criticalOther

Coldcard Hardware Wallet Weak PRNG Seed Generation Flaw

First seen Aug 2, 2026 · Updated Aug 2, 2026

cryptocurrencyhardware-walletweak-rngfirmware-vulnerabilitybitcoin-theftsupply-chain

A March 2021 firmware integration error in Coinkite's Coldcard hardware wallet caused seed generation to rely on a deterministic software pseudorandom number generator (PRNG) instead of proper entropy sources, producing predictable private keys. Attackers exploited this weakness to systematically drain 1,196 Bitcoin addresses, stealing 1,082.65 BTC (~$70.2 million) in just 41 minutes on July 30. Galaxy Research identified the pattern and linked the mass sweep directly to the firmware defect, exposing years of latent risk for affected wallet holders.

Technical Analysis

The root cause is a firmware integration flaw introduced in March 2021 that substituted a deterministic software-based PRNG for a cryptographically secure random number generator during Coldcard seed phrase generation, drastically reducing the entropy space of generated private keys. This allowed an attacker to brute-force or precompute the reduced keyspace and derive valid private keys for affected wallets, enabling automated, rapid draining of 1,196 addresses in under an hour. The attack vector is a supply-chain/firmware-level weakness rather than a network exploit, meaning any wallet whose seed was generated under the vulnerable firmware version remains compromised regardless of subsequent patching unless funds are moved to a newly and securely generated wallet. This has no direct impact on AI agent systems, as it is isolated to hardware wallet firmware and cryptocurrency key generation rather than software supply chains, credentials, or infrastructure used by LLM/agent frameworks.

Affected Systems

Coinkite Coldcard hardware wallets running firmware versions affected by the March 2021 integration error; Bitcoin wallet addresses whose seed phrases were generated using the flawed firmware prior to remediation

Indicators of Compromise

  • N/A - no file hashes, IPs, or domains reported; indicator is the observed sweep of 1,196 Bitcoin addresses (1,082.65 BTC transferred) on July 30

Remediation Steps

  1. 1

    Regenerate wallet seeds

    Immediately migrate funds from any Coldcard wallet whose seed was generated during the vulnerable firmware period to a new wallet created with patched firmware and verified secure entropy generation.

  2. 2

    Update firmware

    Ensure all Coldcard devices are updated to the latest firmware version that resolves the PRNG integration flaw.

  3. 3

    Audit historical seed generation

    Review the date range during which the vulnerable firmware was active and treat any wallets created in that window as compromised.

  4. 4

    Monitor affected addresses

    Use blockchain analytics (e.g., Galaxy Research findings) to identify and flag potentially exposed addresses for proactive fund migration.

  5. 5

    Independent entropy verification

    For high-value cold storage, verify seed generation using an independent, audited entropy source rather than relying solely on device-generated randomness.

Industries Most Exposed

cryptocurrencyfinancial servicesfintech

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.