A faulty macro setting in Coldcard’s firmware quietly reduced seed randomness for five years, ultimately leading to the theft of 1,367 BTC from thousands of wallet addresses.
According to on-chain analysis published by Galaxy Research on Aug. 2, 2026, a pseudo-random number generator (PRNG) vulnerability present in Coldcard hardware wallet firmware since March 2021 resulted in the confirmed loss of 1,367 BTC, worth about $86 million, across 4,585 addresses.
The incident represents the largest confirmed loss from a hardware wallet exploit in Bitcoin’s history. The attack did not rely on phishing, physical access to devices, or mistakes by users. Instead, it exposed a deeper issue with self-custody security.
The event highlights that the strength of any self-custody setup, whether hardware-based or software-based, depends heavily on the quality of randomness used during seed creation. A single incorrect configuration in the code was enough to weaken that protection for years without producing any obvious warning signs.
The exploit comes as Bitcoin trades about 1.4% lower on the day at roughly $62,250 after a volatile week that pushed prices down from above $65,000. Bitcoin’s 24-hour trading volume stands near $16.9 billion, compared with more than $20 billion the previous day.
How the Coldcard Firmware Flaw Compromised Seed Security
The vulnerability was traced by Block’s engineering team to Coldcard’s libngu library. Coinkite had configured the board value to zero to disable MicroPython’s random number generator and force the use of the device’s hardware true random number generator (TRNG).
However, the protection check in the libngu library only verified whether the macro existed, not whether it contained a valid value. This allowed the zero setting to bypass the intended safeguard.
As a result, MicroPython removed the STM32 hardware RNG function during compilation and instead relied on Yasmarang, a software-based PRNG that provided only around 40 bits of effective entropy. This was significantly weaker than the 128 bits of randomness expected for a BIP-39 seed phrase.
Newer Coldcard models, including the Mk4, Mk5, and Q versions, improved entropy levels to an estimated 72 bits, but still remained below the ideal standard. The difference between 40-bit and 128-bit entropy creates a major security gap, making vulnerable wallets more susceptible to attacks.
On July 30, 2026, Coinkite published a security warning shortly before attackers drained approximately 594 BTC from about 500 addresses. Additional attack waves followed, bringing total losses to 1,367.05 BTC across 4,585 addresses by Aug. 2.
Most of the stolen Bitcoin has not yet moved, suggesting the attacker may be waiting before transferring or selling the funds.
A Recurring Problem With Weak Randomness
The Coldcard exploit follows a broader pattern of crypto security failures caused by weak randomness in key generation.
In 2013, an Android SecureRandom vulnerability caused repeated ECDSA nonces, exposing private keys from multiple Bitcoin wallets. In 2022, the Profanity vanity address generator flaw contributed to the Wintermute hack, where weak 32-bit entropy allowed attackers to steal approximately $160 million.
The Milk Sad vulnerability disclosed in 2023 revealed that Libbitcoin Explorer’s bx seed tool relied on a Mersenne Twister generator seeded by system time. This reduced the expected 256-bit entropy to roughly 32 bits and exposed more than 120,000 wallets.
Although these incidents involved different technologies and networks, they shared the same underlying issue: a randomness source believed to be secure was weaker than expected.
Ari Redbord, global head of policy at TRM Labs, said the incident demonstrates that self-custody does not remove risk but instead shifts where that risk exists. TRM Labs’ H1 2026 data showed that infrastructure and key compromises accounted for only 15% of security incidents but were responsible for 76% of total losses across 207 reported hacks.
Galaxy Research said it has identified around 600 suspected attacker-controlled addresses and shared the information with federal authorities, compliance companies, and cybersecurity teams. The firm noted that its Coldcard attribution is based on blockchain analysis and behavioral patterns rather than direct reconstruction of the seed phrases for each affected wallet.

More Stories
Strategy Trims Bitcoin Holdings by $105M While Boosting STRC Share Repurchases
Bitcoin and Ether Slide as Coldcard Wallet Exploit Extends Into Fifth Day
Bitcoin Futures Premium Crashes as Yields Sink Below U.S. Treasury Returns