Coldcard Seed Generation Flaw Exposes Bitcoin Wallets to Attack
A recent security issue with Coldcard hardware wallets has put the safety of Bitcoin seed generation back in focus. The problem lies in certain older firmware and device versions, which used a predictable software random number generator instead of a hardware one, reducing entropy from 128 bits to 72.
This weakness can make it possible for attackers to guess or derive wallet seeds, putting funds at risk even if the user has never shared their seed phrase or exposed private keys. A reported sweep in July 2026 affected around 594 BTC from approximately 500 single-signature wallets.
The incident highlights the importance of proper entropy in seed generation and the risks associated with predictable randomness. Coldcard users should verify their device firmware and seed creation method to ensure they are not exposed to this vulnerability.