Coldcard Flaw Exposes $130M in Bitcoin to Predictable Attacks
A recent incident involving the Coldcard hardware wallet has left over $130 million in Bitcoin missing. The reason behind this massive loss is not due to hacking or a security breach, but rather a flaw in the device's firmware that compromised its randomness generation.
The issue arose with firmware 4.0.0, which was shipped since March 2021 and affected various models, including the Mk2, Mk3, Mk4, Mk5, and Q. The problem lies in how the seed phrase is generated, as it bypasses a built-in randomness chip and uses a predictable software substitute instead.
This has resulted in non-random seed phrases being created, making it possible for attackers to compute the key. In July 2026 alone, over $116 million was drained from more than 5,200 addresses, with some estimates reaching $130 million.
The incident highlights the importance of checking a manufacturer's track record rather than relying solely on features like secure elements or open-source code. The market has reordered itself in response to this incident, and it is essential for users to consider a vendor's past behavior when making purchasing decisions.