Coldcard Hardware Wallets Hit by Critical Firmware Bug
A critical firmware error in Coldcard hardware wallets has been identified as the cause of an ongoing Bitcoin theft, which has already drained over $38 million worth of cryptocurrency. The issue affects multiple generations of Coldcard devices, including those released since 2021.
The bug lies in a broken random number generator (RNG) check, which turns off the chip's built-in randomness and uses predictable device details instead. This allows attackers to rebuild wallet private keys, compromising user funds.
Coinkite and Blocks Bitcoin engineering team have confirmed that devices running certain firmware released since 2021 receive almost no real randomness at all. Newer models offer a partial fix, but it still narrows the possible outcomes to roughly four billion combinations, making it vulnerable to brute-force attacks.
The same weakness affects paper wallets, seed backups, and other features sharing the same random source. Users are advised to generate a new seed on updated hardware and move funds immediately, as firmware updates cannot undo the damage.