Coldcard Seed-Generation Flaw Exposed by Massive Bitcoin Heist
The Coldcard seed-generation flaw has exposed weaknesses in Bitcoin hardware wallet security. A firmware change in March 2021 rerouted seed generation from a true random number generator to a deterministic pseudorandom number generator, leaving wallets vulnerable for five years.
Coldcard's migration to Bitcoin Core's libsecp256k1 and the introduction of the libngu MicroPython library led to the use of ngu.random.bytes instead of the board-specific ckcc.rng_bytes call. This resulted in the use of a software Yasmarang fallback, which initialized once with the chip's unique ID XORed with SysTick and RTC time registers.
The error persisted undetected until July 2026, when attackers swept over 1,000 Bitcoin addresses in coordinated waves, removing roughly $70 million to $88 million. Galaxy Research mapped the initial 41-minute sweep of 1,196 addresses on July 30 and later identified additional waves that expanded the observed total.