0x115491061154…11549103

ConfirmedSecurity565 vB172 sat/vB3 min decode

Coldcard Seed Bug Tied to $88.6M Bitcoin Theft From 4,585 Addresses

Onchain Lens links a non-cryptographic random number flaw in Coldcard hardware wallets to 1,367.05 BTC stolen from 4,585 addresses, a loss now valued at roughly $88.6 million.

Outputs

  1. Onchain Lens ties a 2021-introduced PRNG flaw in Coldcard wallets to 1,367.05 BTC (~$88.6M) stolen from 4,585 affected addresses

  2. Waves 1 and 2 account for 1,158.81 BTC across 2,673 suspected victims; Wave 3 drains 207.73 BTC from 293 monitored P2WSH addresses

  3. Coldcard Mk2 and Mk3 face the highest known risk; Mk4, Mk5, and Coldcard Q may also have produced weak seeds under affected firmware

  4. Firmware updates cannot retrofit existing seeds; affected users must generate a new seed phrase and migrate funds

  5. One Canadian investor reportedly lost about $1.6 million within minutes during the attack

Blockchain tracker Onchain Lens has linked a non-cryptographic pseudo-random number generator (PRNG) flaw in Coldcard hardware wallets to the theft of 1,367.05 BTC, worth roughly $88.6 million, across 4,585 reported addresses. The consolidated total spans three exploitation waves that targeted seed phrases generated under vulnerable firmware first introduced in 2021.

What the on-chain record shows

Onchain Lens published the consolidated tally in a recent post. The tracker wrote: "The Coldcard RNG exploit has now been linked to 1,367.05 BTC (~$88.60M) across 4,585 reported affected addresses."

The breakdown splits the activity into two tranches:

  • Waves 1 and 2: 1,158.81 BTC taken from 2,673 suspected victims.
  • Wave 3: 207.73 BTC drained from 293 monitored P2WSH addresses.

One investor in Canada reportedly lost about $1.6 million within minutes of the attack touching their wallet.

How the vulnerability works

Every Coldcard device generates a seed phrase during first boot. That phrase is the master key that controls every address the wallet will ever derive.

A secure seed requires cryptographically strong entropy, typically drawn from a hardware random number generator inside the device's secure element. The wallet should have used that secure source.

A software bug introduced in 2021 caused some units to fall back to a non-cryptographic pseudo-random number generator instead. Researchers say the weaker entropy narrowed the set of plausible seed phrases to a range a determined attacker could feasibly search.

Once an adversary reconstructs the correct seed, no further authentication is required. The attacker can derive the wallet's keys remotely and sign transactions from any internet-connected machine.

Which devices remain exposed

Researchers believe the Coldcard Mk2 and Mk3 models face the highest known risk. The Mk4, Mk5, and Coldcard Q may also have shipped or operated firmware that produced weak seeds, though investigators are still measuring how much entropy those units retained under affected boot conditions.

The full scope of affected firmware versions and serial ranges remains under investigation.

Why firmware updates will not resolve the problem

Installing the latest firmware does not retroactively strengthen an existing seed. Any wallet that first booted under vulnerable firmware must reset its seed from scratch, Onchain Lens and tracking researchers have said.

Affected users should generate a new seed phrase, move all funds to the new wallet, and stop using the compromised seed. An air-gapped device offers no protection once a seed becomes predictable, since remote key derivation removes the need for physical access.

What open source did and did not catch

Coldcard's firmware is open source, and the vulnerable PRNG code remained public for years before the flaw drew sustained outside scrutiny. The case underscores that public repository access alone cannot replace routine independent audits, fuzz testing, and entropy analysis of cryptographic routines.

What holders should do

  • Confirm the latest firmware is installed on the device.
  • Generate a new seed phrase from scratch.
  • Migrate funds to the new wallet in a single transaction.
  • Retire any seed first created under vulnerable firmware, and discard its backup.

What comes next

The $88.6 million figure reflects what Onchain Lens has tied to the PRNG flaw so far. Wave 3 activity traced to 293 P2WSH addresses indicates additional attribution work is in progress, and the consolidated total is likely to rise as more historical addresses match the entropy pattern.

via x.com (Original)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles