Coldcard Wallet Flaw Linked to $88.6 Million Bitcoin Theft
Coldcard manufacturer Coinkite said the exposure stems from weak entropy in seeds generated by affected firmware. Its advisory, published July 30 and updated August 1, says Mk2 and Mk3 firmware from version 4.0.1 through 4.1.9 is affected, along with seeds created on Mk4, Mk5 and Q devices before specified fixed releases. The issue dates to a firmware change introduced in March 2021.
Block Engineering traced the failure to an integration error that sent seed generation to MicroPython's deterministic Yasmarang pseudorandom number generator instead of the STM32 hardware random number generator. Block said Mk2 and Mk3 generation becomes deterministic when the device identifier, timer state and prior call history are known or sufficiently constrained. Later devices add secure-element input, but only four bytes reach the reseed function, limiting the securely distinguished output streams.
An attacker able to reproduce candidate output streams can derive wallet addresses offline and compare them with public blockchain records. A matching candidate can expose the seed or private key needed to move funds. Block stressed that it had not completed full empirical exploitability testing, while Galaxy warned that similar-looking sweeps do not by themselves prove theft or establish that one operator controlled all three waves. No attacker has been publicly identified.
Coinkite has released fixed firmware for every affected model and release track. The company warns that updating alone does not repair an existing seed; affected owners should generate a new seed on fixed firmware, verify a receiving address, send a small test transaction and then move the remaining funds. Restoring an old seed on updated hardware or another wallet preserves the weakness. Seeds created with at least 50 fair, independent and private dice rolls are not considered exposed by this flaw alone.
Users should verify the exact firmware that generated their seed, because exposure depends on that version rather than the software installed today. Coinkite also advises owners protected by a strong, unique BIP-39 passphrase to migrate, while noting that the passphrase adds an independent barrier. Galaxy said it reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms and cybersecurity investigators.