Coldcard Bug Exposes Users to $72M Bitcoin Heist
A devastating bug in Coldcard software has resulted in over $72 million in Bitcoin stolen from more than 2,600 addresses. Hackers discovered a five-year-old flaw in the device's pseudo random number generator (RNG), which used far lower entropy than expected.
The bug allowed attackers to guess seed phrases generated by the devices, giving them access to private keys and associated public keys holding BTC. The issue has been traced back to March 2021, when Coldcard maker Coinkite began using a proprietary library called 'libNgU'.
Despite claims of a true RNG generator, many devices actually fell back to a pseudo RNG, producing insecure seed phrases. It took over five years for security researchers to discover the issue, with the first hack transactions appearing in July 2026.