Coldcard Wallets Affected by RNG Flaw, 594.48 BTC Stolen

iconBeInCrypto
Share
AI summary iconSummary
BTC news today reveals that Coldcard hardware wallets were hit by an RNG flaw, resulting in the theft of 594.48 BTC, worth around $38.3 million. A broken RNG check allowed attackers to guess private keys using serial numbers and internal clocks. Coinkite and Block confirmed the flaw impacts Coldcard models from 2021 onward. Coldcard advises users to generate new seeds on updated devices. Mk3 units with firmware older than 4.0.1 are at risk, while Mk4, Q, and Mk5 are safe. The flaw is similar to the Ill Bloom exploit and highlights risks in weak key generation. This BTC update is urgent for Coldcard users.

A firmware error has disabled secure random number generation across multiple Coldcard hardware wallet generations, fueling an ongoing theft that has already drained 594.48 Bitcoin (BTC), worth about $38.3 million.

Coldcard maker Coinkite and Block’s Bitcoin engineering team traced the bug to a broken random number generator (RNG) check. As a result, attackers can rebuild a wallet’s private keys using predictable device details instead of true randomness.

Coldcard Bitcoin Theft: How It Happened

Coldcard’s firmware turns off the chip’s built-in randomness generator. Instead, a backup system builds wallet keys from the device’s serial number and its internal clock. Both follow patterns an attacker can guess, turning a supposedly random seed into a solvable puzzle.

Sponsored
Sponsored

Devices running certain firmware released since 2021 get almost no real randomness at all. Newer models add a partial fix. It still narrows the possible outcomes to roughly four billion combinations, a number modern computers can work through. Historically, Block traced the flaw to that 2021 update, and a follow-up fix a year later still fell short.

Therefore, the same weakness touches paper wallets, seed backups, and other features that share the same random source. Block’s report confirmed the wider reach. The setup resembles the Ill Bloom exploit, which drained wallets through weak seed phrases earlier this year.

What Users Should Do Now

Attackers do not need physical access to steal funds. A visible address or exported public key gives them a target to test guesses against. Once a guess matches, the attacker holds the private key and can move the coins immediately.

Coinkite recommends that every affected user generate a brand new seed on updated hardware and move funds right away. Firmware updates cannot undo the damage, because the weak seed still exists on the device.

Meanwhile, users who added an extra passphrase to their seed face substantially lower risk from this flaw. It is an approach ZachXBT recently endorsed for mobile wallets, too.

Weak key generation has drained crypto holders before. Similarly, a master key exposure hit South Korea’s tax agency earlier this year. A private key breach crashed Humanity Protocol’s token 88% in June.

Vendors keep expanding offline hardware wallets into retail stores. Yet this incident shows firmware bugs can undercut that promise from inside the device.

Coinkite and Block say they are still assessing how far the flaw’s reach extends across older firmware. Until that review closes, Coldcard owners should assume any seed generated before today’s fix might already be compromised.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.