Coldcard Seed Flaw Exposes Millions in Bitcoin Losses
The Coldcard seed flaw has led to significant losses in Bitcoin, with total estimated losses reaching approximately 2,055 BTC (worth around $130 million) across over 7,700 victim addresses. The issue arose due to a seed-generation flaw in devices made by Canadian firm Coinkite.
According to Galaxy Research and analytics account Lookonchain, the affected firmware routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the hardware random number generator (RNG). This allowed attackers to derive candidate keys offline, ultimately draining coins from victim addresses.
The estimated effective entropy for affected seeds was roughly 40 bits on Mk3 hardware and about 72 bits on Mk4, Mk5, and Q models. The practical cost of reproducing seeds depends on available UID information, boot timing, prior RNG calls, and derivation cost.