Decades of Trust Shaken as Coldcard Bug Exposes $86M Bitcoin Loss Timeline
A silent firmware configuration flaw in Coldcard wallets weakened seed generation security for nearly five years, resulting in the theft of 1,367 BTC spread across 4,585 addresses.
According to on-chain research published by Galaxy Research on Aug. 2, 2026, a pseudo-random number generator (PRNG) vulnerability embedded in Coldcard hardware wallet firmware since March 2021 led to confirmed losses of approximately 1,367 BTC, worth about $86 million.
The incident is now considered the largest confirmed hardware wallet exploit in Bitcoin history by total funds lost. The attackers did not rely on phishing, physical access to devices, or mistakes by wallet owners. Instead, they exploited a weakness in the underlying wallet-generation process.
The breach highlights a fundamental risk in self-custody systems: wallet security is only as strong as the randomness used to create recovery seeds. A single software misconfiguration can weaken that protection for years without generating any obvious warning signs.
The exploit emerged as Bitcoin traded at around $62,250, down 1.4% on the day after a volatile week that saw the asset decline from above $65,000. Bitcoin’s 24-hour trading volume stood near $16.9 billion, falling from more than $20 billion the previous day.
How the Coldcard Bug Compromised Seed Generation
Block’s engineering team traced the issue to Coldcard’s libngu library. Coinkite had configured a board setting to zero to disable MicroPython’s random number generator and force the wallet to use its hardware true random number generator (TRNG).
However, the validation logic in the libngu library only checked whether the macro was defined, rather than confirming whether the value was correct. This allowed the zero setting to pass unnoticed.
Because of this error, MicroPython removed the STM32 hardware RNG function during compilation and instead used Yasmarang, a software-based PRNG that generated only about 40 bits of effective entropy. That was significantly below the 128 bits of randomness expected for a BIP-39 seed phrase.
Later Coldcard models, including Mk4, Mk5, and Q, improved entropy estimates to around 72 bits, but they still did not reach the recommended level. The difference between 40-bit and 128-bit entropy created a major security gap that made vulnerable wallets easier to compromise.
Coinkite released a security alert on July 30, 2026, shortly before attackers carried out the first major wave, draining about 594 BTC from roughly 500 addresses. Additional attack waves followed, increasing the total confirmed losses to 1,367.05 BTC across 4,585 addresses by Aug. 2.
Most of the stolen Bitcoin has remained inactive, suggesting the attacker has not yet moved or sold the funds.
Weak Randomness: A Repeated Crypto Security Problem
The Coldcard incident follows a long list of cryptocurrency breaches caused by failures in random number generation.
In 2013, an Android SecureRandom vulnerability caused repeated ECDSA nonces, exposing private keys connected to multiple Bitcoin wallets. In 2022, the Profanity vanity address generator flaw played a role in the Wintermute hack, where attackers exploited weak 32-bit entropy and stole around $160 million.
In 2023, the Milk Sad vulnerability revealed that Libbitcoin Explorer’s bx seed tool used a Mersenne Twister generator seeded by system time. The issue reduced the expected 256-bit entropy to roughly 32 bits and exposed more than 120,000 wallets.
Although these attacks affected different systems, they shared a common failure: relying on a randomness source that appeared secure but was not strong enough.
Ari Redbord, global head of policy at TRM Labs, said the incident demonstrates that self-custody does not eliminate security risks but instead changes where those risks exist. TRM Labs’ first-half 2026 data showed that infrastructure and key compromises represented 15% of security incidents but accounted for 76% of total financial losses across 207 recorded hacks.
Galaxy Research said it has identified around 600 addresses believed to be controlled by the attacker and has shared the information with federal investigators, compliance firms, and cybersecurity organizations.
The research firm added that its Coldcard attribution is based on blockchain analysis and transaction patterns rather than direct seed reconstruction for each affected wallet.
Share this content:













