Back to advisories

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

COLDCARD hardware wallet firmware contained an RNG integration flaw that caused wallets to use predictable software-based key generation instead of hardware randomization. Attackers exploited this to reconstruct wallet seeds offline and steal approximately $88.6 million in Bitcoin from affected users. Any organization or individual using COLDCARD wallets is at risk of fund theft if they generated keys during the vulnerable firmware window.

CRITICALAdvisoryAug 04, 2026
Action required
Immediately identify any COLDCARD wallet usage in your environment or customer base. Cross-reference with COLDCARD's published list of affected firmware versions and advise users to migrate funds to new wallets generated with patched firmware or alternative hardware.
Affected products
COLDCARDMk2Mk3Mk4Mk5