- deterministic software generatorFlawed RNG used by COLDCARD firmware
- Yasmarang fallbackDeterministic RNG used instead of hardware RNG
ThreatNoir Morning Brief — August 3
Morning Review in IT Security — August 3, 2026
The cybersecurity landscape on August 3, 2026 is marked by significant developments in cryptocurrency security vulnerabilities, privacy law enforcement, and browser-based malware protection. Hardware wallet flaws continue to expose substantial financial losses, while regulatory bodies and technology companies strengthen defenses against emerging threats.
COLDCARD Wallet RNG Flaw Linked to $88 Million Bitcoin Theft
A critical vulnerability in COLDCARD hardware wallet firmware has been identified as the likely cause of an estimated $88.6 million Bitcoin theft affecting thousands of wallet users. The flaw stems from a flawed random number generator that compromised the security of cryptocurrency seeds generated through the affected firmware. Source: COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
The vulnerability involved a deterministic software generator and Yasmarang fallback mechanism that failed to provide adequate entropy for seed generation. This represents a fundamental failure in the cryptographic foundation of affected wallets, leaving users' digital assets vulnerable to theft despite the hardware wallet's intended security properties.
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
A separate analysis by Galaxy Research documented a rapid cryptocurrency theft where an attacker drained 1,196 Bitcoin addresses in just 41 minutes on July 30, stealing 1,082.65 BTC valued at approximately $70.2 million at the time of the attack. The theft has been directly attributed to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet manufactured by Canadian firm Coinkite. Source: Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The root cause traces back to a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of a properly randomized process. This weakness in pseudorandom number generation entropy allowed attackers to predict and compromise wallet seeds with relative ease, enabling the large-scale theft in an extremely compressed timeframe.
Google Chrome to Block New Tab Hijacker Extensions by Default
Google is implementing a new Chrome security feature designed to prevent policy-installed extensions from hijacking the New Tab page or modifying the default search engine settings. Source: Google Chrome may soon block New Tab hijacker extensions by default
This protective measure addresses a persistent malware vector where malicious or compromised extensions alter browser behavior without user consent. By blocking these hijacking capabilities at the browser level, Google aims to reduce user exposure to unwanted search engine redirects and potentially malicious content injection through the New Tab interface.
Austrian Court Decision on Data Privacy and Social Media Disclosure
An Austrian Federal Administrative Court decision has established important precedent regarding the unauthorized sharing of unredacted court judgments on social media platforms. Source: BVwG - W137 2327171-1
The case underscores the intersection of privacy rights and digital information sharing, establishing that public disclosure of court documents containing personal data without proper redaction constitutes a violation of data protection principles. This judgment reinforces the importance of privacy safeguards even for officially issued documents when they contain sensitive personal information.
The morning's security briefing reflects ongoing challenges in cryptocurrency infrastructure, the persistent threat of browser-based malware, and evolving privacy law enforcement in the digital age. Organizations and individuals must remain vigilant regarding hardware wallet firmware updates and browser extension management while respecting data protection obligations in information sharing practices.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Coldcard firmware flaw (PRNG entropy weakness)March 2021 firmware integration error in Coldcard hardware wallet seed generation