Back to all lessons
Awareness Lessons
2 months ago

COLDCARD Firmware Flaw Drains $89M in Bitcoin Due to Weak Seed Entropy

A firmware bug in COLDCARD hardware wallets caused seed generation to fall back to a deterministic software routine instead of the hardware random number generator (RNG), reducing cryptographic entropy from a secure 128 bits down to just 40–72 bits. This weakness made wallet seeds computationally feasible to brute-force, allowing attackers to drain approximately 1,367 BTC across thousands of affected addresses. The critical distinction here is that unlike a software patch, the damage is irreversible — firmware updates cannot retroactively strengthen already-generated seeds, meaning affected users must migrate funds to entirely new wallets. This incident underscores that cryptographic key material is only as strong as the entropy source used to generate it, and hardware security devices must be rigorously validated for their core randomness functions.

Tactical Insight

Immediate actions

  • Upgrade COLDCARD firmware to the latest patched version immediately and generate entirely new seeds on updated devices.
  • Migrate all funds from wallets whose seeds were created on Mk2, Mk3, Mk4, Mk5, or Q models before the fix to freshly generated, entropy-verified wallets.
  • Audit wallet creation logs or device history to identify whether seeds were generated during the vulnerable firmware period.

Long-term improvements

  • Require hardware security device vendors to publish verifiable entropy source validation reports and independent third-party firmware audits before release.
  • Establish a hardware wallet lifecycle policy that includes periodic re-keying of high-value wallets and firmware version attestation checks.
  • Maintain an asset inventory of all cryptographic hardware devices, including firmware versions, to enable rapid response when vulnerabilities are disclosed.

Detection measures

  • Monitor blockchain addresses associated with hardware wallets for anomalous or unauthorized transaction patterns using on-chain alerting tools.
  • Subscribe to vendor security advisories and CVE feeds for all hardware security modules and wallet devices in use.
  • Implement out-of-band verification of RNG output quality during device provisioning using entropy testing tools (e.g., NIST SP 800-22 test suite).