In a shocking turn of events, the Coldcard hardware wallet, a trusted device for securing cryptocurrencies, has been compromised due to a critical flaw in its random number generation (RNG) process. This vulnerability has led to the theft of approximately $70 million in bitcoin from hundreds of wallets on July 30, 2026. The incident has raised significant concerns about the security of hardware wallets and the importance of rigorous firmware testing.
The Exploit Unveiled
According to a detailed analysis by Galaxy Research, the attack was executed in a tightly coordinated 25-minute burst, with broader activity spanning about 41 minutes. The attack targeted wallets that used Coldcard devices running vulnerable firmware released from March 2021 onward. The flaw in the RNG resulted in seeds with only 40 bits of entropy instead of the expected 128 bits, making them significantly easier to guess.
How the Flaw Occurred
The vulnerability stemmed from a configuration issue during a software-library migration in 2021. A configuration setting that was supposed to enable the hardware RNG was incorrectly set to zero, causing the device to fall back to a weaker software-based RNG. This weaker generator relied heavily on predictable inputs such as the device’s serial number and startup timing, drastically reducing the entropy of the generated seeds.
Impact and Response
The attack primarily affected long-term holders who had not updated their firmware or added additional randomness to their seeds. Coinkite, the manufacturer of Coldcard, has issued security advisories and released corrected firmware. Users are advised to update their devices, create new seeds, and transfer their funds to the new wallets immediately. However, simply updating the firmware is not enough; the old seeds remain compromised and must be replaced.
Preventive Measures and Community Response
Users who added their own randomness, such as rolling dice or using a strong BIP-39 passphrase, were largely protected. Multi-signature wallets, which require keys from multiple devices, were also less vulnerable. However, many victims followed standard security practices, believing their Coldcard devices were secure. This incident highlights the need for users to adopt additional security measures and for manufacturers to conduct thorough and independent firmware reviews.
Looking Forward
The Coldcard exploit serves as a stark reminder of the importance of robust security practices in the cryptocurrency ecosystem. Coinkite has accepted full responsibility for the flaw and is working to assist affected users. The incident is also likely to spur increased scrutiny and innovation in hardware wallet security. For users, the immediate priority is to secure their funds and remain vigilant against potential threats. The community’s response will be crucial in restoring trust and ensuring the continued safety of cryptocurrency holdings.
