Coldcard Seed Flaw Exposes $116M in Bitcoin to Theft
A recent security flaw in Coldcard's seed-generation process has left over $116 million in Bitcoin vulnerable to theft. According to TEXITcoin founder Bobby Gray, this is not a failure of self-custody itself, but rather a result of users trusting the hardware wallet to generate secure seed phrases without verifying the source of randomness.
The issue occurred when firmware versions 4.0.1 through 4.1.9 on Coldcard Mk2 and Mk3 devices used a predictable software random-number generator instead of the intended hardware source while creating wallet seeds, resulting in seeds with only 40 bits of entropy instead of the expected 128 bits.
Gray emphasized that users who added independent dice-generated entropy were not affected by the attacks, but those who relied solely on the device's seed generation were left vulnerable. Coinkite has released patched firmware, but existing vulnerable seeds require a complete wallet migration.