Coldcard Seed Flaw Exposes $90M in Bitcoin

iconNS3
Share
AI summary iconSummary
Bitcoin breaking news: Coldcard Seed Flaw Exposes $90M in Bitcoin. NS3 reports that Coldcard used MicroPython’s Yasmarang PRNG instead of hardware entropy, affecting 4,585 addresses. The flaw, present since March 2021, lowered entropy to about 40 bits. Galaxy Research says the breach occurred after 500 addresses were drained. Coinkite suspects AI helped find the bug in public firmware. Bitcoin news outlets are closely tracking the incident.

Key Point

Coldcard generated some seeds through MicroPython’s Yasmarang software PRNG instead of the hardware entropy source. On some models, the effective entropy collapsed to around 40 bits. The flaw shipped in March 2021 and stayed in publicly readable firmware for more than five years. Galaxy Research’s tally reached 4,585 addresses and nearly $90 million after attackers swept 500 addresses. Coinkite’s working assumption is that someone used AI to comb the publicly available firmware for the bug.

Why it matters: Weak seed generation can turn self-custody into a direct loss channel because private-key knowledge may transfer Bitcoin control immediately.

Market Sentiment

Bearish, Stress-on, Tech-driven, Fear.

Reason: Attackers swept 4,585 addresses and nearly $90 million through a Coldcard seed-generation flaw, which points to direct custody risk.

Similar Past Cases

In 2023, the Milk Sad vulnerability in Libbitcoin Explorer exposed wallets generated by the bx seed command because vulnerable versions used a weak Mersenne Twister PRNG for cryptographic key material. Attackers used the flaw to steal large amounts of funds on 12 July 2023, and Libbitcoin Explorer 3.8.0 later removed the problematic entropy generation command. (Milk Sad) The key difference is that Milk Sad centered on a command-line wallet tool, while the current event centers on a hardware signer.

Ripple Effect

Weak entropy can spread risk through any wallet workflow that depends on one device as the only source of seed safety. If users and vendors cannot clearly separate affected seeds from safe seeds, then custody trust could shift toward independently verifiable key generation. If more swept addresses appear, then the incident could reinforce demand for reproducible builds and smaller trusted cores.

Opportunities & Risks

Opportunities: If Coinkite or researchers publish clear affected-device and firmware guidance, then migrating funds to independently generated seeds can reduce exposure for affected users.

Risks: If additional addresses are swept or the affected keyspace remains searchable, then reducing reliance on single-device seed generation limits repeat compromise risk.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.