Researchers believe a COLDCARD RNG flaw may have enabled attackers to steal an estimated $88.6 million in Bitcoin from thousands of hardware wallets.

Galaxy Research linked the suspected exploit to several coordinated transaction waves that drained 1,367 BTC from 4,585 addresses. The activity began on July 30, roughly 30 hours before wallet maker Coinkite publicly disclosed the issue.

The stolen funds remained in attacker-controlled addresses when Galaxy published its findings.

Automated thefts targeted vulnerable wallets

Galaxy identified an initial wave that moved around 1,083 BTC, then valued at $70.2 million, from 1,196 wallet addresses in only 41 minutes.

Each transaction used the same hardcoded fee rate of 30 satoshis per virtual byte. They also left no change output, which suggests an automated system was sweeping wallets whose private keys it already controlled.

Further transaction activity on August 1 increased the estimated theft to 1,367 BTC, worth around $88.6 million.

Chainalysis said the attacker appeared to prioritise the most valuable targets. Approximately $30 million was reportedly taken in the first ten minutes, while one victim lost $1.8 million. This pattern suggests the attacker had already identified vulnerable addresses before the thefts began.

Firmware error weakened wallet seed generation

Block’s Bitcoin Engineering and Security teams investigated reports of stolen COLDCARD funds alongside other researchers. They traced the problem to an integration error in the wallet’s random number generation code.

Although the devices contain a hardware random number generator, flawed firmware checks caused affected models to use MicroPython’s deterministic Yasmarang software fallback instead.

That fallback used the device’s microcontroller identifier and timing data. These values are not secure sources of randomness and may be observable or reconstructed by an attacker.

As a result, attackers could generate possible wallet seeds offline, calculate the Bitcoin addresses linked to them, and compare those addresses with public blockchain data. Once they found a match, they could derive the private keys and take the funds.

Which COLDCARD wallets are affected?

Coinkite says the affected seeds include those generated on:

  • Mk2 and Mk3 devices running firmware versions 4.0.1 to 4.1.9
  • Mk4 and Mk5 devices before standard firmware 5.6.0 or Edge firmware 6.6.0X
  • Q devices before standard firmware 1.5.0Q or Edge firmware 6.6.0QX

Updated firmware is now available. However, installing it alone does not secure a seed that was generated using the flawed random number process.

Affected users should create a new seed

Users with potentially affected wallets should first confirm they have a working backup. They should then install the fixed firmware, generate a completely new seed, record it securely, and verify the new wallet address directly on the device.

Before transferring all remaining Bitcoin, users should send a small test transaction. The old backup should remain available until the migration is complete and confirmed.

Coinkite says wallets created using at least 50 fair, private and independent dice rolls are not at risk from this COLDCARD RNG flaw alone. A strong, unique BIP-39 passphrase also raises the difficulty of an attack, but it does not fix an exposed seed.

TAPSIGNER, OPENDIME and SATSCARD products are not affected, as they use separate codebases.


0 responses to “COLDCARD RNG Flaw Linked to $88.6M Bitcoin Theft”