COLDCARD: an RNG flaw in the firmware allowed the theft of $88.6 million in Bitcoin

Cybersecurity Aug 25, 2026Add to bookmarks

COLDCARD: an RNG flaw in the firmware allowed the theft of $88.6 million in Bitcoin
Illustration : Momiji Shirogane

A vulnerability in the random number generator of the COLDCARD firmware allowed attackers to reconstruct the private seeds of thousands of wallets and drain their funds.

What happened

BleepingComputer reports that a vulnerability in the random number generator (RNG) of the COLDCARD (Coinkite) hardware wallet firmware likely allowed the theft of $88.6 million in Bitcoin from thousands of wallets whose seeds were generated with this faulty firmware.

The fundamental issue: the security of a hardware wallet relies entirely on the entropy of the initial seed. If the RNG generating this seed is predictable or biased, an attacker with sufficient computing power can brute-force the seeds and reconstruct the private keys—without ever touching the hardware itself.

What we know

  • Affected firmware: Earlier versions of COLDCARD firmware with a bias in their RNG
  • Attack vector: No physical access, no phishing—pure exploitation of the RNG bias to remotely recalculate seeds
  • Estimated amount: $88.6 million in Bitcoin (BleepingComputer, 2026-08-02)
  • Victims: Thousands of wallets whose seeds were generated during the vulnerability period

Analysis

The RNG is the Achilles' heel of any cryptographic system. This is why standards like NIST SP 800-90A exist, and serious hardware wallets have their entropy generators audited independently. A bug in this layer is catastrophic because it is undetectable without an audit of the source firmware—the user has no way of knowing their seed is weak.

This type of attack is particularly insidious: funds can be stolen months or years after the wallet is generated, when the attacker decides to act.

Estimated stolen amount

$88.6 million in Bitcoin from thousands of COLDCARD wallets whose seeds were generated with firmware containing an RNG bias—according to BleepingComputer (2026-08-02).

What to do now

• Check your COLDCARD firmware version on Coinkite’s official website and apply the update\n• If your wallet was created with a potentially affected version: move your funds to a new wallet with a seed generated on patched firmware\n• In general: never use a hardware wallet whose firmware has not undergone a public audit

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

6 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information