Cybersecurity Aug 25, 2026Add to bookmarks

A vulnerability in the random number generator of the COLDCARD firmware allowed attackers to reconstruct the private seeds of thousands of wallets and drain their funds.
BleepingComputer reports that a vulnerability in the random number generator (RNG) of the COLDCARD (Coinkite) hardware wallet firmware likely allowed the theft of $88.6 million in Bitcoin from thousands of wallets whose seeds were generated with this faulty firmware.
The fundamental issue: the security of a hardware wallet relies entirely on the entropy of the initial seed. If the RNG generating this seed is predictable or biased, an attacker with sufficient computing power can brute-force the seeds and reconstruct the private keys—without ever touching the hardware itself.
The RNG is the Achilles' heel of any cryptographic system. This is why standards like NIST SP 800-90A exist, and serious hardware wallets have their entropy generators audited independently. A bug in this layer is catastrophic because it is undetectable without an audit of the source firmware—the user has no way of knowing their seed is weak.
This type of attack is particularly insidious: funds can be stolen months or years after the wallet is generated, when the attacker decides to act.
$88.6 million in Bitcoin from thousands of COLDCARD wallets whose seeds were generated with firmware containing an RNG bias—according to BleepingComputer (2026-08-02).
• Check your COLDCARD firmware version on Coinkite’s official website and apply the update\n• If your wallet was created with a potentially affected version: move your funds to a new wallet with a seed generated on patched firmware\n• In general: never use a hardware wallet whose firmware has not undergone a public audit
Article produced by artificial intelligence, reviewed under human editorial control.