Overview
- A firmware change introduced March 17, 2021 routed Coldcard seed generation to a weak software pseudorandom generator instead of the hardware true random number generator, sharply reducing entropy and allowing private keys to be reconstructed.
- Forensics teams led by Galaxy Research have published a dataset linking roughly 8,680 addresses to the exploit and estimate about 1,778 BTC (roughly $112–$115 million) tied to those addresses, with 192 victims confirming losses totaling about 714.8 BTC.
- Coinkite issued an emergency security bulletin and patched firmware on July 30–31, 2026, but the company and researchers warn that installing the patch does not secure seeds already created on affected builds.
- Investigators say attackers operated in coordinated waves with distinct transaction ‘fingerprints,’ most stolen coins remain in attacker-controlled addresses, and analysts report patterns consistent with use of open-source AI tools to find and weaponize the flaw.
- The breach has prompted mass user migrations to new seeds, renewed interest in multisignature custody (which was not affected), and fresh scrutiny of Coldcard’s build practices, licensing and community treatment of independent researchers that may have reduced code review.