Coldcard Hack Exposes Flaw in Seed Generation, Resulting in $86M Loss
A recent Bitcoin hack has resulted in the loss of $86 million worth of cryptocurrency. The incident occurred due to a vulnerability in Coldcard's hardware wallet firmware, which allowed an attacker to drain funds from over 4,500 addresses without any user error or physical device access.
The issue was caused by a misconfigured preprocessor macro that silently collapsed the security guarantee of the seed generation for years. The root cause of the problem lies in Coldcard's libngu library, which relies on a software PRNG with only 40 bits of effective entropy instead of the expected 128 bits.
The hack is considered one of the worst hardware wallet hacks in Bitcoin history, and it has been linked to a pattern of similar incidents. According to Ari Redbord, global head of policy at TRM Labs, self-custody transfers risk rather than eliminate it.