$86M Lost as Coldcard Hardware Wallet Hack Exposes PRNG Vulnerability
A severe hardware wallet hack has left over $86 million in losses for Bitcoin users. A pseudo-random number generator (PRNG) vulnerability embedded in Coldcard's firmware since March 2021 allowed attackers to drain funds from 4,585 addresses.
The incident occurred without any user error or physical device access, making it one of the worst hardware wallet hacks in Bitcoin history by confirmed losses. The vulnerability was discovered in the libngu library and resulted in a significant disparity between expected and actual entropy.
Ari Redbord, global head of policy at TRM Labs, noted that self-custody transfers can actually increase risk rather than eliminate it. Galaxy Research reported 600 suspected attacker-controlled addresses to federal investigators and compliance vendors.