A five-year-old firmware bug let attackers guess seed phrases and drain 2,000 BTC from COLDCARD walletsCrypto
4 Aug 2026, 8:52 pm (8 hours ago)· 1

A five-year-old firmware bug let attackers guess seed phrases and drain 2,000 BTC from COLDCARD wallets

A March 2021 firmware error left COLDCARD hardware wallets generating weak, guessable seed phrases, and attackers exploited it to drain more than 2,000 BTC from over 7,300 addresses without ever touching the devices.

On Thursday, July 30, COLDCARD, the Bitcoin only hardware wallet built by Coinkite and prized for its air-gapped signing, was compromised in an attack that appears to have siphoned off more than 2,000 BTC and touched over 7,300 separate addresses. COLDCARD has long been a favourite among security-conscious Bitcoiners who want to keep their keys entirely away from the internet, which is exactly why an attack of this kind lands so hard. What makes the incident so unsettling is that the victims did nothing careless: the weakness was baked into the device firmware itself, and attackers were able to reach the funds without ever laying a finger on the physical wallets.

A bug that quietly weakened every seed

Air-gapped wallets like COLDCARD are supposed to be the gold standard of safety because they keep private keys completely offline. The trouble here traces back to a firmware build error from March 2021. Because of that mistake, some devices generated their recovery seed phrases from a far smaller pool of possible values than they were designed to. In plain terms, the randomness that is meant to make a seed impossible to guess was badly reduced, shrinking the number of realistic combinations. That narrow pool turned into an open door, and in an era when AI powered tools can churn through possibilities at scale, guessing a weakened seed becomes far more feasible. Crucially, it meant attackers could rebuild vulnerable seeds without any physical access to the hardware.

Also read

Every ordinary Bitcoin or crypto wallet leans on a recovery seed of 12 to 24 words. That string is effectively the master credential; whoever holds it controls the right to move the coins. So when multiple COLDCARD wallets were emptied of their Bitcoin on the same day, it struck at the core promise of non-custodial cold storage, the very setup people choose precisely to avoid trusting anyone else.

Where the randomness went wrong

The first detailed explanation of the technical root cause came from Block's Bitcoin Engineering and Security team. They pointed to the use of MicroPython's predictable Yasmarang pseudorandom number generator, pulled in through the libNgU library, in place of the device's dedicated hardware random number generator. That single substitution is the heart of the failure.

Instead of drawing on genuine hardware randomness, the software fallback seeded its starting numbers from data the device could already see about itself. That included the chip's Unique ID number, which is literally printed on the component, internal system timers counting how many milliseconds the device had been powered on, and even the order and history of button presses. None of those inputs are truly unpredictable, so the resulting seed was chosen from a small pond of real randomness rather than the vast, cryptographically safe space of 2²⁵⁶ combinations it should have used. That is what let attackers compromise many addresses in one sweep.

Turning the flaw into a heist

The method was almost mechanical. Attackers most likely loaded the flawed 2021 COLDCARD software onto their own computers, used it to generate seeds from the same predictable pool, and then converted those seeds into public Bitcoin addresses. After that, a straightforward automated script compared the freshly generated list of vulnerable addresses against the public Bitcoin blockchain, singling out the ones that actually held BTC. Once the funded addresses were identified, draining them was trivial.

How much was taken

The pace was brutal. The first wave alone pulled 1,082.65 BTC out of 1,196 addresses in just 41 minutes, and more waves followed. Galaxy Research's latest assessment places the stolen amount, with high confidence, at 1,596 BTC spread across roughly 7,300 addresses, tied to three confirmed waves plus 14 additional smaller incidents. On top of that, the firm has flagged a further 448.7 BTC it believes is likely connected to the same COLDCARD vulnerability, which could push the total past 2,000 BTC, though victims have not confirmed those funds. Galaxy has stressed that the attack is still ongoing and that all the figures could shift as the investigation continues.

The scramble to patch

Once the breach became clear, CoinKite pushed out several firmware upgrades, working alongside Rodolfo Novak and a low profile white hat known as Peter D. Gray, who goes by Doc-Hex on GitHub. The first patch corrected the routing so the device uses its hardware random number generator, and it added a build-time test specifically designed to stop the software fallback from ever creeping back in. The company then shipped corrected firmware for its Q1, Mk3, Mk4 and Mk5 devices, followed by a corrected Edge release.

There is an important limit to these fixes. The upgrades guarantee that seed phrases for new wallets are drawn from a genuinely random pool, but they cannot repair a seed that was already weak. On Saturday, Doc-Hex added a repository-wide advisory urging users to replace their secrets immediately, warning that builds from 2021 all the way through July 2026 carried poor entropy. In response, many users moved their Bitcoin into fresh wallets, and a large number switched to multi-signature setups to guard against this class of failure.

What the episode really shows

The takeaway is uncomfortable but useful: offline wallets do their job well in most situations, yet they are not immune to built-in firmware flaws, key-generation mistakes and zero-day vulnerabilities. The sensible response for crypto users is to layer on every extra security feature available, stay alert rather than assuming a device is infallible, and, above all, avoid parking an entire stack of holdings in a single wallet.

Can the thieves actually cash out?

Plenty of people in the community doubt the stolen BTC can be liquidated cleanly. Exchanges and other centralized intermediaries can flag and watch addresses tied to the stolen coins, which would force the attackers toward mixers or other black-market routes to move the money. Some have floated the idea that the hackers strike a plea with CoinKite and hand the BTC back in return for an audit fee of 5% of the haul, though that remains an unverified proposal. Adding to the pressure, several white-hat hackers are racing to reclaim the stolen coins, turning the whole thing into a time-bound challenge for whoever is trying to profit.

Wong summed up the likely outcome, saying, "I expect a slow bleed through mixers and OTC channels rather than a clean cash-out." The point cuts both ways for the attackers: the moment any of these coins pass through centralized intermediaries, there remains a realistic chance they can be recovered or frozen.

Questions & Answers

What caused the COLDCARD hack?
A firmware build error from March 2021 made some wallets generate seed phrases from a much smaller pool of random values, making them possible to guess.
How much Bitcoin was stolen?
Galaxy Research puts the confirmed figure at 1,596 BTC across roughly 7,300 addresses, with another 448.7 BTC likely linked, potentially pushing the total above 2,000 BTC.
How fast did the attack happen?
The first wave alone drained 1,082.65 BTC from 1,196 addresses in just 41 minutes, followed by more waves.
Did attackers need physical access to the wallets?
No. Because the seeds were generated from predictable data, attackers could reconstruct vulnerable seeds without ever touching the devices.
What is the technical root cause?
The device used MicroPython's predictable Yasmarang pseudorandom number generator via the libNgU library instead of its hardware random number generator.
Does the firmware update fix affected wallets?
The upgrades ensure new wallets use true randomness, but they cannot repair an already-weak seed, so affected users must move funds to a new wallet.
Which firmware versions are affected?
Doc-Hex warned that builds from 2021 through July 2026 carried poor entropy and urged users to replace their secrets immediately.
Can the hackers cash out the stolen BTC?
It is difficult, since exchanges can flag the tainted addresses, forcing the use of mixers or OTC channels, and coins entering centralized intermediaries can still be recovered or frozen.

Comments 0

No comments yet — be the first.

Citizen journalism

Become a TrendKia journalist

Voice of the people

Share news, photos and videos from your area with TrendKia and let your voice reach the nation. Every citizen a journalist.

Join now
CH 01 LIVE
TrendKia TV ON AIR