Galaxy: Coldcard RNG Bug Drains ≥1,596 BTC, Losses Could Reach ~$130M

iconChainGPT
Share
AI summary iconSummary
BTC news today reveals a critical flaw in Coldcard hardware wallets caused by a 2021 firmware update, leading to the theft of at least 1,596 BTC across three major attacks and 14 smaller ones. Galaxy Research estimates losses could hit 2,055 BTC (~$130M) if a fourth wave is confirmed. Coinkite identified the issue as a faulty RNG implementation. Affected users are urged to apply the BTC update and transfer funds to secure addresses. Galaxy is working with law enforcement and exchanges to track attacker wallets and limit further damage.

Galaxy Research now says the Coldcard hardware-wallet bug has already cost users at least 1,596 BTC — and that total could swell to about 2,055 BTC (roughly $130 million) if a suspected fourth wave of thefts is confirmed. In a post on X, Galaxy said it has traced 1,596 BTC stolen from roughly 7,300 addresses across three confirmed waves of attacks, plus 14 smaller related incidents. The firm is withholding a suspected fourth wave from its confirmed tally until victim reports validate on-chain signals; if that activity is attributed to the same exploit, the overall loss would reach about 2,055 BTC. How Galaxy arrived at the figures - Galaxy’s on-chain mapping identified the 1,596 BTC across the three confirmed waves. An earlier, broader blockchain-only read had put four-wave movement at about 1,815.75 BTC, but the firm has tightened its confirmed estimate while retaining the larger, still-unverified figure tied to the suspected fourth wave. - Galaxy’s analysts flagged the potential fourth wave on Aug. 3 after spotting transaction patterns similar to earlier attacks. Their running estimate for that suspected wave rose to about 448.7 BTC from 709 possible victim addresses, though they emphasize that blockchain evidence alone can’t confirm every victim or whether a single operator carried out all the thefts. - Blockchain activity suggests the suspected fourth wave is “substantially comprised of” one attacker, giving Galaxy medium–high confidence in that assessment even as they wait for direct confirmations. What the vulnerability is Coinkite — maker of Coldcard devices — disclosed the flaw last week and traced it to a March 2021 change in firmware. While integrating a new cryptographic library, the seed-generation path accidentally fell back to a deterministic pseudo-random generator provided by MicroPython instead of the device’s hardware-backed true random number generator. Because the hardware RNG still appeared in other parts of the firmware, casual internal checks missed the switch in entropy source. Independent review Block’s Bitcoin engineering and security team independently reviewed the firmware and reached the same conclusion: the vulnerable firmware used the deterministic MicroPython fallback for seed creation instead of the STM32 hardware RNG. Coinkite estimates the effective entropy for affected devices is far below the intended level — about 40 bits for some Mk2/Mk3 units and roughly 72 bits for vulnerable Mk4/Mk5 and Coldcard Q models, versus the intended 128 bits. Attack behavior and investigation status - Galaxy reports that most stolen balances were distributed to many newly created addresses rather than consolidated into a single collector wallet; some funds were later routed through second-hop transactions that make tracing harder. During the suspected fourth wave, Galaxy observed attack activity spike to about 13.8 wallet sweeps per Bitcoin block compared with about 0.3 sweeps per block beforehand. - Approximately 90% of the stolen BTC remains untouched on-chain, and none of the coins taken in the first three confirmed waves have moved since they were stolen — a window that gives investigators time to monitor and respond. - Galaxy is working with U.S. federal law enforcement, crypto exchanges and cyber-investigation groups and is sharing confirmed attacker and victim addresses as the probe expands. The firm warned that other attackers could try to exploit the same vulnerability while affected wallets remain in use, so identifying attacker-controlled addresses is critical so exchanges and authorities can act if funds start moving. Advice for affected users Galaxy and Coinkite advise Coldcard users to move funds from any wallets created with vulnerable firmware to new, secure addresses and to generate entirely new seed phrases only after applying patched firmware. Coinkite has released emergency firmware updates for all affected models (examples include v4.2.0 for Mk2/Mk3, v5.6.0 for Mk4/Mk5, and v1.5.0Q for Coldcard Q) and says it has destroyed remaining inventory containing the vulnerable firmware. Important caveats from Coinkite - Installing the update protects only wallets created after the firmware fix; existing seeds generated under vulnerable firmware remain exposed and must be replaced. - Coinkite recommends generating a completely new seed on a patched device, verifying a receiving address, sending a small test transaction, and only transferring the full balance after the test succeeds. - Wallets created using at least 50 fair private dice rolls are not vulnerable to this RNG issue alone, and a strong BIP-39 passphrase provides additional security — but Coinkite still recommends migration because the original seed material remains weak. Other recovery notes Galaxy previously pointed out that users who see an unconfirmed theft transaction might have a narrow opportunity to replace it using Bitcoin’s Replace-by-Fee (RBF) mechanism, but that option only applies before the original tx is mined and does not guarantee recovery. Bottom line This incident is a stark reminder that firmware-level mistakes can undermine hardware-wallet security. If you own a Coldcard device, verify your firmware, assume any seeds created on vulnerable versions are compromised, and migrate funds only after applying Coinkite’s fixes and following their migration checklist. Galaxy’s ongoing mapping and law-enforcement collaboration aim to track attacker addresses and limit further losses as the investigation continues.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.