Coldcard Firmware Bug Traced to $88.6M in Bitcoin Thefts Across 4,500+ Addresses

❓What:
A firmware integration error from March 2021 in Coinkite's Coldcard hardware wallet caused seed generation to route through a deterministic software PRNG instead of the device's STM32 hardware RNG, on five affected models/tracks.
Block traced the root cause to a production config flag (MICROPY_HW_ENABLE_RNG) that checked whether a macro existed rather than whether it was enabled, silently binding builds to MicroPython's weak Yasmarang fallback, seeded only from chip UID and timer state at init with no further entropy collected.
Galaxy Research mapped an initial sweep of 1,196 addresses in 41 minutes on July 30, draining 1,082.65 BTC (~$70.2M at the time); two additional suspected waves have since raised the total to 1,367.05 BTC (~$88.6M) across 4,585 addresses.
Coinkite shipped emergency firmware on July 31 for all affected models, but patching does not repair seeds already generated on vulnerable firmware.
Estimated effective entropy is roughly 40 bits on the Mk3 and ~72 bits on Mk4/Mk5/Q, versus 128 bits expected for a standard 12-word BIP-39 seed.
⚠️Impact:
Any wallet whose seed was generated on vulnerable firmware remains at risk even after updating — the weakness lives in the seed itself, not the installed firmware version.
Restoring an old vulnerable seed to patched firmware, or to a different wallet, carries the exposure forward.
Multisig setups only mitigate risk if the signing quorum isn't composed entirely of affected devices.
No public report has yet reconstructed a victim's seed and matched it to a specific drained address, and the attacker(s) remain unidentified — Galaxy notes wave 3 shouldn't be assumed to share an operator with waves 1–2.
This follows a separate weak-PRNG disclosure (Coinspect's "Ill Bloom" research, early July) tied to $5M+ drained across multiple chains, suggesting seed-entropy failures are a live pattern this year, not an isolated incident.
💡Recommendations:
Update all Coldcard devices to the emergency firmware immediately (Mk3: 4.2.0+; Mk4/Mk5: 5.6.0+; Q: 1.5.0Q+).
Treat any seed generated before the patch as compromised unless it was created from 50+ fair, independent, private dice rolls — Coinkite's stated exception.
Generate a new seed on patched firmware and migrate funds; do not restore old seeds.
A strong, unique BIP-39 passphrase creates a practically separate wallet the seed words alone can't reach — but Coinkite still recommends full seed replacement rather than relying on this alone.
For multisig users, confirm the quorum includes devices/codebases outside the affected path (TAPSIGNER, OPENDIME, and SATSCARD use different codebases and are unaffected).
Read the full story HERE
