Bearish

Coldcard seed flaw leads to $130M Bitcoin losses across 7,700 addresses

min

Analysts estimate that losses from the Coldcard seed-generation flaw have reached about 2,055 BTC worth $130 million across more than 7,700 victim addresses. The issue stems from weak randomness in certain Coinkite Coldcard firmware versions, enabling attackers to derive seeds offline and sweep funds.

Coldcard firmware flaw: deterministic PRNG and weak entropy

March 2021 builds misrouted seed generation to a deterministic software PRNG instead of the STM32 hardware RNG. The production config defined the hardware-RNG macro as zero, while the libngu check only verified macro existence, binding the build to MicroPython’s Yasmarang fallback. This fallback initialized from chip unique IDs and timer registers and did not add fresh entropy after startup. An attacker who could determine or constrain device UID, timer state and prior RNG-call history could reproduce candidate outputs offline and match derived addresses against the blockchain.

Coinkite estimated effective entropy: roughly 40 bits on Mk3 and about 72 bits on Mk4, Mk5 and Q, compared to 128 bits for a 12‑word BIP‑39 seed. Practical cracking cost depends on available UID info, boot timing, prior RNG calls and derivation cost. Coinkite released emergency firmware on July 31. Updating firmware does not fix a weak seed. Users must generate a new seed on patched firmware and move funds, since restoring the old seed preserves the weakness.

On-chain sweep waves and attacker patterns

Initial sweep on July 30: 1,082.65 BTC drained from 1,196 addresses in 41 minutes, close to one BTC per address. A later, third suspected wave: roughly 208 BTC from 1,912 addresses, averaging just over 0.1 BTC per victim. Later transactions batched about six victims per sweep, sent each victim’s coins to a separate destination and used P2WSH outputs instead of earlier single-key outputs. Galaxy Research assessed each wave as executed by one operator, but on-chain data cannot confirm whether all waves share the same attacker.

Galaxy said it has not computationally confirmed that every affected address used weak Coldcard entropy. It reported about 600 suspected attacker-controlled addresses to federal investigators, compliance firms and cybersecurity investigators.

Implications: hardware wallet seed-generation paths require continuous auditing and correct entropy sourcing. Users with potentially affected seeds must regenerate on patched firmware and migrate funds. The scale of losses and ongoing sweeps create downside pressure on market sentiment.