COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
A vulnerability in COLDCARD hardware wallet firmware has been linked to the theft of an estimated $88.6 million in Bitcoin. Attackers drained funds from…
By Dillip Chowdary • Aug 06, 2026 • Source: BleepingComputer
A vulnerability in COLDCARD hardware wallet firmware has been linked to the theft of an estimated $88.6 million in Bitcoin. Attackers drained funds from thousands of wallets whose seed phrases were produced by a flawed random number generator. Reporting from BleepingComputer ties the losses to seed generation on affected COLDCARD devices rather than to exchange hacks or user phishing alone.
Hardware wallets derive private keys from a seed generated at setup. That seed depends on high-quality entropy from the device RNG. When the generator is biased or predictable, the space of possible seeds shrinks and becomes searchable. An attacker who models the flaw can regenerate candidate seeds offline, derive the matching keys, and move Bitcoin without ever touching the physical device.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers building or integrating custody systems, this is a failure in the entropy path, not in key storage after setup. Cold storage still fails if seed creation is weak. Teams that treat hardware wallets as a black-box trust boundary need explicit checks on how entropy is sourced, tested, and audited—especially for devices that generate seeds on-device rather than importing user-supplied entropy.
The scale of the loss, roughly $88.6 million across thousands of wallets, puts pressure on the hardware wallet market, where COLDCARD competes as an air-gapped, security-focused product. Buyers and auditors will compare vendors on RNG design, independent entropy reviews, and whether past firmware generations remain in the field with the same seed-generation path.
Practical next steps: anyone who generated a seed on a COLDCARD under the affected firmware generation should treat that seed as compromised, move funds to a new wallet whose seed was generated on a clean, independently verified entropy source, and watch for official COLDCARD guidance on which firmware builds and generation methods are implicated. Do not reuse old seeds or derive new accounts from them.
Advertisement
🔎 More interesting news
- Building a better MCP server and proving it
- Pods as Workers, Not Agents: Rethinking the Deployment Unit for AI Agents on Kubernetes
- Ship Safe, an open source security scanner for coding agents
- Show HN: Wallfacer – A terminal session manager for Claude Code, and more
- Today's full Tech Pulse briefing →