$86M in Bitcoin Lost Due to Hardware Wallet Firmware Flaw
A recent Bitcoin hack has resulted in the confirmed loss of $86 million across 4,585 addresses. The incident is attributed to a pseudo-random number generator (PRNG) vulnerability embedded in Coldcard's hardware wallet firmware since March 2021.
The issue was identified by Block's engineering team and lies in Coldcard's libngu library. Coinkite configured the board to zero, intending to use its hardware true random number generator (TRNG), but the libngu guard only checked if the macro was defined, allowing zero to pass.
This led to MicroPython relying on Yasmarang, a software PRNG with limited entropy, instead of the expected 128 bits for a BIP-39 seed phrase. Later models improved to an estimated 72 bits of effective entropy, but still fell short of the ideal.
The attack drained approximately $594 million from 500 addresses on July 30, 2026, and two additional waves were tracked, totaling $1,367.05 BTC across 4,585 addresses by August 2. Most of the stolen Bitcoin remains unspent, suggesting the attacker is biding their time.
The incident highlights a recurring pattern in crypto security: entropy failures that compromise key generation and seed phrases. This vulnerability was not limited to Coldcard products but is a structural issue affecting various codebases and chains.