[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGj1dx1T9ZEw9O6iF0D4KXRflc9RB1_a6eTUD0ae4ASk":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"ca8e7f2c-1fcb-405b-8c08-b97bccbeb503","COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft","coldcard-seed-generation-flaw-linked-to-nearly-89-million-bitcoin-theft-b0cdd0","Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.","A firmware error in COLDCARD hardware wallets (Mk2, Mk3, Mk4, Mk5, Q models) weakened seed generation by routing to a deterministic software fallback instead of the hardware RNG, resulting in seeds with only 40–72 bits of entropy instead of 128. Galaxy Research linked three suspected Bitcoin thefts totaling 1,367.05 BTC (~$88.6M) across 4,585 addresses to exploitation of this flaw. Coinkite's firmware updates cannot repair seeds already generated; affected users must create entirely new seeds and migrate their funds.","COLDCARD firmware flaw in seed generation linked to $88.6M Bitcoin theft across 1,367 BTC.","Security CryptoCOLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices. byWaqasAugust 3, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening A firmware error that weakened wallet seed generation in several COLDCARD hardware wallets has been linked to three suspected Bitcoin thefts involving 1,367.05 BTC. Galaxy Research, the research division of digital assets company Galaxy, valued the observed losses at about $88.6 million. The initial theft occurred on July 30, when 1,082.65 BTC was removed from 1,196 addresses within 41 minutes. According to Galaxy Research’s blockchain analysis on X, the transactions shared identical fees and lacked change outputs, indicating that one operator may have conducted the sweep. Two later suspected attacks brought the observed total to 4,585 drained addresses. The third involved 207.7294 BTC taken from 1,912 addresses, with the attacker using separate destination addresses and different transaction formats that made the activity harder to group. Galaxy has cautioned that its findings come from Bitcoin blockchain data and the unspent transaction output set. The company has not confirmed that every affected address was generated by vulnerable COLDCARD firmware, or that the same attacker conducted all three attacks. It is also worth noting that no public investigation has reproduced a victim’s seed and matched it to one of the drained addresses. The reported connection between the firmware flaw and the thefts is supported by blockchain patterns and technical analysis, but it has not been conclusively proven. 🚨 A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained.Our estimated observed size of the Coldcard hack is now 1,367.05 BTC (~$88.6m) across 4,585 addresses. More updates in the thread below 👇 https:\u002F\u002Ft.co\u002FhPtXh9444D pic.twitter.com\u002Fg6xA4OOi2f— Galaxy Research (@glxyresearch) August 1, 2026 For a hardware wallet, the seed is the secret value from which its recovery phrase, private keys and Bitcoin addresses are derived. If that value is created with weak randomness, an attacker may be able to generate candidate seeds offline and compare their addresses with records on the public blockchain. Block’s Bitcoin Engineering and Security analysis traced the error to firmware changes introduced in 2021. Seed generation was meant to use COLDCARD’s hardware random number generator, but an integration mistake directed it to a deterministic software fallback included with MicroPython. The faulty check only tested whether a configuration setting existed, not whether it was enabled. Because the setting was defined with a value of zero, the build passed its check while using the software generator, which depended heavily on device identifiers and timing information. Under Coinkite’s current estimates, affected Mk2 and Mk3 seeds may have about 40 bits of effective entropy. Additional randomness included on the Mk4, Mk5, and Q increased their estimate to about 72 bits, still below the intended 128-bit security level. According to Coinkite’s security advisory, affected seeds include those generated on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9. Mk4 and Mk5 seeds created before standard firmware 5.6.0 or Edge 6.6.0X are also covered, along with Q seeds created before standard 1.5.0Q or Edge 6.6.0QX. Installing fixed firmware prevents the same error during future seed generation, but it does not repair an existing seed. Restoring the old recovery phrase on updated firmware or importing it into another wallet carries the same weakness with it. Coinkite advises affected owners to install the correct fixed version, generate a new seed, verify its backup and receiving address, send a small test payment, and then transfer the remaining balance. Coinkite says users who supplied at least 50 fair, private dice rolls during seed creation are not exposed to this flaw alone. A strong and unique BIP-39 passphrase adds another barrier, but Coinkite still recommends migration. The company’s technical explanation remains preliminary while its investigation continues. TAPSIGNER, OPENDIME, and SATSCARD are not affected because they use different code. (Photo by Mariia Shalabaieva on Unsplash) Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts BitcoinBlockchainCOLDCARDCyber AttackCybersecuritydata breachVulnerability Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Malware New Voldemort Malware Uses Google Sheets to Target Key Sectors Globally The Voldemort Malware campaign is spreading globally with over 20,000 phishing emails sent to more than 70 organizations,… byWaqas Read More Hacking News Security Killnet Claim They’ve Stolen Employee Data from Lockheed Martin The pro-Russia Killnet hacker group claims that the stolen information includes PII data such as email addresses and… byWaqas Read More Security Artificial Intelligence OpenAI’s Guardrails Can Be Bypassed by Simple Prompt Injection Attack Just weeks after its release, OpenAI’s Guardrails system was quickly bypassed by researchers. Read how simple prompt injection attacks fooled the system’s AI judges and exposed an ongoing security concern for OpenAI. byDeeba Ahmed Read More Security New Attacks Exploit Year-Old ServiceNow Flaws – Israel Hit Hardest Article updated with a statement from ServiceNow. byDeeba Ahmed","https:\u002F\u002Fhackread.com\u002Fcoldcard-seed-generation-flaw-bitcoin-theft\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002Fcoldcard-seed-generation-flaw-bitcoin-theft.jpg","2026-08-03T17:52:36+00:00","2026-08-03T18:00:08.578341+00:00",9,[18,21,23,25,27,29],{"name":19,"type":20},"COLDCARD Mk2","product",{"name":22,"type":20},"COLDCARD Mk3",{"name":24,"type":20},"COLDCARD Mk4",{"name":26,"type":20},"COLDCARD Mk5",{"name":28,"type":20},"COLDCARD Q",{"name":30,"type":31},"Coinkite","vendor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"0493c7e9-989a-4692-b4e6-136f5ec09675","Cryptography","cryptography",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[49],{"type":50,"value":51,"context":52},"malware","COLDCARD seed generation flaw (CVE pending)","Firmware vulnerability in COLDCARD hardware wallets affecting seed entropy generation"]