Skip to content
Back to Guavy Wire
Crypto

Coldcard Crisis Exposes Weakness in Hardware Wallet Security

Instruments
BTC
Share

Coldcard, a leading hardware wallet manufacturer, has faced a major crisis after it was discovered that a firmware defect in some of its devices exposed users to a significant risk of theft. The bug, which affected certain models of Coldcard wallets running firmware versions 4.0.1 through 4.1.9, diverted the device's random-number generation from its STM32 hardware source to MicroPython's deterministic Yasmarang fallback.

This resulted in seeds with low cryptographic randomness, allowing attackers to reconstruct the keys used for Bitcoin transactions. The flaw affected an estimated 7,700 addresses, with losses totaling around $130 million, according to TRM Labs' estimates.

Coldcard's technical notes revealed that the correct hardware random-number generator existed in the firmware binary, but it was not being used correctly. This oversight allowed attackers to exploit the weakness and steal funds from affected users.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc