infosecurity-magazine.com — 03.08.2026 11:40
-
01.08.2026 20:17 2 articles · 6d ago
1,196 Bitcoin addresses are drained in a 41-minute sweep
Victim Impact UpdateAn attacker drains 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. The sweep is tied to Coldcard seed generation exposure and represents the direct financial impact on affected wallet holders.
Show sources
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — thehackernews.com — 01.08.2026 20:17
- COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft — www.bleepingcomputer.com — 03.08.2026 00:14
-
01.08.2026 20:17 1 articles · 6d ago
Coinkite ships emergency firmware for affected Coldcard models
Mitigation Patch UpdateCoinkite ships emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed. Owners with exposed seeds are told to generate a new one on patched firmware and move their coins, because the old seed can carry the weakness forward.
Show sources
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — thehackernews.com — 01.08.2026 20:17
-
01.08.2026 20:17 2 articles · 6d ago
Galaxy Research ties the Bitcoin sweep to a Coldcard seed-generation flaw
Initial DisclosureGalaxy Research maps the sweep to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Coinkite, and Block explains that an attacker who can constrain device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline. The analysis says libngu bound the build to MicroPython's Yasmarang fallback, the fallback was seeded from the chip's unique ID and timer registers, and candidate seeds can be checked against public blockchain data.
Show sources
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — thehackernews.com — 01.08.2026 20:17
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — thehackernews.com — 01.08.2026 20:17