Coldcard Vulnerability Allows 594 BTC Theft via Predictable Seed Generation

iconCrypto Economy
Share
AI summary iconSummary
A Coldcard vulnerability news emerged as attackers stole 594 BTC, valued at $38 million, from about 500 wallets in 25 minutes on July 30, 2026. The flaw exploited predictable seed generation by bypassing hardware randomness. Coinkite released emergency firmware updates, but existing weak seeds remain at risk. The firm suspects AI may have accelerated the attack. A BTC update is now critical for affected users.

TL;DR

  • An attacker drained roughly 594 BTC worth about $38 million from around 500 Coldcard wallets during a coordinated 25-minute sweep early Friday.
  • The flaw bypassed hardware randomness and generated seeds from predictable chip data, shrinking the secret space meant to make private keys effectively unguessable.
  • Coinkite issued emergency firmware updates, but existing weak seeds remain vulnerable and must be replaced; the company suspects AI helped uncover the bug at scale.

A vulnerability in Coldcard hardware wallets allowed an attacker to drain roughly 594 BTC, worth about $38 million, from around 500 single-signature wallets in only 25 minutes. The sweep occurred between 01:31 and 01:56 UTC on Friday, moving funds through 500 transactions inside a three-block window with remarkable speed and precision. A device designed to keep keys offline instead produced seeds that could be narrowed down and guessed. Investigators traced 562 BTC into one address that had not moved, while evidence showed many affected wallets had remained dormant for years before the coordinated theft began.

Predictable device data undermined Coldcard’s randomness

The failure originated in Coldcard firmware introduced during March 2021. A build setting caused devices to bypass their hardware randomness generator, while a supporting-library check tested only whether that setting existed, not whether it was enabled. Key creation then fell back to software seeded with a chip serial number and clock registers, neither of which is secret or genuinely unpredictable to attackers. The supposedly enormous search space protecting each wallet was reduced by predictable device information. Exposure depends on the firmware running when the wallet was created, rather than when the hardware itself was purchased.

An attacker drained roughly 594 BTC worth about $38 million from around 500 Coldcard wallets

Coinkite warned users who generated seeds on Mk3 devices running firmware 4.0.1 or later, while describing its conclusions about newer models as preliminary. The company released emergency updates for Mk4, Mk5 and Q devices, but installing patched firmware cannot strengthen a seed already produced under vulnerable conditions. Owners must create a fresh seed and transfer funds, because software updates cannot rewrite compromised randomness. Recommended safeguards include a strong BIP-39 passphrase, at least 99 dice rolls, or both, while unsupported Mk3 users face a separate and potentially complicated migration process for protecting any remaining balances safely.

The manufacturer believes an attacker may have used artificial intelligence to inspect older versions of its open-source firmware and discover the flaw. That conclusion remains an assumption, not confirmed attribution, and carries an uncomfortable irony: Coinkite said its own AI-assisted review weeks earlier found nothing serious. The incident shows how the same analytical tools can strengthen defenders or accelerate exploitation. Beyond wallet seeds, the flawed generator may also have affected paper-wallet keys, seed-splitting masks, cloning keys and Key Teleport transfers, widening the ongoing security review beyond the 594 BTC already stolen from hundreds of victims.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.