Coldcard Rolls Out Security Overhaul After $130 Million Bitcoin Exploit

1 hour ago 2 sources negative

Key takeaways:

  • Coldcard's $130M breach exposes systemic risks in hardware wallet seed generation.
  • Affected users must migrate funds promptly; other wallet vendors face similar audit pressure.
  • Hardware wallet trust hinges on randomness; expect increased scrutiny on RNG implementations.

Coinkite, the maker of Coldcard hardware wallets, has released a major security overhaul after attackers exploited a seed-generation flaw to steal roughly $130 million in Bitcoin. The company is urging owners of Coldcard Mk4, Mk5, and Q devices to upgrade to firmware 5.6.1 or 1.5.1Q, following a three-week review that included outside security researchers and AI-assisted vulnerability analysis.

The incident began in July, when attackers started draining air-gapped Coldcard wallets by reconstructing private keys generated with insufficient randomness. The first wave moved 594 BTC — about $38 million at the time — from roughly 500 wallets in just 25 minutes. By early August, Galaxy Research had tracked about $88.6 million stolen across 4,585 addresses, and by August 14 the figure had risen to more than 1,778 BTC, worth roughly $112 million. Across three major attack waves and dozens of smaller incidents, total losses now stand near $130 million. Blockchain analytics firm TRM Labs has separately cited roughly $116 million in Bitcoin moved from compromised wallets.

According to Coinkite and researchers, the underlying flaw dates to 2021. On some affected devices, seed entropy was reduced from about 128 bits to roughly 40 bits, making wallet seeds easier to guess without physical access. Block engineers traced the root cause to a predictable random-number-generator fallback and a 32-bit reseed in Coldcard firmware.

The new firmware tightens multiple security layers. Coldcard now requires users to add external randomness when generating a seed, using at least 65 key presses, 50 dice rolls, or 128 coin flips, which the device combines with its own hardware randomness. Coinkite also replaced its Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and added checks for hardware RNG failures. It fixed issues involving transaction signing, USB data handling, firmware validation, Delta Mode, and wallet backups. The device now checks a partially signed Bitcoin transaction (PSBT) immediately before signing, stopping if the transaction has changed.

Coinkite said users who generated seeds on affected firmware between 2021 and July 2026 should create a new seed on patched firmware and move their Bitcoin. The company added that law enforcement is investigating, and it remains committed to helping affected customers migrate.

Ledger CTO Charles Guillemet called the episode a reminder that a hardware wallet's security model depends on randomness, saying, "Cryptography is hard and implementing it securely is harder." The exploit has become a wake-up call for Bitcoin self-custody and may prompt wider scrutiny of seed-generation practices across the hardware wallet industry.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.