Coldcard Firmware Bug: Five-Year-Old RNG Flaw Drains $130M in Bitcoin
The Coldcard firmware bug behind the current wave of bitcoin thefts traces back to a March 2021 update that routed seed generation through a deterministic software pseudo-random number generator instead of the STM32 hardware RNG. Galaxy Research has confirmed losses of 1,596 BTC, worth more than $100 million, from roughly 7,300 addresses in attacks that began July 30, and a suspected fourth wave could push the total toward 2,055 BTC, or about $130 million.
Coinkite, the Canadian maker of the Coldcard hardware wallet, has acknowledged the flaw and shipped emergency firmware updates. The vulnerability cut seed entropy far below the 128 bits users expect: Mk3 seeds dropped to roughly 40 bits, while Mk4, Mk5, and Coldcard Q models produced about 72 bits. That is a search space small enough for attackers to pre-compute seeds and rebuild private keys without physical access to any device.
The first wave emptied 1,196 addresses in 41 minutes on July 30, taking 1,082.65 BTC. Two more confirmed waves and 14 smaller incidents followed, and the attackers shifted from large holdings to smaller wallets: the third wave drained roughly 208 BTC from 1,912 addresses with an average balance just above 0.1 BTC. About 600 of the affected addresses belonged to federal investigators, industry compliance firms, and cyber-investigation teams, according to Galaxy Research.
Why the Coldcard firmware bug breaks the cold-storage promise
The attack required no phishing, no malware, and no contact with the devices. It worked because a key generated offline is only as secure as the firmware that produced it: once the seed was predictable, "cold storage" offered no protection. The air-gapped design of the device was never the weak point, which is what unsettles holders, since cold wallets are widely treated as the safest way to store bitcoin.
Affected firmware and what users should do
| Model | Vulnerable firmware | Seed entropy |
|---|---|---|
| Mk2 / Mk3 | 4.0.1 to 4.1.9 | ~40 bits on Mk3 (128 expected) |
| Mk4 / Mk5 | below 5.6.0 / Edge 6.6.0X | ~72 bits |
| Coldcard Q | below 1.5.0Q / Edge 6.6.0QX | ~72 bits |
Coinkite's advisory covers Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, Mk4 and Mk5 builds before standard 5.6.0 or Edge 6.6.0X, and Coldcard Q before standard 1.5.0Q or Edge 6.6.0QX. Firmware updates protect seeds generated after installation, but they cannot repair seeds created on vulnerable builds. Coinkite CEO Rodolfo Novak has advised anyone who generated a seed on a Coldcard to move funds now to addresses created with updated firmware or a different wallet.
For affected users, the only safe path is to update the device, generate a fresh seed, and transfer funds to the new addresses before moving anything else. Seeds from vulnerable firmware remain compromised and cannot be fixed, and entering an old recovery phrase into any online computer exposes it to the same risk. Coinkite has also said the bug lived in the interaction between two software components, and that AI-assisted code review may have helped attackers find it.
For the broader market, the Coldcard firmware bug shifts the risk calculus of self-custody: firmware provenance, update hygiene, and seed migration now matter as much as the device's offline design. The episode is the strongest evidence yet that hardware wallet security depends on the entire firmware supply chain, and users holding funds generated on affected builds should assume those keys are exposed.
Why this matters
For everyday bitcoin holders, the incident is a reminder that a hardware wallet's reputation is only as strong as the code inside it, and that a firmware update can be an emergency rather than a routine chore. The attack waves are still ongoing, and the final loss total has not been settled, so anyone with funds tied to a vulnerable seed should migrate immediately.
AI-generated image.
Related Articles
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.