Particle.news

Coldcard RNG Bug Tied to More Than $100 Million in Bitcoin Thefts; Patch Does Not Fix Compromised Seeds

A firmware error made some recovery phrases weak and now owners must create new seeds with independent randomness before moving funds.

Overview

  • Coinkite disclosed the vulnerability at the end of July and released patched firmware on July 31, 2026, while warning that updating devices does not repair seeds already created with the flawed code.
  • The root cause was a March 17, 2021 firmware change that caused certain Coldcard builds to fall back to a predictable software pseudorandom number generator instead of using the device’s hardware entropy.
  • Researchers say the weakened randomness cut effective seed entropy to attackable levels on affected models, with some analyses citing search spaces as small as roughly 40 bits on older devices and about 72 bits on later ones.
  • On-chain forensics led by Galaxy Research has tied multiple coordinated theft waves to the flaw and confirmed roughly 1,596–1,719 BTC stolen so far, reports place losses commonly between $100M and $111M with higher totals still under investigation.
  • Coinkite is preparing a technical post-mortem and assisting customers while the community urges immediate migration to newly generated seeds using patched firmware, independent entropy (for example dice), or strong BIP‑39 passphrases and calls for stricter firmware audits going forward.